Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2677+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
NEWS

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Trezor confirms ShipMonk's breach exposed 67,000 more customers via old records the fulfillment partner had assured were deleted, pushing the total to ~80,689.

Dylan H.

News Desk

September 5, 2026
4 min read

A Breach That Kept Getting Bigger

Hardware wallet maker Trezor disclosed on September 4 that a data breach at its shipping and fulfillment partner ShipMonk is substantially larger than first reported. Older U.S. order records that ShipMonk had assured Trezor were deleted turned out to still be present in the leaked dataset, fully exposing 67,000 additional U.S. customers on top of the initial disclosure.


How the Numbers Grew

Trezor first disclosed the incident on August 13, after ShipMonk reported unauthorized access on August 10. That initial notice covered:

  • 11,742 customers with names, emails, phone numbers, and shipping addresses fully exposed
  • 1,947 customers with partial exposure (name, city, and email only)
  • Roughly 13,689 people total, linked to orders from the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal placed between May 10 and August 8, 2026

The September 4 update adds 67,000 more U.S. customers, whose exposed data — names, email addresses, phone numbers, shipping addresses, and order numbers — came from orders placed between November 2019 and August 2021. That pushes the cumulative total of affected Trezor customers to roughly 80,689.


How the Breach Happened

ShipMonk told customers that attackers exploited a vulnerability in the analytics platform Metabase, which notified ShipMonk on August 6 that an unauthorized party had used a software flaw to reach account and customer data. Later reporting ties the campaign to a critical SQL injection zero-day that granted administrator access on compromised Metabase instances.


The Retention Policy Failure

The core of this second disclosure isn't a new intrusion technique — it's a broken data-deletion promise. ShipMonk's contract with Trezor requires fulfillment partners to delete or anonymize order data 90 days after delivery. Trezor says it repeatedly requested, and received, written assurance that ShipMonk had deleted the older records in line with that policy. The 2019–2021 order data should not have existed on ShipMonk's systems at all by the time of the breach.

Trezor's statement was blunt:

"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications... We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."


What Wasn't Affected

Trezor emphasizes that its own infrastructure was not breached: devices remain secure, wallet seed backups were not leaked, and package/parcel contents were not exposed. The company also notes this is the first time since its 2013 founding that a breach has exposed customer phone numbers and shipping addresses — data that significantly raises the risk of targeted phishing and even physical safety concerns for known cryptocurrency hardware wallet owners.


Why This Matters

For a company selling hardware specifically designed to keep private keys offline and secure, a third-party logistics breach exposing home addresses and phone numbers is a serious real-world risk multiplier — attackers now have a verified list of people who own cryptocurrency wallets, along with where to find them. The retention-policy failure also underscores a recurring theme in vendor risk management: a written assurance of data deletion is not the same as verified deletion, and companies that outsource fulfillment need audit rights, not just contractual language, to confirm compliance.


Recommended Actions

  1. Affected Trezor customers should watch for phishing — emails, calls, or physical mail impersonating banks, cryptocurrency exchanges, or Trezor itself, especially anything referencing past ShipMonk order details.
  2. Never share a wallet recovery seed or PIN with anyone contacting you about this breach; Trezor's actual devices and backups were not compromised.
  3. Treat exposed shipping addresses as a physical security concern, not just a digital one, given the connection to cryptocurrency asset ownership.
  4. Organizations using third-party fulfillment or analytics vendors should require verifiable proof of data deletion — audit logs or attestations — rather than accepting written assurances alone.
  5. Review any Metabase deployments in your own environment for the SQL injection zero-day referenced in this campaign and confirm current patch status.

Sources

  • The Hacker News — Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
#Trezor#Data Breach#ShipMonk#Cryptocurrency#Third-Party Risk#Data Retention

Related Articles

14,000 Trezor Customers Impacted by Data Breach at ShipMonk

Hackers stole shipping data including names, addresses, emails, and phone numbers from 14,000 Trezor customers via a breach at logistics firm ShipMonk.

4 min read

Medtronic Notifies Customers Impacted by ShinyHunters Data Breach

Healthcare device giant Medtronic is sending breach notification letters to customers after ShinyHunters gained unauthorized access to personal data held...

4 min read

Ericsson US Discloses Data Breach Affecting Employees and Customers

Ericsson's U.S. subsidiary has disclosed a data breach after attackers hacked a third-party service provider between April 17–22, 2025, exposing names,...

5 min read
Back to all News