← BACK TO FEED
data breachsupply chain securityTrezorShinyHuntersthird-party risk

Trezor's Shipping Partner Kept Data It Promised to Delete. 67,000 Customers Are Now Paying the Price.

Trezor has disclosed that a breach at its shipping provider ShipMonk exposed the personal data of 67,000 U.S. customers, including names, addresses, phone numbers, and order details from 2019–2021 — data Trezor had repeatedly been assured was deleted. The breach stemmed from a zero-day SQL injection vulnerability (CVE-2026-72898) in Metabase, with the ShinyHunters extortion gang reportedly responsible. While the hardware wallets themselves remain secure, Trezor has warned affected customers to be vigilant against phishing, scam calls, and social engineering attacks exploiting the leaked information.

Hardware wallet maker Trezor has disclosed that 67,000 US customers had their personal data exposed in a breach at third-party logistics firm ShipMonk, despite Trezor having repeatedly obtained written confirmation that the data had been deleted.

The exposed records cover orders placed between November 2019 and August 2021 and include names, email addresses, phone numbers, shipping addresses, and order numbers. The breach has no bearing on the security of Trezor's actual hardware wallets, which is presumably cold comfort to the people whose home addresses are now floating around somewhere.

This disclosure follows an earlier announcement last month covering 13,689 customers whose data was either fully or partially exposed. At the time, Trezor said the breach was contained within its 90-day data retention window. That window, it turns out, was largely irrelevant, because ShipMonk apparently never honoured the deletion requests in the first place.

"We repeatedly requested and received written assurance confirming the deletion of the data," Trezor said. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."

ShipMonk informed Trezor of the breach on 10 August 2026, after attackers gained unauthorised access to its systems. The vector was CVE-2026-72898, a critical SQL injection flaw in Metabase with a CVSS score of 10.0, exploited as a zero-day. ShipMonk has said nothing publicly about the incident, though it reportedly locked down the affected systems after the fact.

Enterprise blockchain security firm Holborn has attributed the attack to ShinyHunters, the extortion group with a long track record of high-profile data theft. The breach is being characterised as a software supply chain attack, with ShipMonk's Metabase instance used as the entry point to reach multiple customers' data.

Trezor has notified affected customers directly and is warning them to stay alert. The leaked data is exactly the kind that makes phishing campaigns and impersonation scams effective, and given that physical addresses were included, there are potential real-world security risks too.

The broader lesson here is one the industry keeps learning the hard way. A company's security is only as good as its weakest supplier. Trezor had a data retention policy, contractual protections, and written confirmations. None of it mattered because the third party simply did not follow through. Holborn put it plainly: organisations need genuine visibility into their third-party risk, not just paperwork.

WATCH THE SHORT
READ NEXT
ShinyHunters Padded the Carhartt Breach With Millions of Fake RecordsShinyHunters Turns Up the Heat on Ernst & Young After Tax Data BreachShinyHunters Dumps 41GB of Brinks Home Data After Ransom Goes Unpaid