A Breach That Kept Getting Bigger
Hardware wallet maker Trezor disclosed on September 4 that a data breach at its shipping and fulfillment partner ShipMonk is substantially larger than first reported. Older U.S. order records that ShipMonk had assured Trezor were deleted turned out to still be present in the leaked dataset, fully exposing 67,000 additional U.S. customers on top of the initial disclosure.
How the Numbers Grew
Trezor first disclosed the incident on August 13, after ShipMonk reported unauthorized access on August 10. That initial notice covered:
- 11,742 customers with names, emails, phone numbers, and shipping addresses fully exposed
- 1,947 customers with partial exposure (name, city, and email only)
- Roughly 13,689 people total, linked to orders from the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal placed between May 10 and August 8, 2026
The September 4 update adds 67,000 more U.S. customers, whose exposed data — names, email addresses, phone numbers, shipping addresses, and order numbers — came from orders placed between November 2019 and August 2021. That pushes the cumulative total of affected Trezor customers to roughly 80,689.
How the Breach Happened
ShipMonk told customers that attackers exploited a vulnerability in the analytics platform Metabase, which notified ShipMonk on August 6 that an unauthorized party had used a software flaw to reach account and customer data. Later reporting ties the campaign to a critical SQL injection zero-day that granted administrator access on compromised Metabase instances.
The Retention Policy Failure
The core of this second disclosure isn't a new intrusion technique — it's a broken data-deletion promise. ShipMonk's contract with Trezor requires fulfillment partners to delete or anonymize order data 90 days after delivery. Trezor says it repeatedly requested, and received, written assurance that ShipMonk had deleted the older records in line with that policy. The 2019–2021 order data should not have existed on ShipMonk's systems at all by the time of the breach.
Trezor's statement was blunt:
"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications... We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."
What Wasn't Affected
Trezor emphasizes that its own infrastructure was not breached: devices remain secure, wallet seed backups were not leaked, and package/parcel contents were not exposed. The company also notes this is the first time since its 2013 founding that a breach has exposed customer phone numbers and shipping addresses — data that significantly raises the risk of targeted phishing and even physical safety concerns for known cryptocurrency hardware wallet owners.
Why This Matters
For a company selling hardware specifically designed to keep private keys offline and secure, a third-party logistics breach exposing home addresses and phone numbers is a serious real-world risk multiplier — attackers now have a verified list of people who own cryptocurrency wallets, along with where to find them. The retention-policy failure also underscores a recurring theme in vendor risk management: a written assurance of data deletion is not the same as verified deletion, and companies that outsource fulfillment need audit rights, not just contractual language, to confirm compliance.
Recommended Actions
- Affected Trezor customers should watch for phishing — emails, calls, or physical mail impersonating banks, cryptocurrency exchanges, or Trezor itself, especially anything referencing past ShipMonk order details.
- Never share a wallet recovery seed or PIN with anyone contacting you about this breach; Trezor's actual devices and backups were not compromised.
- Treat exposed shipping addresses as a physical security concern, not just a digital one, given the connection to cryptocurrency asset ownership.
- Organizations using third-party fulfillment or analytics vendors should require verifiable proof of data deletion — audit logs or attestations — rather than accepting written assurances alone.
- Review any Metabase deployments in your own environment for the SQL injection zero-day referenced in this campaign and confirm current patch status.