ShipMonk breach exposes data of 13,689 Trezor customers
An intruder accessed Trezor customer order data held by shipping provider ShipMonk. Trezor first said 13,689 customers in seven countries were exposed. On September 4, 2026, Trezor said the breach was much larger than first reported: ShipMonk had not deleted older order records as promised, and about 67,000 more US customers who ordered between November 2019 and August 2021 were also exposed. Trezor devices, systems, and funds remain unaffected. Earlier reporting tied the ShipMonk breach to a security flaw in Metabase, a data analytics tool (tracked as CVE-2026-72898), which also hit other companies including laptop maker Framework, plus Anaconda and n8n according to a September 7, 2026 report. ShipMonk itself has still not publicly acknowledged the incident.
- Started
- Aug 10, 2026
- Latest activity
- Sep 7, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- United States, United Kingdom, Sweden, Colombia, Brazil, Italy, Portugal
- Sectors
- Technology, Consumers
- Scale
- One shipping provider, ShipMonk, and about 81,000 Trezor customers combined.
Current status
No new ShipMonk-specific update was found after September 8; a September 10 report described a separate Mathspace breach linked to the same Metabase flaw, while later Trezor reports concerned a separate email-provider phishing incident.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Impact
Full names, email addresses, phone numbers, and shipping addresses were exposed for 11,742 customers, and names, cities, and email addresses for another 1,947 customers, in the original disclosure. Trezor's September 4, 2026 update added about 67,000 more US customers with full exposure of name, email, phone number, shipping address, and order number, some from records dating back to 2019 that should have been deleted under a 90 day retention policy. The wider exposure raises the risk of targeted phishing scams and, because home addresses were included, physical safety risks for crypto holders.
What to do
Affected customers should distrust urgent messages, never share or enter their wallet backup online, and confirm claims through official Trezor channels. Anyone who did not receive an email from help@trezor.io is not affected.
Timeline
-
Sep 10, 2026
Information Age reported that Mathspace was a separate victim of the same Metabase vulnerability, with more than one million students, parents, teachers, and staff affected. The report did not connect Mathspace to the ShipMonk breach.
Containedia.acs.org.au -
Sep 8, 2026
Infosecurity Magazine reported that the total exposure reached about 81,000 customers. It said Trezor remains in contact with ShipMonk, which secured and hardened the affected systems. No new attack, additional victim group, attribution confirmation, or official closure was reported.
Containedinfosecurity-magazine.com -
Sep 7, 2026
A security analysis report identified the Metabase vulnerability behind the ShipMonk breach as CVE-2026-72898 and said it also hit Metabase Cloud tenants Anaconda and n8n in addition to Framework. It also noted ShipMonk has still not publicly acknowledged the breach.
Containedtech.yahoo.com -
Sep 5, 2026
The Hacker News reported that ShipMonk had secured the affected systems and that security firm Halborn linked the breach to ShinyHunters. Neither victim nor a government agency confirmed that attribution.
Containedthehackernews.com -
Sep 4, 2026
Trezor publicly disclosed that roughly 67,000 additional US customers were exposed, with full names, emails, phone numbers, shipping addresses, and order numbers, and emailed all newly affected customers directly.
Activetrezor.io -
Sep 2, 2026
ShipMonk informed Trezor that the data breach was larger than previously stated, including order data from their relationship between November 2019 and August 2021 that ShipMonk had assured Trezor was deleted.
Activetrezor.io -
Aug 18, 2026
A roundup report said the ShipMonk breach behind the Trezor data exposure was traced to a zero-day vulnerability in Metabase, a third-party analytics tool, the same flaw used in a separate breach at laptop maker Framework. Trezor's own systems and devices were confirmed not affected.
Containedmemeburn.com -
Aug 14, 2026
Trezor said the 1,947 customers with partial data exposure may include older orders and that it was checking the timeframe with ShipMonk.
Containedtheregister.com -
Aug 13, 2026
Trezor disclosed that 13,689 customers were affected and said ShipMonk had secured the affected systems.
Containedtrezor.io -
Aug 10, 2026
ShipMonk told Trezor that an unauthorized party had accessed systems containing customer order data.
Emergingtrezor.io
Sources
- Recent customer data exposed in shipping provider incident Trezor Aug 13, 2026
- We have some difficult news to share Trezor on X Aug 13, 2026
- Trezor Customer Data Exposed in Shipping Partner Breach Decrypt Aug 13, 2026
- Third-party breach exposes shipping addresses of 14,000 Trezor buyers CoinDesk Aug 13, 2026
- Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers Cyber Security News Aug 13, 2026
- Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach The Register Aug 14, 2026
- Every Hardware Wallet Breach of 2026 and Why They Are Not the Same Thing Memeburn Aug 18, 2026
- Crypto industry hit by 3 hacks in 15 days Yahoo Finance Aug 19, 2026
- Framework Laptop Discloses Data Breach Affecting 18,000 Customers via Metabase Zero-Day WebProNews Aug 10, 2026
- 67,000 More Trezor Customers Exposed as Data Breach Widens Yahoo Tech / Decrypt Sep 4, 2026
- Trezor says ShipMonk breach affected another 67,000 customers The Block Sep 4, 2026 unverified
- Trezor says data breach affects another 67K US customers Cointelegraph Sep 4, 2026
- Trezor data breach expands to over 80,000 customers after ShipMonk kept old records AMBCrypto Sep 4, 2026
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted The Hacker News Sep 5, 2026
- Trezor's Supply Chain Cracked Through ShipMonk's Unpatched Metabase: 67,000 Crypto Customers Exposed Yahoo Tech Sep 7, 2026
- Crypto Hardware Wallet Maker Trezor Reports 67K Additional US Customers Impacted in ShipMonk Data Breach Crowdfund Insider Sep 7, 2026
- Trezor Supply Chain Breach Now Impacts 81,000 Customers Infosecurity Magazine Sep 8, 2026
- More than 1m caught in Mathspace data breach Information Age Sep 10, 2026
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach BleepingComputer Sep 11, 2026
Related reports
- ShipMonk breach exposed 81,000 Trezor customers Sep 7, 2026
- Trezor breach via ShipMonk hits 80,000 customers Sep 4, 2026
- Trezor customers' personal data leaked in ShipMonk breach Aug 13, 2026
- Trezor shipping partner leaks 14,000 customer details Aug 11, 2026
- Trezor shipping breach leaks customer data Jul 31, 2026