On Friday, Trezor, a prominent hardware wallet manufacturer, revealed that approximately 67,000 of its U.S. customers were affected by a data breach involving its shipping provider, ShipMonk. This incident follows a previous disclosure in which Trezor reported that 13,689 customer records were compromised due to similar vulnerabilities.
The compromised data includes sensitive information such as the names, email addresses, phone numbers, shipping addresses, and order numbers from transactions that occurred between November 2019 and August 2021. Importantly, Trezor clarified that the security of its hardware wallets remains intact and that no payments or private keys were exposed in this breach.
Trezor expressed significant disappointment with ShipMonk, stating that it had consistently sought and received written assurances regarding the deletion of customer data as per their contractual and policy agreements. Despite these assurances, the company indicated that the data had not been properly removed from ShipMonk’s systems, exacerbating the severity of the breach.
This incident is characterized as part of a broader attack that exploited a critical SQL injection vulnerability (CVE-2026-72898) in Metabase, a tool used by ShipMonk. This attack illustrates the increasing risks organizations face in their supply chains, highlighting the need for robust third-party risk management strategies within cybersecurity protocols. Following the breach disclosure on August 10, 2026, it was noted that the exposure for some customers was limited to names and email addresses only, specifically omitting shipping information.
Trezor emphasizes its data retention policy, stating that all customer data associated with purchases is deleted or anonymized after 90 days. This timeframe is designed to cover the entirety of an order’s life cycle, including delivery, returns, and refunds. The company aims to minimize the retention of personally identifiable information beyond what is necessary.
While ShipMonk has reportedly fortified its security posture since the incident, it has yet to publicly acknowledge the breach. The potential for social engineering tactics is a significant concern, as the leaked information could enable malicious actors to conduct phishing campaigns or other forms of deception aimed at compromised individuals.
Holborn, an enterprise blockchain security firm investigating the breach, links the attack to the ShinyHunters extortion gang. It highlights how the incident not only underscores the vulnerabilities inherent in third-party logistics but also calls attention to the need for enhanced visibility into third-party risk exposure.
In summary, the Trezor incident serves as a stark reminder of the complexities of maintaining cybersecurity in connected business environments, particularly concerning vulnerabilities in the supply chain. As organizations increasingly rely on third-party providers, they must ensure comprehensive oversight and security measures are in place to protect sensitive customer data against potential exploits.