Hardware cryptocurrency wallet manufacturer Trezor disclosed a data breach on Wednesday affecting nearly 14,000 customers after its shipping provider ShipMonk was compromised through a zero-day vulnerability in the Metabase analytics platform.
The breach exposed full names, email addresses, phone numbers, and shipping addresses of 11,742 customers, while an additional 1,947 customers had partial data including name, city, and email exposed. Affected customers span seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, and all placed orders between May 10 and August 8, 2026.
Trezor said the attack originated when ShipMonk informed the company on August 10 that unauthorized actors had accessed systems containing customer order data. ShipMonk subsequently told affected customers that the breach resulted from a critical SQL injection zero-day in Metabase, a widely used open-source business intelligence tool.
“On August 6, 2026, Metabase informed us that an unauthorized party exploited a vulnerability in Metabase’s software to access data related to your account and your customers,” ShipMonk said in breach notification emails. The vulnerability, since patched by Metabase with all active sessions invalidated, allowed attackers to gain administrator-level access to compromised instances and carry out data theft.
The same Metabase zero-day has been linked to additional breaches at laptop maker Framework and online form builder Tally, making it a widespread supply chain attack vector. ShipMonk has also reportedly received extortion emails from the ShinyHunters gang, a well-known threat actor group that has previously been involved in major data breaches and operates data leak sites.
Trezor emphasized that its own systems, operations, and devices were not compromised in the incident. However, the company warned that affected customers now face significantly elevated phishing risks. Attackers with access to shipping data for hardware wallet buyers can craft highly targeted social engineering campaigns impersonating banks, crypto exchanges, or Trezor itself.
The incident marks Trezor’s second major data breach involving third-party systems. In January 2024, the company disclosed that 66,000 users had their names, usernames, and email addresses exposed through a separate breach of its support ticketing portal, which was subsequently used to launch phishing attacks targeting wallet recovery seeds.
Sources: BleepingComputer, SecurityWeek, Trezor Blog
discussion