HackMyIP
← Back to News
2026-09-05 The Hacker News

Trezor Discloses 67,000 Customers Exposed in ShipMonk Supply Chain Breach

Data BreachSupply ChainZero-Day

Hardware wallet manufacturer Trezor revealed on Friday that 67,000 additional U.S. customers had their personal data exposed in a breach at its third-party fulfillment partner ShipMonk. The leaked information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers from transactions placed between November 2019 and August 2021. Trezor emphasized that the incident does not affect the security of its hardware wallets or seed phrases, but warned that exposed users face heightened risks of targeted phishing campaigns and impersonation attempts. Users can verify their exposure with an email breach checker and run a privacy checkup to assess their overall exposure footprint.

The breach stemmed from a software supply chain attack involving CVE-2026-72898, a critical SQL injection vulnerability in Metabase with a maximum CVSS score of 10.0. According to enterprise blockchain security firm Holborn, the ShinyHunters extortion gang is believed to be behind the intrusion, which ShipMonk reportedly disclosed to Trezor on August 10, 2026. Trezor stated that throughout its relationship with ShipMonk, it repeatedly received written assurances confirming that customer data had been deleted in accordance with its 90-day retention policy, and expressed disappointment that the data remained on ShipMonk's systems despite those confirmations. ShipMonk has not publicly acknowledged the incident, though it is said to have patched the exploited flaw and strengthened its security posture following the break-in.

This latest disclosure is in addition to 13,689 customers Trezor reported as affected in the previous month, including 1,947 individuals whose exposure was limited to names, cities, and email addresses. Trezor reiterated its strict data minimization stance, noting that it deletes or anonymizes all customer purchase data after 90 days—the shortest window that still accommodates the full lifecycle of an order, including delivery, returns, and refunds. The company said it has directly notified all impacted customers and is advising them to remain vigilant against social engineering attacks, fraudulent phone calls, and spoofed email communications designed to exploit the leaked details.

Holborn characterized the incident as a textbook example of third-party risk exposure, highlighting how a single zero-day vulnerability in a vendor's software stack can cascade into a large-scale data exposure for otherwise security-conscious organizations. Security professionals recommend that affected individuals rotate credentials on any accounts associated with the exposed email addresses, monitor for suspicious communications, and consider stronger authentication measures. A password checker can help identify whether any reused credentials appear in known credential dumps, reducing the risk of follow-on account takeovers.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →