HackMyIP
← Back to News
2026-08-14 SecurityWeek

Trezor Data Breach Exposes Nearly 14,000 Customers via ShipMonk

Data BreachSupply ChainZero-Day

Hardware wallet manufacturer Trezor has disclosed that a data breach at fulfillment provider ShipMonk exposed the personal information of nearly 14,000 customers. Trezor said the incident did not affect its own systems or the security of Trezor devices. The company was notified of the breach on August 10 and identified customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who placed orders between May 10 and August 8.

The exposed records include full names, shipping addresses, email addresses, and phone numbers for 11,742 customers. A further 1,947 customers had their names, cities, and email addresses accessed, although Trezor warned that older orders may also have been involved because of ShipMonk’s data-retention practices. Trezor said it shared the information with ShipMonk to process deliveries and maintains a 90-day storage policy that it says was also applied to fulfillment partners. Affected customers have been notified and should use the email breach checker to assess whether their details appear in known exposure databases.

The breach is being linked to a vulnerability in Metabase, the data analytics platform used by ShipMonk. SecurityWeek reported that attackers likely exploited a SQL injection zero-day patched by Metabase the previous week. The extortion group ShinyHunters later claimed responsibility for a Metabase attack and leaked data allegedly obtained from the company, but the precise scope and attribution of the ShipMonk incident remain unclear. ShipMonk had not publicly acknowledged the breach at the time of publication.

Although no wallet credentials, recovery seeds, or Trezor devices were compromised, attackers may use the stolen contact and shipping details for convincing phishing, impersonation, or delivery-fraud campaigns. Customers should treat unexpected messages requesting personal information, wallet access, seed phrases, or urgent payments with suspicion, and review their exposure with a privacy checkup.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →