Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Reported exploitedShipMonkShinyHuntersMetabaseOur summary
Hardware wallet vendor Trezor has disclosed that the recent compromise of its shipping provider, ShipMonk, has affected an additional 67,000 U.S. customers, exposing personal details including names, contact information, and shipping addresses for orders placed between November 2019 and August 2021. This expansion follows a previous disclosure involving roughly 13,600 users and contradicts written assurances previously provided by ShipMonk stating that such data had been deleted per contractual agreements.
The intrusion stems from the active exploitation of CVE-2026-72898, a critical zero-day SQL injection vulnerability in Metabase, which allowed the ShinyHunters group to access customer records stored by the logistics firm. While Trezor confirmed that the security of its hardware wallets remains intact, the company warned customers to remain vigilant against targeted phishing campaigns and social engineering attacks leveraging the stolen information.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.