[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMNsUtMriZ1Hv0_Iq05-f1Yh54LRy3kTT9Pce98I3DWE":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"6b866601-bf68-4886-b7e5-f4a844107ad8","Trezor data breach impact now reaches 81,000 customers","trezor-data-breach-impact-now-reaches-81-000-customers-93b610","Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]","Cryptocurrency hardware wallet maker Trezor has reported that a data breach at its shipping provider, ShipMonk, has now affected a total of 81,000 customers. The breach, initially affecting 14,000 customers, expanded to include an additional 67,000 US customers due to ShipMonk's failure to delete exposed data as contracted. The attackers exploited a zero-day SQL injection vulnerability in the Metabase analytics platform, and ShipMonk has received extortion demands from the ShinyHunters gang.","Trezor data breach impacts 81,000 customers due to third-party logistics provider ShipMonk.","Trezor data breach impact now reaches 81,000 customers By Sergiu Gatlan September 7, 2026 08:16 AM 0 Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. In total, the breach has affected 81,000 customers after Trezor initially disclosed on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers. As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026. On Friday, it published an update to confirm that the breach impact has expanded after ShipMonk failed to delete the exposed data from its systems as required by Trezor's contract and data policy. \"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed,\" Trezor said. \"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.\" The company added that the breach did not affect its operations or services, that its systems were not compromised, and that all Trezor devices are secure. It also warned affected customers to be wary of any messages requesting personal information, as they may be targeted in phishing attacks. \"Be aware of the increased risk of phishing. The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks,\" Trezor said. Metabase campaign linked to ShinyHunters extortion gang While the company has yet to share how ShipMonk's systems were breached, breach notification emails sent to affected customers and seen by BleepingComputer said the attackers exploited a vulnerability in the third-party analytics platform Metabase. As BleepingComputer previously reported, Metabase revealed that the threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances and carry out data theft attacks after gaining administrator access to the compromised instance. BleepingComputer has also learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang. The list of affected companies in the Metabase campaign includes online form-building platform Tally and laptop maker Framework, which have also notified customers of data breaches after their instances were hijacked. In January 2024, Trezor disclosed another data breach after threat actors compromised its third-party support ticketing portal and accessed data (e.g., names, usernames, and email addresses) from roughly 66,000 users. This stolen data was later used in phishing attacks attempting to steal recipients' 24-word wallet recovery seeds. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Trezor discloses data breach affecting nearly 14,000 customersIDScan sued over alleged data breach affecting 153 million driversFrench hospital fined €500,000 after breach exposes data of 727,000FulcrumSec claims Manchester Airports hack, theft of 86 GB of dataDropbox accounts breached through Lenovo email verification flaw","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Ftrezor-data-breach-impact-now-reaches-81-000-customers\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F09\u002F07\u002FTrezor.jpg","2026-09-07T12:16:32+00:00","2026-09-07T14:00:08.460799+00:00",8,[18,21,24,26],{"name":19,"type":20},"Metabase","product",{"name":22,"type":23},"Trezor","vendor",{"name":25,"type":23},"ShipMonk",{"name":27,"type":28},"ShinyHunters","threat_actor","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":29,"icon":31,"name":32,"slug":33},null,"Breaches","breaches",[35,40,42,47],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":41},{"id":29,"icon":31,"name":32,"slug":33},{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":48},{"id":49,"icon":31,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53],{"type":54,"value":27,"context":55},"malware","Extortion gang linked to the ShipMonk data breach."]