Executive Summary
On August 13, 2026, Trezor disclosed that nearly 14,000 of its customers were impacted by a data breach at its shipping and logistics provider, ShipMonk. The breach resulted in the exposure of sensitive customer data, including full names, shipping addresses, phone numbers, and email addresses. The incident was traced to the exploitation of a critical SQL injection vulnerability in the third-party analytics platform Metabase, used by ShipMonk. While no compromise of Trezor devices or internal systems occurred, the breach significantly increases the risk of phishing and social engineering attacks targeting affected customers. The breach is notable as the first in Trezor’s history to expose both customer phone numbers and shipping addresses. All affected customers have been notified directly by email, and the incident underscores the risks associated with third-party service providers in the cryptocurrency sector.
Technical Information
The breach originated from ShipMonk, a third-party logistics provider for Trezor, following the exploitation of a critical SQL injection zero-day vulnerability in the Metabase analytics platform. Attackers leveraged this vulnerability to gain administrator access to ShipMonk’s Metabase instance, enabling the exfiltration of customer order data. The attack chain began with the exploitation of the public-facing application, escalated privileges to administrator level, and culminated in the theft of sensitive customer information. Following the breach, the ShinyHunters extortion group sent extortion emails to ShipMonk.
The technical attack chain is mapped to the following MITRE ATT&CK techniques: Initial Access via Exploit Public-Facing Application (T1190), Privilege Escalation via Exploitation for Privilege Escalation (T1068), Collection via Data from Information Repositories (T1213), Exfiltration Over Web Service (T1567), and Impact via Extortion (T1657). The evidence for the attack vector and techniques is of high confidence, corroborated by Trezor’s official disclosure, ShipMonk’s notification, and independent reporting by BleepingComputer and CoinDesk.
No malware was reported as part of this incident; the breach was achieved solely through vulnerability exploitation. The ShinyHunters group, known for targeting SaaS and fintech companies, was identified as the actor behind the extortion phase, though technical artifacts confirming attribution are not publicly available.
The breach highlights the increasing trend of supply chain attacks in the cryptocurrency and fintech sectors, where attackers target third-party providers to access sensitive data. The exposure of customer personally identifiable information (PII) such as names, emails, phone numbers, and shipping addresses elevates the risk of targeted phishing, impersonation, and social engineering attacks. Trezor’s 90-day data retention policy limited the scope of the breach, but some older orders with partial data exposure were also affected.
Affected Versions & Timeline
The breach affects customers who received orders from Trezor via ShipMonk between May 10 and August 8, 2026, in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Specifically, 11,742 customers had full exposure (name, email, phone number, shipping address), and 1,947 customers had partial exposure (name, city, email address). The incident was first detected when ShipMonk informed Trezor of unauthorized access on August 10, 2026. The vulnerability in Metabase was exploited on or before August 6, 2026, as confirmed by Metabase’s own notification to ShipMonk. All affected customers were notified by email, and those who did not receive a notification were not impacted. Orders fulfilled through Amazon were not affected, as they were handled by a separate partner.
Threat Activity
The threat actor identified in the extortion phase is the ShinyHunters group, a cybercriminal organization active since at least 2020 and known for data breaches and extortion campaigns. Their tactics typically involve exploiting web application vulnerabilities, stealing large datasets, and issuing extortion demands. In this incident, ShinyHunters exploited a critical SQL injection vulnerability in Metabase to gain administrator access and exfiltrate customer data from ShipMonk’s systems. Following the breach, ShipMonk received extortion emails from the group. There is no evidence at this time that the stolen data has been published, shared, or offered for sale, nor have there been confirmed cases of scams or hacks linked to the incident. However, the risk of phishing and impersonation attacks against affected customers remains high.
Mitigation & Workarounds
The following mitigation steps are recommended, prioritized by severity:
Critical: All affected customers should be vigilant for phishing attempts via email, phone, or postal mail. Any suspicious communications purporting to be from Trezor, banks, or cryptocurrency exchanges should be treated with caution, and verification should be sought through official channels.
High: Organizations using third-party analytics platforms such as Metabase should immediately review their exposure to known vulnerabilities, apply all available security patches, and restrict administrative access to essential personnel only. Regular vulnerability assessments and penetration testing of public-facing applications are essential to prevent similar exploitation.
Medium: Review and enforce strict data retention policies with all third-party service providers to minimize the amount of customer data at risk in the event of a breach. Ensure that contractual agreements with vendors include clear security requirements and incident notification procedures.
Low: Educate customers and staff about the risks of social engineering and phishing, providing guidance on how to recognize and report suspicious activity. Consider implementing additional verification steps for customer support interactions involving sensitive information.
Indicators of Compromise
Indicators of compromise are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.
References
Trezor Official Disclosure (Aug 13, 2026): https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident?srsltid=AfmBOoq0wvdvOL844nuX5-lUFXUi9y9qWoLubLlezHhoTWn476oB3CdN
BleepingComputer (Aug 13, 2026): https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/
CoinDesk (Aug 13, 2026): https://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach
About Rescana
Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor risks associated with vendors and supply chain partners. Our platform enables continuous monitoring of third-party security posture, supports evidence-based risk assessments, and facilitates rapid response to emerging threats. For questions regarding this incident or to discuss how our capabilities can support your organization’s risk management strategy, please contact us at info@rescana.com.


