Cyber Security News

Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers

Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S. order records that should have been deleted remained in the leaked dataset.

On September 4, 2026, Trezor said it was told two days earlier that the incident also included order data from a prior ShipMonk partnership between November 2019 and August 2021, fully exposing about 67,000 additional U.S. customers.

Trezor first disclosed the incident on August 13 after ShipMonk reported unauthorized access on August 10. That notice covered 11,742 customers whose names, emails, phone numbers and shipping addresses were fully exposed, plus 1,947 with partial exposure of name, city and email, totaling about 13,689 people.

Those records were linked to orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026. An August 14 update already admitted that some partial-exposure records included older orders.

ShipMonk told customers that attackers exploited a vulnerability in the analytics platform Metabase. Metabase notified the logistics firm on August 6 that an unauthorized party used a software flaw to reach account and customer data. Later reporting tied the campaign to a critical SQL injection zero-day that yielded administrator access on compromised instances. Trezor’s own systems were not breached, its devices remain secure, and wallet backups were not leaked. Parcel contents were not exposed.

The latest update undercuts the retention argument Trezor used to bound the first disclosure. The company requires fulfillment partners to delete or anonymize order data 90 days after delivery. Trezor said it repeatedly requested and received written assurance that ShipMonk had deleted the older records, yet the data was still in ShipMonk’s systems.

The newly acknowledged U.S. files include name, email, phone number, shipping address, and order number, bringing the overall impact above 80,000 customers.

That combination of home addresses, phone numbers and hardware-wallet purchase history is useful for phishing and, Trezor now warns, physical security risk.

Scammers can impersonate Trezor, banks, or exchanges by email, call, or letter and push victims to enter a recovery seed. Affected customers have been emailed from help@trezor.io; anyone who did not receive that message is not in the leaked set.

Recipients should treat urgent requests for personal data as hostile, verify claims only through official Trezor channels, and never type a wallet backup into a website or share it with anyone.

Trezor said this is the first incident since its 2013 founding to expose customer phone numbers and shipping addresses, and it is preparing an Anonymous Delivery option with locker pickup and automatic deletion of shipping identifiers.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago