NG Solution Team
Cybersecurity

Trezor ShipMonk breach exposes 67,000 US customer records

On September 4, 2026, Trezor disclosed that a breach at its third‑party logistics provider ShipMonk exposed sensitive order data for approximately 67,000 U.S. customers whose orders were fulfilled between November 2019 and August 2021. An earlier August 2026 disclosure had covered 13,689 customers. The compromised fields include full names, email addresses, phone numbers, shipping addresses and order numbers. Trezor reported that no wallet seeds, private keys or funds were exposed and that its own systems were not compromised. The intrusion exploited a critical SQL injection zero‑day in the Metabase analytics platform (CVE‑2026‑72898, CVSS 10.0). The activity has been attributed to the ShinyHunters extortion group. Trezor said it has directly notified affected individuals and continues to advise vigilance against scams.

Trezor impact and affected customers

The expanded disclosure raises the total number of affected records beyond the initial 13,689 to include roughly 67,000 additional U.S. customers. The exposed data links individuals to cryptocurrency hardware wallet purchases and includes physical addresses and purchase history, increasing the risk of targeted phishing, social‑engineering fraud and potential physical targeting. Trezor’s reliance on written assurances from ShipMonk that old shipping logs were deleted proved insufficient, as records retained by the provider remained accessible and were exfiltrated.

Technical details: Metabase zero‑day (CVE‑2026‑72898)

Attackers exploited a sophisticated supply‑chain route: a critical SQL injection vulnerability in Metabase allowed creation of administrator‑level sessions and bulk download of customer data stored within Metabase. The incident maps to MITRE ATT&CK techniques T1190 (Exploit Public‑Facing Application) and T1005 (Data from Local System), with possible use of T1078 (Valid Accounts) if account/session creation was used for further access. The breach did not involve known malware deployment or commodity tooling; it relied on direct exploitation of the Metabase vulnerability. Attribution to the ShinyHunters extortion gang is based on reporting by enterprise blockchain security firm Holborn and pattern analysis rather than on direct technical evidence disclosed publicly.

Timeline and vendor response

Trezor was initially notified on August 10, 2026; a public disclosure on August 13 covered 13,689 customers. On September 2, 2026, Trezor was informed that the breach was significantly larger, involving an additional approximately 67,000 U.S. customers, with public updates and media coverage appearing on September 4–5. The attack window is not precisely defined in public sources, but the exposed dataset spans orders placed from November 2019 through August 2021. ShipMonk has reportedly secured the affected systems and implemented additional security measures; as of the latest reporting, ShipMonk had not issued a public statement.

Mitigation and recommended actions

Organizations using Metabase or similar analytics platforms should immediately review exposure to CVE‑2026‑72898 and apply available patches or mitigations. Technical validation of third‑party data deletion and retention practices is essential. High‑priority actions include comprehensive third‑party risk assessments and technical audits of vendors that handle sensitive customer data. Affected customers should be vigilant for phishing emails, fraudulent calls and social‑engineering attempts. Medium‑priority steps include updating security awareness training and incident response plans to address supply‑chain and third‑party breaches. Organizations should also monitor threat intelligence for updates on ShinyHunters and related attack patterns.

Related posts

Metabase Zero-Day Under Active Exploitation Grants Unauthenticated Admin Access

Emily Brown

Was patient data compromised in AdaptHealth’s cybersecurity breach?

Michael Johnson

BTCPay Server: Critical Vulnerability — Update to 2.4.2 Now

Jessica Williams

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy