Trezor ShipMonk Breach Exposes 67,000 U.S. Customer Records via Metabase Zero-Day Vulnerability (CVE-2026-72898)

Trezor ShipMonk Breach Exposes 67,000 U.S. Customer Records via Metabase Zero-Day Vulnerability (CVE-2026-72898)

Executive Summary

On September 4, 2026, Trezor disclosed that a breach at its third-party logistics provider, ShipMonk, exposed sensitive order data for approximately 67,000 U.S. customers from November 2019 through August 2021. This incident follows an earlier disclosure in August 2026, which affected 13,689 customers. The compromised data includes names, email addresses, phone numbers, shipping addresses, and order numbers. No wallet seeds, private keys, or funds were exposed, and Trezor’s own systems remain uncompromised. The breach was enabled by exploitation of a critical zero-day SQL injection vulnerability (CVE-2026-72898, CVSS 10.0) in the Metabase analytics platform used by ShipMonk. The attack is attributed to the ShinyHunters extortion group. The exposed data increases the risk of phishing, social engineering, and potential physical targeting of affected customers. Trezor has directly notified all impacted individuals and continues to advise vigilance against scams. This incident highlights the importance of third-party risk management and the limitations of data deletion policies without verification.

Technical Information

The breach at ShipMonk was the result of a sophisticated supply chain attack exploiting a zero-day SQL injection vulnerability (CVE-2026-72898, CVSS 10.0) in the Metabase analytics platform. Attackers leveraged this flaw to create administrator-level sessions, enabling bulk downloads of sensitive customer data stored within Metabase. The attack is mapped to MITRE ATT&CK techniques T1190 (Exploit Public-Facing Application) and T1005 (Data from Local System), with possible use of T1078 (Valid Accounts) if admin session creation was abused for further access.

The compromised data set includes full names, email addresses, phone numbers, shipping addresses, and order numbers for approximately 67,000 U.S. customers, in addition to the 13,689 customers previously disclosed. The breach did not impact Trezor’s wallet systems, and no cryptographic secrets or funds were exposed. However, the exposure of physical addresses and purchase history creates significant risks for targeted phishing, social engineering, and potential physical threats.

Attribution for the attack has been assigned to the ShinyHunters extortion gang, based on reporting from enterprise blockchain security firm Holborn. While this attribution is consistent with ShinyHunters’ historical targeting of SaaS, e-commerce, and supply chain providers, it is based on pattern analysis and third-party reporting rather than direct technical evidence.

The incident underscores the criticality of robust third-party risk management, particularly for organizations handling sensitive customer data. Trezor’s reliance on written assurances of data deletion from ShipMonk proved insufficient, as years-old records remained accessible and were ultimately exfiltrated. This highlights the limitations of contractual data deletion policies without technical verification or audit.

ShipMonk has reportedly secured the affected systems and implemented additional security measures following the breach. As of the latest reporting, ShipMonk has not issued a public statement regarding the incident.

Affected Versions & Timeline

The breach affected Trezor customers whose orders were fulfilled by ShipMonk between November 2019 and August 2021. The initial notification to Trezor occurred on August 10, 2026, with public disclosure on August 13, 2026, covering 13,689 customers. On September 2, 2026, Trezor was informed that the breach was significantly larger, involving an additional 67,000 U.S. customers. Public updates and media coverage followed on September 4–5, 2026.

The vulnerability exploited was CVE-2026-72898, a critical SQL injection flaw in Metabase. The attack window is not precisely defined in public sources, but the data exposed spans orders from November 2019 through August 2021.

Threat Activity

The threat actor, identified as the ShinyHunters extortion gang, exploited a zero-day vulnerability in Metabase to gain unauthorized access to ShipMonk’s systems. By creating administrator-level sessions, the attackers were able to perform bulk downloads of customer data tables. The attack did not involve deployment of malware or commodity tools; instead, it relied on direct exploitation of a software vulnerability.

The primary risk to affected customers is increased exposure to phishing, social engineering, and potential physical targeting. The attackers now possess data that links individuals to cryptocurrency hardware wallet purchases, including physical addresses. While no downstream attacks have been publicly confirmed as of the latest updates, the risk profile for affected individuals is significantly elevated.

The breach demonstrates a common pattern in recent supply chain attacks, where third-party service providers become the weak link in otherwise secure environments. The incident also illustrates the challenges of enforcing data deletion policies and the need for technical validation of compliance.

Mitigation & Workarounds

The following mitigation and response actions are prioritized by severity:

Critical: Organizations using Metabase or similar analytics platforms should immediately review their exposure to CVE-2026-72898 and apply all available patches or mitigations. Technical validation of data deletion and retention policies with third-party vendors is essential to prevent similar incidents.

High: All organizations handling sensitive customer data through third-party providers should conduct comprehensive third-party risk assessments, including technical audits of data retention and deletion practices. Customers affected by this breach should be vigilant for phishing emails, fraudulent calls, and social engineering attempts leveraging the exposed data.

Medium: Security awareness training for staff and customers should be updated to reflect the increased risk of targeted phishing and impersonation attacks. Organizations should review and update incident response plans to address supply chain and third-party breaches.

Low: Regularly monitor public disclosures and threat intelligence sources for updates on the ShinyHunters group and related supply chain attack patterns.

Indicators of Compromise

The following indicators are provided as a point-in-time reference and should be validated before enforcement in production environments.

Type

Indicator

Reported (date)

Source

 

Domain

cryptoslate[.]com

2026-09-05

https://cryptoslate.com/users-exposed-by-trezor-breach-grows-sixfold-after-supposedly-deleted-shipping-logs-are-found/

Domain

trezor[.]io

2026-09-04

https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident?srsltid=AfmBOopoBysb50Bf0n7OLbW8vZu1IYePxm5tMjIb7Jciz4Q2p52wkFhq

URL

hxxps://cryptoslate[.]com/users-exposed-by-trezor-breach-grows-sixfold-after-supposedly-deleted-shipping-logs-are-found/

2026-09-05

https://cryptoslate.com/users-exposed-by-trezor-breach-grows-sixfold-after-supposedly-deleted-shipping-logs-are-found/

URL

hxxps://trezor[.]io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident?srsltid=AfmBOopoBysb50Bf0n7OLbW8vZu1IYePxm5tMjIb7Jciz4Q2p52wkFhq

2026-09-04

https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident?srsltid=AfmBOopoBysb50Bf0n7OLbW8vZu1IYePxm5tMjIb7Jciz4Q2p52wkFhq

References

Trezor Official Blog: https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident?srsltid=AfmBOopoBysb50Bf0n7OLbW8vZu1IYePxm5tMjIb7Jciz4Q2p52wkFhq

The Hacker News: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html

CryptoSlate: https://cryptoslate.com/users-exposed-by-trezor-breach-grows-sixfold-after-supposedly-deleted-shipping-logs-are-found/

About Rescana

Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organizations identify, assess, and monitor risks associated with their vendors and supply chain partners. Our platform enables continuous visibility into third-party exposures, supports technical validation of vendor data handling practices, and facilitates rapid response to supply chain incidents. For more information or to discuss your organization’s third-party risk posture, contact us at info@rescana.com.