logo

Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers

ID: 7ac84666-6e10-53bb-b8a5-03ad8fa327fc

STIX ID: report--7ac84666-6e10-53bb-b8a5-03ad8fa327fc

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-09-04

Date Updated: 2026-09-16

Author: Guru Baran

...
...

Trezor disclosed that a ShipMonk data breach — caused by exploitation of a critical SQL injection zero‑day in Metabase — exposed order records spanning 2019–2026, increasing the impacted customer count to over 80,000. Exposed fields include names, emails, phone numbers, shipping addresses and order numbers; Trezor systems and wallet backups were not compromised, but attackers can use the PII for phishing and physical‑security attacks. Affected customers were notified and Trezor plans shipment privacy mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.