Trezor Reveals Further 67,000 Customers Affected by ShipMonk Data Breach
Hardware wallet maker Trezor has revealed that 67,000 additional U.S. customers had their personal data exposed in a breach at ShipMonk, the company's shipping provider. The exposed data includes names, email addresses, phone numbers, shipping addresses, and order numbers spanning orders placed between November 2019 and August 2021. Trezor confirmed that the security of its hardware wallets themselves was not affected.
Trezor said it had repeatedly requested and received written confirmation from ShipMonk that customer data had been deleted in line with its 90-day retention policy, but the data remained on ShipMonk's systems. This latest disclosure adds to an earlier report last month covering 13,689 customers whose data was fully or partially exposed. ShipMonk reportedly suffered a breach involving exploitation of a critical SQL injection vulnerability in Metabase (CVE-2026-72898, CVSS 10.0), with the ShinyHunters extortion group linked to the intrusion according to security firm Holborn.
Trezor has notified affected customers directly and is warning them to watch for phishing emails, fake calls, and letters that may attempt to exploit the leaked information, including scams impersonating the company itself.