Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2704+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Trezor Data Breach Impact Now Reaches 81,000 Customers
Trezor Data Breach Impact Now Reaches 81,000 Customers
NEWS

Trezor Data Breach Impact Now Reaches 81,000 Customers

Trezor says a ShipMonk data breach via a Metabase SQLi zero-day now affects 81,000 customers, up from 14,000 in the initial disclosure.

Dylan H.

News Desk

September 7, 2026
3 min read

A Shipping Vendor's Breach Grows Six-Fold

Cryptocurrency hardware wallet maker Trezor has disclosed that a data breach at its third-party shipping and logistics provider, ShipMonk, now affects 81,000 customers — a sharp jump from the 14,000 customers reported when the incident was first disclosed on August 13, 2026.

Trezor says attackers exploited a critical SQL injection zero-day in ShipMonk's Metabase analytics platform to gain access to shipping records.


Timeline

DateEvent
May 10 – August 8, 2026Breach window during which international customer data was exposed
August 13, 2026Trezor discloses the initial breach — ~14,000 customers
September 7, 2026Trezor announces expanded impact after learning ShipMonk retained additional historical records

Who's Affected

GroupCountDetail
International customers~14,000Brazil, Colombia, Italy, Portugal, Sweden, UK
US customers~67,000Orders placed between November 2019 and August 2021
Total~81,000

The expansion happened because ShipMonk had retained older order records well beyond what Trezor initially believed was exposed — a reminder that breach scope assessments at third-party vendors can shift significantly as investigations progress.


What Was Exposed

  • Full names
  • Shipping addresses
  • Email addresses
  • Phone numbers
  • Order numbers

Trezor emphasizes that no wallet seed phrases, private keys, or device firmware were involved — the breach was confined to shipping and order metadata held by ShipMonk, not Trezor's own infrastructure or the security of the hardware devices themselves.


Why This Matters for Crypto Holders Specifically

Unlike a typical e-commerce data leak, a breach exposing "this person owns a hardware crypto wallet, and here is their home address" carries elevated risk. Trezor's own advisory flags this directly:

"Be aware of the increased risk of phishing. The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks."

Physical risk is not hypothetical in this space — hardware wallet owners have previously been targeted for in-person robbery ("wrench attacks") after their identities and holdings were inferred from leaked purchase data.


Recommendations for Affected Customers

  1. Assume your name, address, and phone number are exposed if you ordered a Trezor device in the affected windows, and treat unsolicited contact accordingly.
  2. Never enter your recovery seed anywhere — Trezor will never ask for it, and this breach does not change that guidance, but attackers will use the leaked data to make phishing attempts more convincing.
  3. Be skeptical of "replacement device" or "security update" outreach referencing your order number — verify independently via Trezor's official site before acting.
  4. Consider your physical security posture if your holdings and address may now be linkable by a motivated attacker.
  5. Watch for spear-phishing that references specific order details, since that level of personalization is now possible with the leaked data.

References

  • BleepingComputer — Trezor data breach impact now reaches 81,000 customers

Related Reading

  • Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
#Trezor#Data Breach#Supply Chain#Cryptocurrency#SQL Injection#ShipMonk

Related Articles

14,000 Trezor Customers Impacted by Data Breach at ShipMonk

Hackers stole shipping data including names, addresses, emails, and phone numbers from 14,000 Trezor customers via a breach at logistics firm ShipMonk.

4 min read

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Trezor confirms ShipMonk's breach exposed 67,000 more customers via old records the fulfillment partner had assured were deleted, pushing the total to ~80,689.

4 min read

Metabase SQLi Zero-Day Exploited in Customer Data-Theft Attacks

A CVSS 10.0 unauthenticated SQL injection zero-day in Metabase's open-source analytics platform was actively exploited against cloud and self-hosted instances, compromising customer data at Framework and Tally. Patches are available for all affected versions.

5 min read
Back to all News