"Be aware of the increased risk of phishing," Trezor advised, warning that leaked customer details "could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks."
Scope: 81,000 customers and two distinct exposure windows
Trezor confirmed that an August data breach at its shipping and logistics provider, ShipMonk, now affects a total of 81,000 customers. The company first disclosed on August 13 that attackers accessed the data of nearly 14,000 customers who received orders between May 10 and August 8, 2026; on Friday it published an update saying an additional 67,000 U.S. customers were affected. Those 67,000 customers ordered between November 2019 and August 2021, and exposed fields included full name, email, phone number, shipping address, and order number, Trezor said.
ShipMonk's contractual deletion failure, according to Trezor
Trezor said the expanded impact resulted from ShipMonk's failure to delete the exposed data from its systems as required by Trezor's contract and data policy. "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," the company wrote. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."
Trezor also stated that the breach did not affect its own operations or services, that its systems were not compromised, and that all Trezor devices are secure.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleMetabase exploitation and an extortion link to ShinyHunters
While Trezor has not publicly described how ShipMonk's systems were breached, BleepingComputer reported that breach notification emails seen by the outlet said attackers exploited a vulnerability in the third‑party analytics platform Metabase. Metabase has revealed that threat actors exploited a critical SQL injection zero‑day vulnerability to breach customer instances, gain administrator access, and carry out data theft.
BleepingComputer also reported that ShipMonk has received extortion emails from the ShinyHunters extortion gang. The reporting places ShipMonk among multiple victims of the Metabase campaign; the list of affected companies includes online form platform Tally and laptop maker Framework, which similarly notified customers after their Metabase instances were hijacked.
Context from Trezor's prior breach disclosures
This is not Trezor's first disclosure about third‑party data exposure. In January 2024 the company disclosed a breach after threat actors compromised its third‑party support ticketing portal and accessed names, usernames, and email addresses from roughly 66,000 users. That previously stolen data was later used in phishing attacks attempting to steal recipients' 24‑word wallet recovery seeds, Trezor reported at the time.
What this means for technologists, affected customers, and logistics providers
- Technologists and security teams: Expect attackers who obtain names, emails, phones, and addresses to attempt highly targeted phishing and social‑engineering campaigns. The Metabase incident underlines how exploitation of a third‑party analytics platform can cascade to multiple customer organizations, according to the reporting.
- Affected customers: Trezor's explicit advice is to be wary of messages requesting personal information and to assume an increased phishing risk. The company warned the leaked data "could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks."
- Logistics and procurement leaders: Trezor's statement that it repeatedly received written assurances from ShipMonk — assurances that, per Trezor, did not correspond to actual deletion — spotlights contractual deletion obligations as a practical control that can fail in implementation.
Trezor's update leaves a narrow, concrete record: 81,000 customers affected, two separate exposure periods spanning 2019–2021 and May–August 2026, an attribution of the initial technical vector to a Metabase SQL injection exploit in reporting, and a claim that the expanded impact stems from a failure to delete data as contracted. The next steps to watch are whether ShipMonk or Metabase publish further technical details, whether any additional victims emerge from the same campaign, and how affected customers respond to the increased risk of targeted scams.




