Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Hackers Exploit AI Models Claude, Qwen, DeepSeek for Cyberattacks
September 4, 2026
Microsoft Exchange Online Outage Delays External Emails
September 4, 2026
Microsoft 365 Phishing Evades Blocking With Empty Sender Technique
September 4, 2026
Home/CyberSecurity News/Trezor Confirms ShipMonk Breach Exposed 67,000 US Customers
CyberSecurity News

Trezor Confirms ShipMonk Breach Exposed 67,000 US Customers

Key Takeaways Hardware wallet manufacturer Trezor has confirmed a significant data breach impacting approximately 67,000 additional U.S. customers due to a security incident at its logistics partner,...

Marcus Rodriguez
Marcus Rodriguez
September 4, 2026 4 Min Read
3 0

Key Takeaways

  • Hardware wallet manufacturer Trezor has confirmed a significant data breach impacting approximately 67,000 additional U.S. customers due to a security incident at its logistics partner, ShipMonk.
  • The breach originated from an exploited vulnerability in the Metabase analytics platform used by ShipMonk, granting unauthorized access to customer order data.
  • Exposed data includes names, email addresses, phone numbers, shipping addresses, and order numbers, raising concerns about heightened phishing and potential physical security risks.
  • Trezor’s internal systems and wallet backups remain secure, but the incident highlights critical third-party vendor security and data retention challenges.

Trezor Confirms Broader Impact in ShipMonk Data Breach, 67,000 More US Customers Affected

Hardware wallet producer Trezor has revealed that a data breach at its logistics provider, ShipMonk, is considerably more extensive than initially reported. The expanded scope includes older U.S. order records that were supposed to have been purged but remained accessible within the compromised dataset.

Table Of Content

  • Key Takeaways
  • Trezor Confirms Broader Impact in ShipMonk Data Breach, 67,000 More US Customers Affected
  • Breach Details Evolve
  • Root Cause and Data Exposed
  • Data Retention Policies Called into Question
  • Trezor’s Response and Future Mitigation
  • What You Should Do

Breach Details Evolve

On September 4, 2026, Trezor disclosed that it had been informed two days prior that the security incident also encompassed historical order information from a previous collaboration with ShipMonk, spanning from November 2019 to August 2021. This revelation fully exposed an additional 67,000 U.S. customers.

Trezor first publicly acknowledged the incident on August 13, following ShipMonk’s report of unauthorized access on August 10. The initial disclosure identified 11,742 customers whose names, email addresses, phone numbers, and shipping addresses were fully exposed. An additional 1,947 customers experienced partial exposure of their names, cities, and email addresses, bringing the initial total to approximately 13,689 individuals.

These records were linked to orders placed in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and August 8, 2026. An update on August 14 had already indicated that some partially exposed records included older order data.

Root Cause and Data Exposed

ShipMonk informed its clients that the attackers exploited a vulnerability within the Metabase analytics platform. Metabase had notified the logistics firm on August 6 that an unauthorized party leveraged a software flaw to access account and customer data. Subsequent reports linked this campaign to a critical SQL injection zero-day that provided administrator-level access on compromised instances. Trezor has confirmed that its own systems were not compromised, its devices remain secure, and no wallet backups were leaked. The contents of parcels were also not exposed in the breach.

The newly acknowledged U.S. files contain sensitive information including names, email addresses, phone numbers, shipping addresses, and order numbers. This brings the overall number of affected customers to over 80,000. This combination of personal details, including home addresses and hardware-wallet purchase history, is highly valuable for sophisticated phishing attacks and, as Trezor now warns, poses a potential physical security risk.

Data Retention Policies Called into Question

The latest update significantly undercuts the data retention assurances Trezor previously relied upon for its initial disclosure. Trezor’s policy mandates that fulfillment partners delete or anonymize order data 90 days post-delivery. Despite this, Trezor stated it had repeatedly requested and received written confirmation from ShipMonk that these older records had been deleted. However, the data demonstrably remained within ShipMonk’s systems, leading to its exposure.

Trezor’s Response and Future Mitigation

Trezor has stated that this incident marks the first time since its founding in 2013 that customer phone numbers and shipping addresses have been exposed. In response, the company is developing an “Anonymous Delivery” option, which will include locker pickup services and automatic deletion of shipping identifiers to enhance customer privacy.

Affected customers have been notified via email from [email protected]. Individuals who did not receive this specific email are not believed to be part of the leaked dataset.

What You Should Do

  • Be Vigilant Against Phishing: Exercise extreme caution with all communications claiming to be from Trezor, banks, or cryptocurrency exchanges. Scammers may impersonate these entities via email, phone calls, or even physical mail to trick victims into revealing sensitive information.
  • Verify All Requests: Never click on suspicious links or respond to urgent requests for personal data. Always verify any claims or instructions by directly contacting Trezor through its official channels, not using contact information provided in a suspicious message.
  • Protect Your Recovery Seed: Absolutely never enter your wallet recovery seed into any website, software, or share it with anyone, regardless of who they claim to be. Your recovery seed is the master key to your funds.
  • Monitor Accounts: Keep a close eye on your email accounts for any unusual activity or suspicious login attempts, especially those linked to your Trezor purchase.
  • Consider Anonymous Delivery Options: As Trezor rolls out its Anonymous Delivery option, consider utilizing such features to reduce the exposure of your personal shipping information for future purchases.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitphishingSecurityVulnerabilityzero-day

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Microsoft Teams to Block Malicious QR Codes in Messaging

Next Post

Plex Patches Critical Vulnerabilities in Media Server

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Plex Patches Critical Vulnerabilities in Media Server
September 4, 2026
Trezor Confirms ShipMonk Breach Exposed 67,000 US Customers
September 4, 2026
Microsoft Teams to Block Malicious QR Codes in Messaging
September 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us