Third-Party Vendor Zero-Day Exposes 14,000 Trezor Customers
The breach originated not within Trezor itself, but through its third-party logistics partner ShipMonk, which was exploited via an unpatched zero-day vulnerability in the Metabase analytics platform. This highlights a critical and often underestimated risk: an organization's security posture is only as strong as its weakest vendor link. ShinyHunters, a prolific extortion group, leveraged the Metabase flaw to access customer PII including names, addresses, emails, and phone numbers. Companies that share customer data with third-party service providers must rigorously assess and monitor those vendors' security practices, as failures upstream directly translate into downstream harm for end users.
Tactical Insight
Immediate actions
- Audit all third-party vendors who handle customer PII and demand evidence of patch status for known vulnerabilities.
- Require ShipMonk and similar logistics partners to apply Metabase security patches or mitigations immediately and confirm remediation in writing.
Long-term improvements
- Establish a formal Third-Party Risk Management (TPRM) program that includes mandatory security questionnaires, periodic audits, and contractual breach-notification SLAs.
- Enforce data minimization principles so that vendors only receive the minimum customer data necessary to fulfill their function.
- Include right-to-audit clauses and penetration testing requirements in all vendor contracts that involve customer data.
Detection measures
- Implement continuous monitoring of vendor security posture using tools such as BitSight, SecurityScorecard, or equivalent platforms.
- Require vendors to share relevant security logs and incident notifications within a defined timeframe (e.g., 24–72 hours of discovery).
- Subscribe to vulnerability intelligence feeds (e.g., CISA KEV catalog) to proactively track zero-days affecting tools used by your supply chain.