Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
A breach at ShipMonk, Trezor's shipping provider, has exposed the personal data of approximately 67,000 U.S. customers, including names, email addresses, phone numbers, and shipping addresses. This data was supposedly deleted by ShipMonk, but the breach occurred due to a zero-day SQL injection vulnerability in Metabase, and the ShinyHunters extortion gang is believed to be behind it. Trezor is urging customers to be vigilant against phishing and social engineering attacks leveraging the leaked information.
A breach at ShipMonk, Trezor’s shipping provider, has exposed the personal data of approximately 67,000 U.S. customers, including names, email addresses, phone numbers, and shipping addresses. The exposure follows a previous disclosure last month regarding 13,689 customers whose data was either fully or partially exposed. ShipMonk informed Trezor of the breach on August 10, 2026, following unauthorized access to their systems.
The breach was attributed to a zero-day SQL injection flaw in Metabase, exploited by the ShinyHunters extortion gang. ShipMonk had previously assured Trezor that the data was deleted, in line with their contract and data policy. However, the incident demonstrates a failure in ShipMonk’s security practices and a lack of complete visibility into their third-party risk exposure.
Trezor is urging affected customers to be on the lookout for social engineering attacks and scams, as bad actors can exploit the leaked information to send phishing emails or letters, make fake phone calls, and even impersonate the company in email communications to persuade targets into taking unintended actions.
Holborn, an enterprise blockchain security firm, highlighted the need for organizations to have complete visibility into their third-party risk exposure in order to help manage their overall security posture. The Trezor breach underscores the importance of robust supply chain security and proactive vulnerability management.
ShipMonk has yet to publicly acknowledge the incident.
