Hardware crypto wallet maker Trezor has disclosed that a data breach at its third-party shipping provider, ShipMonk, compromised the personal information of nearly 14,000 customers. Trezor emphasized that the incident did not touch its own infrastructure and that customer devices remain secure.
Trezor says it was notified of the attack on August 10. Customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who placed orders between May 10 and August 8 were affected.
According to the company, attackers accessed full names, phone numbers, email addresses, and shipping addresses belonging to 11,742 customers. A smaller group of 1,947 customers had more limited data exposed, including names, cities, and email addresses, though Trezor notes that for this group, older order data may also have been accessed.
Trezor said the scope of the breach was constrained by its 90-day data retention policy, a standard it says it negotiated with fulfillment partners as well. The company has notified all affected customers via email and is urging them to be alert to suspicious communications requesting personal information or pushing urgent action, warning that the exposed data could be used in targeted phishing campaigns.
Metabase Zero-Day Suspected
ShipMonk reportedly told customers that attackers gained access by exploiting a vulnerability in Metabase, a data analytics platform. The flaw is believed to be a SQL injection zero-day that Metabase patched last week.
The extortion group ShinyHunters has claimed responsibility for the attack on Metabase and leaked data allegedly stolen from the company. ShipMonk itself has not publicly acknowledged the breach, and it remains unclear how many other organizations or individuals may have been affected by the underlying Metabase compromise.
Trezor says it is working directly with ShipMonk to establish a full timeline of events and determine the complete scope of the incident.
What Security Teams Should Watch
- Organizations using Metabase should confirm they have applied the recent patch for the SQL injection vulnerability.
- Affected Trezor customers should treat unsolicited emails or calls referencing their order details with heightened suspicion.
- Third-party fulfillment and analytics vendors represent a growing supply-chain risk vector, even for security-focused hardware providers.
