Skip to main content
Emerging ThreatsData Breaches

Trezor Breach Exposes 67,000 US Customers' Data

Rows of shelving and boxes in a warehouse with a shipping label in focus.

67,000 U.S. customers had personal data exposed after a breach at Trezor’s shipping provider, ShipMonk, the hardware wallet maker disclosed — and the incident traces to a zero-day SQL injection in Metabase, CVE-2026-72898.

Scope of the exposure: names, emails, phones, addresses and order numbers

Trezor reported that ShipMonk’s breach affected another 67,000 customers in the United States, expanding an earlier disclosure. The exposed fields include customer names, email addresses, phone numbers, shipping addresses, and order numbers for purchases placed between November 2019 and August 2021. Trezor said the breach does not affect the security of the company's hardware wallets.

This exposure is in addition to 13,689 customers the company disclosed the month before as having had their data either fully or partially exposed. Trezor said that 1,947 customers previously reported with exposure limited to names, cities, and email addresses (excluding shipping addresses) may include older orders.

CVE-2026-72898: a Metabase zero-day and SQL injection with a 10.0 CVSS score

According to the account Trezor shared, ShipMonk’s systems were accessed following exploitation of a zero-day vulnerability identified as CVE-2026-72898 — a critical SQL injection flaw in Metabase with a CVSS score of 10.0. The source states ShipMonk secured the affected systems and “improved its security” after the digital break-in.

Enterprise blockchain security firm Holborn attributed the attack to an exploitation chain that began with that zero-day flaw. Holborn said the attackers were able to access several Metabase customers by exploiting the SQL injection, stealing sensitive data and extorting the organization.

Trezor’s deletion policy, ShipMonk assurances, and the notification timeline

Trezor said ShipMonk informed the company of the breach on August 10, 2026, after unauthorized access to ShipMonk systems. In a direct statement Trezor wrote, “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.”

Trezor described a 90-day retention rule for purchase-related customer data on its eShop: “After 90 days we delete or anonymize all customer data related to a purchase on our Trezor eShop. We chose 90 days because it is the shortest window that still covers the whole life of an order — delivery, returns, and any refund or replacement. After that we have no reason to keep your address or phone number.”

Despite ShipMonk’s written assurances, Trezor said the data was not deleted in ShipMonk’s systems. Trezor said it has notified affected customers directly.

Customer risk: phishing, fraudulent calls, letters and potential physical-security concerns

Trezor warned customers to watch for social engineering and scams that could exploit the leaked details. “The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks,” the company said.

The company advised vigilance because exposed emails, phone numbers and addresses can be used to tailor phishing campaigns, impersonations, or fraudulent communications that persuade targets into taking unintended actions.

Holborn’s view and what the breach signals for third-party risk

Holborn characterized the incident as a software supply chain attack that began with the Metabase zero-day. “By finding and exploiting the SQL injection flaw in Metabase, the attackers were able to exploit several of its customers, stealing sensitive data and extorting the organization,” Holborn said. In Trezor’s case, Holborn added, that meant exposure of customer order details that had been stored in a Metabase instance by ShipMonk.

ShipMonk itself has yet to acknowledge the incident publicly, according to Trezor’s disclosure.

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams: expect renewed focus on third‑party software instances (the Metabase instance in this case) and on validating deletion and retention controls in downstream vendors, since Trezor says written deletion assurances were not reflected in ShipMonk’s systems.
  • Procurement and vendor-risk teams: will face pressure to obtain verifiable deletion proof and to insist on visibility into how vendors store and purge customer data, given the contrast between contractual assurances and the outcome described by Trezor.
  • End users and customers: should monitor communications closely for phishing, impersonation attempts, or fraudulent contact, and follow any direct notifications from Trezor about mitigation steps.

The episode closes on two concrete questions the record in Trezor’s disclosure leaves open: why the written assurances from ShipMonk did not translate into deleted data, and whether the Metabase instances used by other vendors remain similarly exposed. Holborn’s attribution to an extortion gang using a zero-day SQL injection underscores the single‑vulnerability path through which data in third-party systems can be exposed — and it leaves procurement, security teams and customers watching for the answers.

Original story