ShipMonk Breach Exposes Data of 67,000 More Trezor Customers

Trezor reports expanded customer data exposure
Hardware wallet manufacturer Trezor says a breach at shipping provider ShipMonk exposed the personal and order information of another 67,000 customers in the United States. The affected records include names, email addresses, phone numbers, shipping addresses and order numbers associated with purchases made between November 2019 and August 2021.
Trezor said the incident does not affect the security of its hardware wallets. It has notified affected customers directly, but warned that the information could be used in phishing emails, fraudulent letters and phone calls, or messages impersonating the company.
The newly disclosed population is in addition to 13,689 customers whose data was fully or partly exposed in an earlier disclosure last month. Trezor also said that 1,947 customers whose exposure had been described as limited to names, cities and email addresses, without shipping addresses, may include older orders.
Deletion assurances did not match retained data
Trezor said it repeatedly requested and received written confirmation from ShipMonk that customer data had been deleted in line with their contract, the company’s data policy and prior communications. It said it was disappointed to find that the data had not in fact been deleted from ShipMonk’s systems.
The hardware wallet maker says it deletes or anonymizes purchase-related customer data from the Trezor eShop after 90 days. Trezor described that period as the shortest window covering the full order lifecycle, including delivery, returns, refunds and replacements, after which it says it has no reason to retain a customer’s address or phone number.
ShipMonk informed Trezor of unauthorized access to its systems on August 10, 2026. ShipMonk had not publicly acknowledged the incident at the time of the disclosure. The logistics company is said to have secured the affected systems and improved security after the intrusion.
Critical Metabase flaw linked to supply-chain incident
The digital break-in reportedly involved exploitation of CVE-2026-72898, a critical SQL injection vulnerability in Metabase with a CVSS score of 10.0. Enterprise blockchain security firm Holborn said the ShinyHunters extortion gang is believed to be responsible.
Holborn characterized the incident as a software supply-chain attack: attackers exploited the Metabase flaw, compromised several customers and stole sensitive data for extortion. In Trezor’s case, the exposed material was customer order data held in a ShipMonk Metabase instance.
For businesses, the incident makes third-party data retention and vulnerability exposure operational concerns, not merely contractual ones. Teams should ensure suppliers can demonstrate deletion practices, maintain visibility into externally hosted systems and prepare customers for social-engineering attempts when contact and delivery data is exposed.

