Contained High impact Data breach Checked 12h ago

ShipMonk breach exposes data of 13,689 Trezor customers

An intruder accessed Trezor customer order data held by shipping provider ShipMonk. Trezor first said 13,689 customers in seven countries were exposed. On September 4, 2026, Trezor said the breach was much larger than first reported: ShipMonk had not deleted older order records as promised, and about 67,000 more US customers who ordered between November 2019 and August 2021 were also exposed. Trezor devices, systems, and funds remain unaffected. Earlier reporting tied the ShipMonk breach to a security flaw in Metabase, a data analytics tool (tracked as CVE-2026-72898), which also hit other companies including laptop maker Framework, plus Anaconda and n8n according to a September 7, 2026 report. ShipMonk itself has still not publicly acknowledged the incident.

Started
Aug 10, 2026
Latest activity
Sep 7, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United States, United Kingdom, Sweden, Colombia, Brazil, Italy, Portugal
Sectors
Technology, Consumers
Scale
One shipping provider, ShipMonk, and about 81,000 Trezor customers combined.

Current status

No new ShipMonk-specific update was found after September 8; a September 10 report described a separate Mathspace breach linked to the same Metabase flaw, while later Trezor reports concerned a separate email-provider phishing incident.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Impact

Full names, email addresses, phone numbers, and shipping addresses were exposed for 11,742 customers, and names, cities, and email addresses for another 1,947 customers, in the original disclosure. Trezor's September 4, 2026 update added about 67,000 more US customers with full exposure of name, email, phone number, shipping address, and order number, some from records dating back to 2019 that should have been deleted under a 90 day retention policy. The wider exposure raises the risk of targeted phishing scams and, because home addresses were included, physical safety risks for crypto holders.

What to do

Affected customers should distrust urgent messages, never share or enter their wallet backup online, and confirm claims through official Trezor channels. Anyone who did not receive an email from help@trezor.io is not affected.

Timeline

  1. Sep 10, 2026

    Information Age reported that Mathspace was a separate victim of the same Metabase vulnerability, with more than one million students, parents, teachers, and staff affected. The report did not connect Mathspace to the ShipMonk breach.

    Containedia.acs.org.au
  2. Sep 8, 2026

    Infosecurity Magazine reported that the total exposure reached about 81,000 customers. It said Trezor remains in contact with ShipMonk, which secured and hardened the affected systems. No new attack, additional victim group, attribution confirmation, or official closure was reported.

    Containedinfosecurity-magazine.com
  3. Sep 7, 2026

    A security analysis report identified the Metabase vulnerability behind the ShipMonk breach as CVE-2026-72898 and said it also hit Metabase Cloud tenants Anaconda and n8n in addition to Framework. It also noted ShipMonk has still not publicly acknowledged the breach.

    Containedtech.yahoo.com
  4. Sep 5, 2026

    The Hacker News reported that ShipMonk had secured the affected systems and that security firm Halborn linked the breach to ShinyHunters. Neither victim nor a government agency confirmed that attribution.

    Containedthehackernews.com
  5. Sep 4, 2026

    Trezor publicly disclosed that roughly 67,000 additional US customers were exposed, with full names, emails, phone numbers, shipping addresses, and order numbers, and emailed all newly affected customers directly.

    Activetrezor.io
  6. Sep 2, 2026

    ShipMonk informed Trezor that the data breach was larger than previously stated, including order data from their relationship between November 2019 and August 2021 that ShipMonk had assured Trezor was deleted.

    Activetrezor.io
  7. Aug 18, 2026

    A roundup report said the ShipMonk breach behind the Trezor data exposure was traced to a zero-day vulnerability in Metabase, a third-party analytics tool, the same flaw used in a separate breach at laptop maker Framework. Trezor's own systems and devices were confirmed not affected.

    Containedmemeburn.com
  8. Aug 14, 2026

    Trezor said the 1,947 customers with partial data exposure may include older orders and that it was checking the timeframe with ShipMonk.

    Containedtheregister.com
  9. Aug 13, 2026

    Trezor disclosed that 13,689 customers were affected and said ShipMonk had secured the affected systems.

    Containedtrezor.io
  10. Aug 10, 2026

    ShipMonk told Trezor that an unauthorized party had accessed systems containing customer order data.

    Emergingtrezor.io

Sources

Related reports