Full Report
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]
Analysis Summary
# Incident Report: Supply Chain Breach via ShipMonk
## Executive Summary
Trezor, a cryptocurrency hardware wallet manufacturer, experienced a significant data breach originating from its shipping and logistics provider, ShipMonk. The incident resulted in the exposure of personal information for approximately 81,000 customers due to the exploitation of a zero-day vulnerability in a third-party analytics platform. The scope of the breach expanded significantly when it was discovered that the vendor failed to adhere to data retention policies, keeping legacy customer records from as far back as 2019.
## Incident Details
- **Discovery Date:** August 13, 2026 (Initial disclosure)
- **Incident Date:** May 10, 2026 – August 8, 2026 (Primary window)
- **Affected Organization:** ShipMonk (Logistics provider for Trezor)
- **Sector:** Cryptocurrency / Logistics / E-commerce
- **Geography:** United States, Brazil, Colombia, Italy, Portugal, Sweden, and United Kingdom
## Timeline of Events
### Initial Access
- **Date/Time:** May 2026
- **Vector:** Exploitation of a third-party analytics platform.
- **Details:** Threat actors exploited a critical SQL injection zero-day vulnerability in **Metabase**, an analytics tool used by ShipMonk.
### Lateral Movement
- **Details:** After exploiting the SQL injection vulnerability, attackers gained administrator-level access to the Metabase instance, allowing them to query and extract data from connected databases.
### Data Exfiltration/Impact
- **Details:** Attackers exfiltrated the personal details of 81,000 customers. Data included full names, shipping addresses, email addresses, phone numbers, and order numbers.
- **Legacy Impact:** 67,000 of the affected records belonged to U.S. customers who ordered between November 2019 and August 2021—data that should have been deleted per Trezor’s contract.
### Detection & Response
- **How it was discovered:** Likely through extortion attempts by the threat actor and internal audits following the Metabase zero-day disclosure.
- **Response actions taken:** Trezor issued public notifications on August 13 and a subsequent update on September 6. They confirmed their internal systems remained secure and initiated an investigation into ShipMonk's data retention failure.
## Attack Methodology
- **Initial Access:** Zero-day SQL injection in Metabase.
- **Persistence:** Not specified, but typical of administrative hijacking of web applications.
- **Privilege Escalation:** Exploitation allowed attackers to gain Administrator access to the analytics instance.
- **Collection:** Automated querying of databases via the Metabase interface.
- **Exfiltration:** Data theft via the hijacked analytics platform.
- **Impact:** Potential for targeted phishing, fraudulent calls, and physical security risks to cryptocurrency holders.
## Impact Assessment
- **Financial:** High potential for secondary loss through phishing of affected customers; specific extortion amounts from ShinyHunters not disclosed.
- **Data Breach:** Exposure of PII (Personally Identifiable Information) for 81,000 customers.
- **Operational:** Disruption of logistics trust and vendor management overhead.
- **Reputational:** Significant damage to Trezor's brand due to repeat supply chain incidents (third breach reported in recent years).
## Indicators of Compromise
- **Network indicators:** Activity associated with Metabase exploitation (specific IPs not provided in text, would typically include traffic to `metabase.sh` or local instances).
- **Behavioral indicators:** Unusual administrative logins to analytics platforms; large-scale SQL queries resulting in high data egress.
- **Attribution:** Linked to the **ShinyHunters** extortion gang.
## Response Actions
- **Containment:** ShipMonk addressed the Metabase vulnerability.
- **Eradication:** Trezor demanded confirmation of data deletion (though previous confirmations were found to be inaccurate).
- **Recovery:** Notification of customers and issuance of security warnings regarding phishing risks.
## Lessons Learned
- **Vendor Non-Compliance:** Even with written assurances and contracts, vendors may fail to delete data. Trust but verify (via audits) is essential.
- **Supply Chain Vulnerability:** Hardware security is irrelevant if the customer PII associated with the purchase is poorly protected by third parties.
- **Legacy Data Risks:** Storing data longer than necessary (2019–2021 records) significantly increased the breach magnitude.
## Recommendations
- **Rigorous Auditing:** Implement technical verification of data deletion by third-party vendors rather than relying on written confirmation.
- **Data Minimization:** Enforce strict "auto-delete" policies for customer PII once a shipment is confirmed delivered and the return window has closed.
- **Vulnerability Management:** Rapidly patch or isolate third-party analytics tools (like Metabase) that interact with sensitive production databases.
- **Phishing Education:** Provide specific guidance to users on how to distinguish legitimate Trezor communications from scams using leaked PII.