Trezor Data Breach Affects 81,000 Customers: What You Need to Know

www.news4hackers.com-trezor-data-breach-affects-81-000-customers-what-you-need-to-know-trezor-data-breach-affects-81-000-customers-what-you-need-to-know

Cryptocurrency hardware wallet provider Trezor confirmed an expansion of a data breach affecting 81,000 customers following a security incident at its logistics partner, ShipMonk.

Initial Breach and Expansion

The breach initially impacted 14,000 users in August 2026, with attackers accessing personal information including full names, shipping addresses, phone numbers, and order details. The scope of the incident has since grown to include an additional 67,000 U.S. customers who placed orders between November 2019 and August 2021.

ShipMonk’s Failure

Trezor stated that ShipMonk failed to remove the exposed data from its systems as required by contractual obligations and data protection policies. The company reiterated that it had repeatedly requested written confirmation of data deletion but found that the information remained accessible. This failure led to the broader exposure of customer records, despite prior assurances from ShipMonk.

Regions Affected

The breach affected users in multiple regions, including Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom, with impacted orders spanning from May 10 to August 8, 2026.

Trezor’s Statement

Trezor emphasized that its internal systems and devices remain secure, and no compromise was detected in its core operations. However, the company issued warnings to affected individuals about heightened risks of phishing attacks, as stolen data could be used for fraudulent communications or physical security threats.

Metabase Vulnerability

A separate investigation revealed that the breach at ShipMonk was linked to a vulnerability in the third-party analytics platform Metabase. Attackers exploited a critical SQL injection zero-day flaw to gain administrator access and exfiltrate customer data. This method aligns with tactics previously attributed to the ShinyHunters extortion group, which has targeted other organizations, including online form-building platform Tally and laptop manufacturer Framework.

ShinyHunters Connection

ShipMonk has also been identified as a recipient of extortion demands from ShinyHunters, though the company has not publicly commented on the matter. The Metabase breach highlights the cascading risks of third-party vulnerabilities, as compromised data from one entity can propagate to multiple downstream organizations.

Previous Breaches

This incident marks the second data breach disclosed by Trezor in 2026. In January 2024, a separate breach occurred when threat actors infiltrated its third-party support ticketing portal, exposing details such as names, usernames, and addresses for approximately 66,000 users. Stolen credentials from that incident were later used in phishing campaigns targeting wallet recovery seeds.

Recommendations and Conclusion

Trezor advised customers to exercise caution with unsolicited communications and to verify the legitimacy of any requests for personal information. The company has not provided further details on the specific methods used to compromise ShipMonk’s systems but emphasized ongoing efforts to strengthen security protocols. The breach underscores the challenges of managing third-party risks in cybersecurity, particularly for organizations handling sensitive user data. As threat actors increasingly target supply chain vulnerabilities, enterprises are urged to implement rigorous oversight of vendor security practices and ensure compliance with data deletion requirements.



About Author

en_USEnglish