Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customer
Hardware wallet maker Trezor disclosed a data breach at its shipping provider ShipMonk, exposing 67,000 U.S. Customers' order data from 2019-2021.

Hardware wallet manufacturer Trezor disclosed on Friday, September 26, 2026, that a breach at its shipping provider, ShipMonk, exposed the data of 67,000 U.S. Customers. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers for purchases made between November 2019 and August 2021.
Trezor stated that the security of its hardware wallets was not affected. The company said ShipMonk informed it of the breach on August 10, 2026, following unauthorized access to the logistics company's systems. This latest disclosure adds to the 13,689 customers Trezor said were impacted in a notification last month.
Breach Details and Data Retention Policy
Trezor emphasized its strict data retention policy in its disclosure. "After 90 days we delete or anonymize all customer data related to a purchase on our Trezor eShop," the company said. "We chose 90 days because it is the shortest window that still covers the whole life of an order."
The company expressed frustration with ShipMonk's handling of the data. "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," Trezor stated. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."
Of the previously disclosed 13,689 affected customers, the exposure for 1,947 was limited to names, cities, and email addresses, excluding full shipping addresses. Trezor noted these may relate to older orders.
Attack Vector and Third-Party Risk
The breach was a software supply chain attack originating from a critical zero-day vulnerability. According to enterprise blockchain security firm Holborn, attackers exploited CVE-2026-72898, an SQL injection flaw in the business intelligence tool Metabase, which had a maximum CVSS score of 10.0.
Holborn linked the ShinyHunters extortion gang to the breach. By exploiting the flaw in Metabase, the attackers compromised several of ShipMonk's customers, stealing sensitive data. "In Trezor's case, this meant the exposure of customer order details that were stored in a Metabase instance by ShipMonk," Holborn said.
The security firm stated the incident highlights the critical need for organizations to gain complete visibility into their third-party risk exposure to manage their overall security posture. ShipMonk has not publicly acknowledged the incident but is said to have secured the affected systems and improved its security following the digital break-in.
User Warnings and Company Response
Trezor has directly notified the affected customers. The company warned users to be vigilant for social engineering attacks and scams, as the leaked information could be weaponized by bad actors.
"The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks," Trezor said. It cautioned that attackers might send phishing emails, make fake phone calls, send fraudulent letters, or even impersonate Trezor in communications to trick targets.
Holborn's analysis framed the event as a stark reminder of supply chain vulnerabilities. "The Trezor breach was the result of a supply chain attack beginning with a zero-day vulnerability," the firm concluded.





