14,000 Trezor Customers Impacted by Data Breach at ShipMonk
A data breach at ShipMonk, a third-party shipping provider for Trezor, exposed the personal information of nearly 14,000 customers. The compromised data includes full names, shipping addresses, email addresses, and phone numbers. The breach did not affect Trezor's own systems or hardware wallets but may increase the risk of phishing attacks targeting affected customers. The incident was caused by exploitation of a vulnerability in Metabase, likely an SQL injection zero-day that was recently patched. Trezor has a strict 90-day data retention policy, limiting the scope of exposed data. Customers from multiple countries including the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal were impacted. Trezor has notified affected customers and is working with ShipMonk to investigate the breach further.
AI Analysis
Technical Summary
The breach involved unauthorized access to customer shipping information held by ShipMonk, Trezor's third-party fulfillment partner. Attackers exploited a vulnerability in Metabase, a data analytics platform used by ShipMonk, likely the recently patched SQL injection zero-day. Approximately 11,742 customers had full personal details exposed, while 1,947 had partial data exposure including names, cities, and email addresses. Trezor's internal systems and devices were not compromised. The breach affects customers who placed orders between May 10 and August 8, 2026. Trezor enforces a 90-day data retention policy, which limits the amount of data exposed. The extortion group ShinyHunters claimed responsibility for the Metabase attack. ShipMonk has not publicly acknowledged the breach. Trezor has alerted affected customers and advised caution against phishing attempts.
Potential Impact
The breach exposed sensitive personal information of nearly 14,000 Trezor customers, including names, addresses, email addresses, and phone numbers. This data exposure increases the risk of targeted phishing attacks and social engineering attempts against affected individuals. There is no indication that Trezor's hardware wallets or internal systems were compromised, so the security of the devices themselves remains intact. The breach is limited in scope due to Trezor's data retention policies. However, the exposure of personal data can lead to privacy violations and potential fraud.
Mitigation Recommendations
Trezor has notified all impacted customers and advised them to be vigilant against phishing and suspicious communications requesting personal information or urgent actions. Customers should follow these warnings and avoid responding to unsolicited requests. Trezor and ShipMonk are investigating the breach to determine the full scope and timeline. The vulnerability in Metabase exploited by attackers has been patched; organizations using Metabase should ensure they have applied the latest security updates. No action is required to secure Trezor devices themselves as they were not affected.
Affected Countries
United States, United Kingdom, Sweden, Colombia, Brazil, Italy, Portugal
14,000 Trezor Customers Impacted by Data Breach at ShipMonk
Description
A data breach at ShipMonk, a third-party shipping provider for Trezor, exposed the personal information of nearly 14,000 customers. The compromised data includes full names, shipping addresses, email addresses, and phone numbers. The breach did not affect Trezor's own systems or hardware wallets but may increase the risk of phishing attacks targeting affected customers. The incident was caused by exploitation of a vulnerability in Metabase, likely an SQL injection zero-day that was recently patched. Trezor has a strict 90-day data retention policy, limiting the scope of exposed data. Customers from multiple countries including the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal were impacted. Trezor has notified affected customers and is working with ShipMonk to investigate the breach further.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The breach involved unauthorized access to customer shipping information held by ShipMonk, Trezor's third-party fulfillment partner. Attackers exploited a vulnerability in Metabase, a data analytics platform used by ShipMonk, likely the recently patched SQL injection zero-day. Approximately 11,742 customers had full personal details exposed, while 1,947 had partial data exposure including names, cities, and email addresses. Trezor's internal systems and devices were not compromised. The breach affects customers who placed orders between May 10 and August 8, 2026. Trezor enforces a 90-day data retention policy, which limits the amount of data exposed. The extortion group ShinyHunters claimed responsibility for the Metabase attack. ShipMonk has not publicly acknowledged the breach. Trezor has alerted affected customers and advised caution against phishing attempts.
Potential Impact
The breach exposed sensitive personal information of nearly 14,000 Trezor customers, including names, addresses, email addresses, and phone numbers. This data exposure increases the risk of targeted phishing attacks and social engineering attempts against affected individuals. There is no indication that Trezor's hardware wallets or internal systems were compromised, so the security of the devices themselves remains intact. The breach is limited in scope due to Trezor's data retention policies. However, the exposure of personal data can lead to privacy violations and potential fraud.
Defensive Guidance
Trezor has notified all impacted customers and advised them to be vigilant against phishing and suspicious communications requesting personal information or urgent actions. Customers should follow these warnings and avoid responding to unsolicited requests. Trezor and ShipMonk are investigating the breach to determine the full scope and timeline. The vulnerability in Metabase exploited by attackers has been patched; organizations using Metabase should ensure they have applied the latest security updates. No action is required to secure Trezor devices themselves as they were not affected.
Affected Countries
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/","fetched":true,"fetchedAt":"2026-08-14T08:26:13.592Z","wordCount":1059}
Threat ID: 6a7ed125bf8831d539b2ccfb
Added to database: 08/14/2026, 08:26:13 UTC
Last enriched: 08/14/2026, 08:26:23 UTC
Last updated: 08/14/2026, 12:38:12 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.