Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Trezor disclosed that 67,000 U.S. customers had data exposed in a breach at shipping provider ShipMonk, including names, emails, phone numbers, shipping addresses, and order numbers from purchases between November 2019 and August 2021.
- Trezor said it had repeatedly requested and received written confirmation from ShipMonk that customer data was deleted in line with their contract and data policy, but the data was not actually deleted in ShipMonk's systems.
- The 67,000 newly disclosed customers add to 13,689 impacted users Trezor revealed last month, bringing the combined exposure past 80,000 customers.
- ShipMonk informed Trezor of the breach on August 10 after attackers exploited CVE-2026-72898, a maximum-severity SQL injection zero-day flaw in Metabase (CVSS 10.0).
- Enterprise security firm Holborn attributed the attack to the ShinyHunters extortion gang, characterizing it as a software supply chain attack that exposed multiple ShipMonk customers.
- Trezor warned affected users to watch for social engineering attacks, phishing emails, fraudulent calls, and physical security risks stemming from the leaked personal details.
- ShipMonk has not publicly acknowledged the incident, though it reportedly secured affected systems and improved its security after the digital break-in.
Why it matters: The disclosure adds 67,000 U.S. customers to the 13,689 already revealed last month, pushing total exposure past 80,000. ShipMonk's exploitation via a maximum-severity Metabase zero-day exposes how third-party vendor data retention can undermine a company's own 90-day deletion policy. Trezor is now warning users to brace for phishing, fraudulent calls, and physical security threats tied to the leaked shipping details.
Ask SkimNews




