14,000 Trezor Customers Impacted by Data Breach at ShipMonk
Trezor disclosed a data breach compromising nearly 14,000 customers' personal information, though the breach originated from third-party fulfillment provider ShipMonk, not Trezor's own systems Attackers exploited a SQL injection zero-day vulnerability in Metabase, an analytics platform used by ShipMonk, to access customer data including names, addresses, phone numbers, and email addresses The extortion group ShinyHunters claimed responsibility for the Metabase attack and leaked stolen data, thou
Analysis
TL;DR
- Trezor disclosed a data breach compromising nearly 14,000 customers' personal information, though the breach originated from third-party fulfillment provider ShipMonk, not Trezor's own systems
- Attackers exploited a SQL injection zero-day vulnerability in Metabase, an analytics platform used by ShipMonk, to access customer data including names, addresses, phone numbers, and email addresses
- The extortion group ShinyHunters claimed responsibility for the Metabase attack and leaked stolen data, though ShipMonk has not yet publicly acknowledged the incident
- Trezor's strict 90-day data storage policy limited the scope of exposure, though 1,947 customers with older orders may have had partial data compromised
- Affected customers are advised to remain vigilant against sophisticated phishing attempts leveraging their stolen personal information
Why It Matters
This incident highlights the critical risk of third-party supply chain vulnerabilities in the cybersecurity landscape, demonstrating how a single vendor's compromised infrastructure can expose customer data across multiple organizations. It also underscores the real-world consequences of unpatched SQL injection vulnerabilities in analytics platforms like Metabase, which are increasingly targeted by organized cybercrime groups.
Technical Details
- The breach was caused by exploitation of a SQL injection zero-day vulnerability in Metabase, a data analytics and business intelligence platform, which was patched by Metabase shortly before the incident came to light
- Attackers accessed customer records containing full names, phone numbers, email addresses, and shipping addresses for 11,742 customers, plus partial data (names, cities, emails) for an additional 1,947 customers
- Trezor's data retention policy limited exposure to orders placed between May 10 and August 8, as the company enforces a 90-day data storage policy that was also negotiated with fulfillment partners
- The attack was attributed to the ShinyHunters extortion group, which publicly claimed responsibility and leaked stolen data from Metabase, indicating a coordinated campaign against organizations using the platform
- Trezor's own systems and hardware devices were not compromised; the breach was isolated to customer data shared with ShipMonk for order fulfillment purposes
Industry Insight
- Organizations must conduct rigorous third-party risk assessments and ensure vendors implement equivalent data security and retention policies, as supply chain exposure can undermine even strong internal security postures
- The targeting of Metabase by ShinyHunters suggests analytics platforms are becoming high-value targets for cybercriminals, prompting the need for proactive vulnerability management and timely patch deployment across all software dependencies
- Companies should prepare incident response playbooks that account for third-party breaches, including clear communication strategies, customer notification protocols, and phishing awareness campaigns to mitigate secondary attack vectors
Disclaimer: The above content is generated by AI and is for reference only.