Trezor Reports ShipMonk Breach Exposed Data Of 67,000 U.S. Customers

Trezor Reports ShipMonk Breach Exposed Data Of 67,000 U.S. Customers

Hardware wallet manufacturer Trezor has disclosed that an additional 67,000 customers in the United States were impacted by a data breach involving its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers associated with purchases made between November 2019 and August 2021. Trezor clarified that the incident does not affect the security of its hardware wallets or the protection of cryptocurrency stored through its devices.

The company said ShipMonk informed Trezor about the breach on August 10, 2026, following unauthorized access to its systems. Trezor stated that throughout its relationship with the logistics provider, it had repeatedly requested and received written confirmation that customer data was being deleted according to contractual requirements, data policies, and previous communications. However, the company said it was disappointed that the information remained available within ShipMonk systems despite those confirmations. “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” Trezor said. The company added that the newly disclosed exposure is separate from the 13,689 customers whose information was previously reported as partially or fully exposed last month. At that time, Trezor said the exposure was limited by its 90 day data storage policy.

Trezor explained that customer purchase-related information is deleted or anonymized after 90 days through its eShop processes. The company said this timeframe was selected as the shortest period needed to complete the entire order lifecycle, including delivery, returns, refunds, and replacements. After this period, Trezor stated that it has no operational requirement to retain customer addresses or phone numbers. Following the incident, Trezor revealed that 1,947 customers whose exposed information was limited to names, cities, and email addresses, without shipping addresses, may include details from older orders. The company has notified affected customers directly and warned them to remain cautious against potential social engineering attempts. The exposed information could be used by attackers to send phishing emails, make fraudulent calls, distribute fake letters, or impersonate Trezor representatives to convince users to take unintended actions. “The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks,” Trezor said. The company encouraged customers to verify communications carefully and avoid sharing sensitive information in response to unexpected messages or requests.

ShipMonk has not publicly acknowledged the incident at the time of disclosure. Reports indicate that the logistics company secured the affected systems and strengthened security measures following the security incident, which involved exploitation of CVE-2026-72898, a critical SQL injection vulnerability in Metabase with a CVSS score of 10.0. According to enterprise blockchain security firm Holborn, the ShinyHunters extortion group is believed to be connected to the breach. Holborn described the incident as a supply chain attack that began with the exploitation of a zero day vulnerability. The security firm said attackers were able to compromise affected systems through the Metabase SQL injection flaw, leading to the exposure of sensitive information stored in a Metabase instance managed by ShipMonk. Holborn highlighted that the incident demonstrates the importance of maintaining visibility into third party risks, as organizations increasingly rely on external providers for business operations. The security firm noted that the exposure of Trezor customer order details through a third party system shows how vulnerabilities in connected services can impact organizations beyond their direct infrastructure.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment