Cybersecurity

ShipMonk Leak Raises Number of Affected Trezor Customers to 81,000

Trezor confirmed that a breach at shipping and logistics provider ShipMonk affected an additional 67,000 U.S. customers, bringing the total to 81,000. Notification emails indicate the exploitation of a critical SQL injection vulnerability in the Metabase platform, while customers were warned about phishing and potential security risks.

2026-09-07
4 min read
8 views
فريق تحرير certi.news
ShipMonk Leak Raises Number of Affected Trezor Customers to 81,000

Trezor announced that the scope of the data breach at shipping and logistics provider ShipMonk in August had expanded to include an additional 67,000 customers in the United States, bringing the total number of affected customers to approximately 81,000. The company had disclosed on August 13 that the data of nearly 14,000 customers had been accessed without authorization.

According to Trezor, the exposed data includes full names, shipping addresses, email addresses, and phone numbers, as well as order numbers for the U.S. group that made purchases between November 2019 and August 2021. The customers affected in the initial disclosure had received their orders between May 10 and August 8, 2026, and included customers in Brazil, Colombia, Italy, Portugal, Sweden, the United Kingdom, and the United States.

How did the scope of the incident expand?

Trezor said ShipMonk did not delete the exposed data from its systems, despite the fact that the companies’ contract and data policy required it to do so. It added that it repeatedly requested written confirmation from ShipMonk that the deletion had been completed and received those confirmations, before it became clear that the data had remained in the provider’s systems.

Notification emails reviewed by BleepingComputer explain that the attackers exploited a vulnerability in the third-party analytics platform Metabase. Metabase had said that threat actors exploited a critical SQL injection vulnerability classified as a zero-day, then carried out data theft after obtaining administrator privileges in the compromised instance.

Trezor has not yet explained exactly how ShipMonk’s systems were breached. The report also stated that ShipMonk received extortion messages from the ShinyHunters group, which the report linked to the Metabase exploitation campaign that affected other companies, including form-building platform Tally and laptop company Framework.

What does this mean for Trezor users?

Trezor emphasized that the incident did not affect its operations or services, that its systems were not breached, and that Trezor devices themselves remain secure. However, the nature of the leaked data gives attackers enough information to tailor phishing messages or make calls and carry out scams that appear to be connected to genuine orders. The company therefore warned customers about any message requesting personal information, also noting the possibility of physical safety risks for affected individuals.

The incident is particularly significant because Trezor suffered another breach in January 2024 at a third-party support ticketing portal, which resulted in access to the data of approximately 66,000 users. That data was later used in phishing campaigns aimed at stealing 24-word wallet recovery phrases.

Editorial analysis

The actual change here is not a breach of Trezor devices or services, but the expanded impact of a supply-chain incident caused by retaining data that should have been deleted. This highlights that contractual compliance assurances alone are insufficient when they are not accompanied by a verifiable ability to delete data and monitor third-party systems.

The source does not provide details about when the Metabase vulnerability was exploited or the volume of data that was actually transferred, nor does it clarify whether all affected records were used in fraud campaigns. These points remain open questions, while the clearest practical step for customers is to treat any communication that links itself to Trezor orders or previous shipping information with caution.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news