Trezor: ShipMonk Breach Exposed 67,000 U.S. Customers — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Trezor disclosed on Friday that a breach at shipping provider ShipMonk exposed data of 67,000 U.S. customers, including names, email addresses, phone numbers, shipping addresses, and order numbers from orders placed between November 2019 and August 2021.
- Trezor said it had repeatedly requested and received written confirmation from ShipMonk that customer data was deleted under its 90-day retention policy, and expressed disappointment that the data remained in ShipMonk's systems.
- ShipMonk notified Trezor of the breach on August 10, 2026, after unauthorized access exploited CVE-2026-72898, a critical SQL injection flaw in Metabase with a CVSS score of 10.0, according to enterprise blockchain security firm Holborn.
- Holborn attributed the attack to the ShinyHunters extortion gang and characterized the incident as a supply chain attack exploiting a third-party Metabase instance to reach Trezor customer data stored by ShipMonk.
- Trezor confirmed the 67,000-customer exposure is in addition to 13,689 customers it disclosed last month as having had their data either fully or partially exposed in the same ShipMonk incident.
- Trezor warned affected customers to watch for phishing emails, fraudulent phone calls, fake letters, and impersonation attempts, noting the leaked shipping information could also expose individuals to physical security risks.
- ShipMonk has not publicly acknowledged the incident; the company reportedly secured the affected systems and improved security after the digital break-in.
Why it matters: Trezor says its hardware wallets remain uncompromised, but the 67,000 affected customers now face targeted phishing, fraud calls, and physical security risks tied to leaked shipping addresses. The breach also exposes ShipMonk's failure to honor documented data-deletion commitments—a critical third-party trust failure for a company whose customers buy crypto self-custody devices precisely to avoid this kind of exposure.
Ask SkimNews




