Trezor confirmed that a breach at fulfillment provider ShipMonk exposed historical order and personal data for roughly 67,000 additional U.S. customers, bringing the total affected population to more than 80,000. The records relate to orders placed from November 2019 through August 2021 and include names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor said its own systems, hardware wallets, wallet backups, and parcel-content details were not compromised.
Attackers reportedly gained access by exploiting CVE-2026-72898, a critical SQL-injection zero-day in the Metabase analytics platform that could enable administrator-level access. Halborn attributed the incident to the ShinyHunters extortion group. Trezor said ShipMonk retained data that it had represented as deleted or anonymized, and warned impacted customers to expect phishing, impersonation, fraudulent calls or letters, and heightened physical-security risks tied to hardware-wallet ownership.

See which actors are running it and whether you're in range.
13 events from the most recent confirmed update back to the earliest known activity.
Trezor said it was evaluating potential legal action against ShipMonk and accelerating development of anonymous delivery options to reduce the personal data transferred from its systems. It also said ShipMonk had secured and hardened the affected systems following the incident.
Trezor stated that it had repeatedly received written assurances that the historical customer data had been deleted or anonymized under its retention policy, but the affected records remained in ShipMonk systems.
Trezor confirmed that ShipMonk's breach also exposed historical order records for about 67,000 additional U.S. customers, involving orders from November 2019 through August 2021. The records included names, emails, phone numbers, shipping addresses, and order numbers, bringing the total affected population above 80,000.
Shipup publicly confirmed a data breach caused by exploitation of a critical Metabase Cloud vulnerability. The incident exposed customer names, email addresses, and, where provided, phone numbers for customers of Micromania, Easypara, Aroma-Zone, Le Printemps, and Citadium; Shipup did not disclose the number affected.
Trezor updated its disclosure to acknowledge that some records initially characterized as partially exposed were associated with older orders.
Trezor disclosed that 11,742 customers had names, email addresses, phone numbers, and shipping addresses exposed, while 1,947 others had partial exposure of names, cities, and email addresses. The initially identified records related to orders placed from May 10 through August 8, 2026, across seven countries.
ShipMonk informed Trezor that its systems had experienced unauthorized access, initiating Trezor's response to the logistics-provider incident.
Metabase published a security advisory for the critical unauthenticated SQL-injection vulnerability, which can grant administrator privileges on vulnerable instances. CERT-FR reported numerous compromises and urged immediate patching, while documenting request patterns and containment actions for potentially exposed deployments.
Metabase notified ShipMonk that an unauthorized party had used a software flaw to access account and customer data.
Following the ShipMonk data exposure, Trezor customers reported receiving phishing telephone calls and physical letters containing QR codes. The reported scams use the exposed customer contact and delivery information for targeting.
Trezor stated that the ShipMonk breach did not compromise Trezor's own systems, operations, services, or hardware-wallet devices. It warned affected customers that exposed contact and address data could still facilitate phishing, fraud, and physical-security risks.
Halborn assessed that the ShinyHunters extortion gang was responsible for the ShipMonk breach, describing it as a supply-chain attack that used the Metabase flaw to compromise customers, steal data, and extort the organization.
Subsequent reporting characterized the incident as exploitation of CVE-2026-72898, a critical CVSS 10.0 SQL-injection zero-day in Metabase that could provide administrator access to affected instances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecert.ssi.gouv.fr
Open sourcedomainsure.com
Open sourcecyberveille.ch
Open sourcecysecurity.news
Open sourcethehackernews.com
Open sourcecryptika.com
Open sourcehalborn.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.