Trezor Discloses Data Breach via ShipMonk Affecting 67,000 U.S. Customers
Trezor disclosed a data breach at its shipping provider ShipMonk exposing 67,000 U.S. customers' personal information, including names, addresses, and order details, despite claims the data was deleted as per contractual agreements. The breach involved a zero-day SQL injection vulnerability (CVE-2026-72898) in Metabase, exploited by the ShinyHunters extortion group, highlighting supply chain security risks.
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
*** END OF TRANSMISSION ***