Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, exposed the personal information of an additional 67,000 customers in the United States.
The newly disclosed victims bring the total number of affected Trezor customers to approximately 81,000. Trezor initially disclosed the breach on August 13, stating that attackers had accessed customer names, shipping addresses, email addresses, and phone numbers for about 14,000 people.
The incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who placed Trezor orders between May 10 and August 8, 2026.
ShipMonk published an update Friday confirming the expanded scope of the data breach. The company reportedly failed to delete Trezor customer information from its systems as required under Trezor’s contract and data retention policy.
“An additional 67,000 customers in the United States who placed orders between November 2019 and August 2021 were affected, and their details—including names, email addresses, phone numbers, shipping addresses, and order numbers—were exposed,” Trezor said.
“Throughout our relationship with ShipMonk, we repeatedly requested and received written assurances confirming the deletion of our data in accordance with our contract, data policy, and past communications. We are extremely disappointed that, despite receiving this confirmation, our data was not deleted from their systems.”
Trezor said the breach did not affect its operations or services, and that its own systems were not compromised. The company also confirmed that all Trezor hardware wallet devices remain secure.
However, Trezor warned affected customers to be alert for phishing scams and other fraudulent messages seeking personal or cryptocurrency-related information.
“Be aware of the increased risk of phishing. Leaked information could be used in fraudulent emails, fraudulent phone calls or letters, and could expose affected individuals to physical security risks,” Trezor said.
ShipMonk breach linked to Metabase campaign and ShinyHunters extortion attempts
ShipMonk has not disclosed exactly how its systems were compromised. However, a breach notification email sent to affected customers and reviewed by BleepingComputer said attackers exploited a vulnerability in the third-party analytics platform Metabase.
Metabase previously revealed that attackers had exploited a critical SQL injection zero-day vulnerability to compromise customer instances. The attackers gained administrative access to affected environments and used that access to steal data.
BleepingComputer also learned that ShipMonk has received extortion emails from the ShinyHunters cybercrime group.
Other organizations reportedly affected by the Metabase campaign include online form creation platform Tally and laptop manufacturer Framework. Both companies notified customers after their Metabase instances were compromised.
Trezor disclosed another third-party data breach in January 2024 after threat actors compromised a customer support ticket portal. That incident exposed information belonging to approximately 66,000 users, including names, usernames, and email addresses.
The stolen information was later used in a phishing campaign designed to trick recipients into revealing their 24-word cryptocurrency wallet recovery seeds.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



