Third-Party Breach Exposes 67K Trezor Customers Whose Data Was Supposedly Deleted
Trezor's shipping provider, ShipMonk, was compromised via a zero-day SQL injection vulnerability (CVE-2026-72898) in Metabase, exposing personal data for 67,000 customers despite Trezor's prior assurances that the data had been deleted. This incident illustrates a critical failure in third-party data governance: organizations cannot simply trust vendor claims about data deletion without verification and contractual enforcement. The breach exposes customers to phishing, social engineering, and targeted attacks — particularly dangerous given Trezor's cryptocurrency-focused user base. It also underscores that an organization's security posture is only as strong as its weakest third-party vendor, making rigorous supplier oversight non-negotiable.
Tactical Insight
Immediate actions
- Audit all third-party vendors to verify they have actually deleted customer data as contractually required, using documented proof of deletion.
- Demand ShipMonk and similar vendors provide CVE patch status reports and remediation timelines for all internet-facing analytics or BI tools like Metabase.
- Notify affected customers immediately and advise them to watch for phishing attempts targeting cryptocurrency holdings.
Long-term improvements
- Enforce strict data minimization and retention clauses in all third-party contracts, with independent audits to confirm deletion.
- Implement a Third-Party Risk Management (TPRM) program that continuously assesses vendor security posture, including scheduled penetration testing requirements.
- Apply the principle of least data sharing — only provide vendors with the minimum personal data required to fulfill their service.
Detection measures
- Require vendors handling customer PII to provide real-time breach notification SLAs of no more than 24–48 hours.
- Deploy continuous monitoring of data flows to third-party systems to detect unauthorized access or anomalous exfiltration patterns.
- Subscribe to threat intelligence feeds to receive early warnings about zero-day exploits targeting commonly used third-party SaaS and analytics platforms.