Full Report
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
Analysis Summary
# Incident Report: Supply Chain Breach via ShipMonk Affecting Trezor Customers
## Executive Summary
Hardware wallet manufacturer Trezor disclosed a secondary wave of customer data exposure resulting from a breach at its third-party logistics provider, ShipMonk. The incident involved the exploitation of a zero-day SQL injection vulnerability in the Metabase business intelligence tool by the ShinyHunters extortion group. While Trezor hardware wallets remain secure, approximately 80,000+ customers have had sensitive shipping and order information exposed, highlighting a significant failure in third-party data retention policies.
## Incident Details
- **Discovery Date:** August 10, 2026
- **Incident Date:** August 2026 (ongoing disclosure of historical data)
- **Affected Organization:** ShipMonk (Logistics provider for Trezor)
- **Sector:** Cryptocurrency / E-commerce Logistics
- **Geography:** United States
## Timeline of Events
### Initial Access
- **Date/Time:** August 2026
- **Vector:** Zero-day exploitation of CVE-2026-72898.
- **Details:** Attackers exploited a critical SQL injection flaw (CVSS 10.0) in Metabase, an open-source business intelligence tool used by ShipMonk to manage data.
### Lateral Movement
- **Details:** Once the SQL injection was successful, attackers gained unauthorized access to ShipMonk’s internal database instances containing client order history.
### Data Exfiltration/Impact
- **Details:** The ShinyHunters group exfiltrated sensitive customer data. While Trezor believed data older than 90 days had been deleted per contract, ShipMonk had failed to purge the records.
- **Scope:** 67,000 U.S. customers (added to an initial 13,689 disclosed in August).
### Detection & Response
- **August 10, 2026:** ShipMonk notified Trezor of the unauthorized access.
- **Late August 2026:** Initial disclosure of ~13k affected customers.
- **September 5, 2026:** Trezor disclosed that an additional 67,000 customers from the 2019-2021 period were impacted due to ShipMonk's failure to delete data.
## Attack Methodology
- **Initial Access:** Zero-day exploitation (SQL Injection).
- **Persistence:** Not explicitly disclosed; likely database access via the web application vulnerability.
- **Privilege Escalation:** Exploitation of CVE-2026-72898 allowed for high-level database queries.
- **Discovery:** Reconnaissance of ShipMonk's data stack (Metabase).
- **Collection:** Gathering of Trezor eShop order history spanning 2019 to 2021.
- **Exfiltration:** Data theft by the ShinyHunters extortion gang.
- **Impact:** Financial extortion attempts against the organization and social engineering risks for customers.
## Impact Assessment
- **Financial:** Potential for extortion payments and costs related to incident response/notification.
- **Data Breach:** Exposure of Names, Email addresses, Phone numbers, Shipping addresses, and Order numbers.
- **Operational:** Disruption of shipping data management and trust breakdown between Trezor and ShipMonk.
- **Reputational:** High; Trezor customers are sensitive to privacy, and the failure of a partner to delete data as contracted reflects poorly on Trezor's supply chain oversight.
## Indicators of Compromise
- **Behavioral indicators:** Unusual SQL query patterns originating from the Metabase instance; unauthorized data egress to known extortion group infrastructure.
- **Vulnerability:** CVE-2026-72898 (Metabase SQL Injection).
## Response Actions
- **Containment:** ShipMonk secured affected systems and patched the Metabase zero-day.
- **Eradication:** Improved security posture and system hardening following the digital break-in.
- **Recovery:** Trezor initiated direct notification to all 80,000+ affected customers.
## Lessons Learned
- **Third-Party Compliance:** Written assurances of data deletion are insufficient without technical verification or independent audits.
- **Data Retention:** Retaining customer data longer than the necessary window (90 days in this case) significantly expands the "blast radius" of a breach.
- **Software Supply Chain:** Vulnerabilities in auxiliary tools (like Metabase) can lead to full compromise of sensitive customer databases.
## Recommendations
- **Audit Third Parties:** Implement periodic technical audits or "Right to Audit" clauses that include proof of data destruction.
- **Vulnerability Management:** Ensure rapid patching cycles for all internet-facing business intelligence and data management tools.
- **Customer Awareness:** Advise users to remain vigilant against targeted phishing ("whale-phishing") and physical security threats, as their home addresses are now linked to hardware wallet ownership.