Trezor, a cryptocurrency hardware wallet maker, has announced that a data breach at its shipping and logistics provider, ShipMonk, now affects approximately 81,000 customers. The company initially disclosed in August that attackers had accessed the data of nearly 14,000 customers, including full names, shipping addresses, email addresses, and phone numbers. That earlier incident impacted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who placed orders between May 10 and August 8, 2026.
In a new update published Friday, Trezor confirmed that the breach’s scope has expanded because ShipMonk failed to delete exposed data from its systems, a requirement under their contract and data policy. An additional 67,000 U.S. customers who ordered between November 2019 and August 2021 had their full details - including name, email, phone number, shipping address, and order number - exposed. Trezor stated that it had repeatedly requested and received written assurance from ShipMonk confirming the deletion of the data throughout their relationship, and expressed disappointment that the data was not removed despite those confirmations.
Trezor emphasized that the breach did not compromise its own systems or affect its operations, adding that all Trezor devices remain secure. The company has not yet disclosed how ShipMonk’s systems were compromised, but breach notification emails sent to affected customers and seen by BleepingComputer indicate that attackers exploited a vulnerability in the third-party analytics platform Metabase. Metabase previously revealed that threat actors used a critical SQL injection zero-day vulnerability to gain administrator access to customer instances and steal data.
BleepingComputer also reported that ShipMonk received extortion emails from the ShinyHunters extortion gang. Other companies affected by the same Metabase campaign include online form-building platform Tally and laptop maker Framework, both of which have notified customers of data breaches following the hijacking of their instances. Trezor has warned affected customers to be cautious of unsolicited messages requesting personal information, noting that the leaked data could be used in phishing scams, fraudulent calls, or letters, and could potentially create physical security risks.
This is not the first time Trezor has faced a data exposure tied to a third-party provider. In January 2024, the company disclosed a separate breach in which attackers compromised its support ticketing portal, accessing data such as names, usernames, and email addresses from roughly 66,000 users. That stolen information was later used in phishing attacks that attempted to steal recipients’ 24-word wallet recovery seeds. The company’s latest advisory urges affected U.S. customers, who represent the bulk of the newly disclosed victims, to remain alert to phishing attempts that may exploit their exposed personal details.
More cybersecurity news from TechManNews.






