AI Security AI安全 6h ago Updated 1h ago 更新于 1小时前 41

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted Trezor称ShipMonk数据泄露导致6.7万美国客户数据曝光,这些数据此前称已被删除

Trezor disclosed that a breach at its shipping provider ShipMonk exposed 67,000 U.S. customers' personal data, including names, emails, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021. ShipMonk had previously provided written assurances that customer data was deleted per contract and data policy, but the data remained in their systems despite those confirmations. The breach was caused by the exploitation of CVE-2026-72898, a critical SQL injection zero-day Trezor通过物流商ShipMonk泄露事件,67,000名美国客户数据遭泄露,包括姓名、邮箱、电话、地址和订单号(2019年11月至2021年8月) 攻击者利用Metabase零日漏洞CVE-2026-72898(CVSS 10.0)实施SQL注入,ShinyHunters勒索团伙涉嫌作案 Trezor此前已收到ShipMonk关于数据删除的书面保证,但数据未被删除,违反合同和数据政策 这是典型的供应链攻击案例,攻击者通过单一漏洞影响了ShipMonk的多个客户 Trezor强调硬件钱包本身未受影响,但警告用户需警惕利用泄露信息进行的钓鱼诈骗和社会工程学攻击

62
Hot 热度
58
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • Trezor disclosed that a breach at its shipping provider ShipMonk exposed 67,000 U.S. customers' personal data, including names, emails, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021.
  • ShipMonk had previously provided written assurances that customer data was deleted per contract and data policy, but the data remained in their systems despite those confirmations.
  • The breach was caused by the exploitation of CVE-2026-72898, a critical SQL injection zero-day vulnerability in Metabase (CVSS score: 10.0), attributed to the ShinyHunters extortion gang.
  • The exposure is in addition to 13,689 customers disclosed in a prior breach, bringing the total affected to approximately 80,689 customers.
  • Trezor emphasized that its hardware wallets remain secure, but warned affected users about potential social engineering, phishing, and physical security risks stemming from the leaked data.

Why It Matters

This incident underscores the critical importance of third-party and supply chain risk management in cybersecurity. Organizations relying on external logistics and data processing partners must enforce contractual data deletion obligations and validate compliance through independent audits rather than accepting assurances at face value. The breach also highlights how a single unpatched vulnerability in a widely used analytics platform like Metabase can cascade across multiple customer organizations.

Technical Details

  • The attack vector was CVE-2026-72898, a critical SQL injection zero-day flaw in Metabase (CVSS 10.0), which ShipMonk exploited to gain unauthorized access to its systems and the stored customer data of its clients, including Trezor.
  • The exposed dataset spans over 21 months (November 2019 to August 2021) and includes highly sensitive personally identifiable information (PII): full names, email addresses, phone numbers, shipping addresses, and order numbers.
  • Trezor operates a 90-day data retention policy for its eShop, after which customer data is supposed to be deleted or anonymized, covering the full order lifecycle including delivery, returns, and refunds.
  • ShipMonk failed to honor its contractual and policy obligations to delete this data, retaining it despite repeated written confirmations provided to Trezor.
  • The breach was carried out by the ShinyHunters extortion gang, which typically targets organizations through supply chain vulnerabilities to steal data and demand ransom.

Industry Insight

  • Organizations must treat third-party data handling relationships as a security extension of their own infrastructure; contractual clauses and written assurances are insufficient without continuous verification and audit mechanisms.
  • The Metabase SQL injection vulnerability demonstrates the compounding risk of widely deployed analytics tools across multiple enterprises—patching and vulnerability monitoring for third-party software should be treated as a critical security priority.
  • Companies should proactively communicate breach details to affected customers with specific guidance on social engineering threats, as leaked PII is frequently weaponized for targeted phishing and physical security threats well after the initial incident.

TL;DR

  • Trezor通过物流商ShipMonk泄露事件,67,000名美国客户数据遭泄露,包括姓名、邮箱、电话、地址和订单号(2019年11月至2021年8月)
  • 攻击者利用Metabase零日漏洞CVE-2026-72898(CVSS 10.0)实施SQL注入,ShinyHunters勒索团伙涉嫌作案
  • Trezor此前已收到ShipMonk关于数据删除的书面保证,但数据未被删除,违反合同和数据政策
  • 这是典型的供应链攻击案例,攻击者通过单一漏洞影响了ShipMonk的多个客户
  • Trezor强调硬件钱包本身未受影响,但警告用户需警惕利用泄露信息进行的钓鱼诈骗和社会工程学攻击

为什么值得看

本文揭示了供应链安全风险的严重性——即使核心产品安全,第三方依赖也可能成为数据泄露的突破口。对于AI从业者而言,这提醒我们在构建系统时需严格审查第三方服务商的安全实践,并建立完整的数据生命周期管理机制。

技术解析

  • 漏洞利用:攻击者利用Metabase的零日SQL注入漏洞CVE-2026-72898(CVSS评分10.0),通过该漏洞获取ShipMonk系统访问权限,进而窃取存储在其上的客户数据
  • 数据泄露范围:67,000名美国客户数据受影响,包括姓名、邮箱、电话、 shipping地址和订单号;另有1,947名客户仅姓名、城市和邮箱泄露,可能涉及更早订单
  • 供应链攻击路径:攻击者首先利用Metabase漏洞入侵ShipMonk系统,再通过ShipMonk访问Trezor存储在其中的客户订单数据,形成典型的供应链攻击链
  • 数据保留策略缺陷:Trezor声称90天后会删除或匿名化客户数据,但ShipMonk未按合同要求删除数据,且提供了虚假的删除确认
  • 攻击者身份:Holborn安全公司指出ShinyHunters勒索团伙涉嫌作案,该团伙以数据窃取和勒索著称

行业启示

  • 供应链安全审计必须常态化:企业不能仅依赖供应商的安全承诺,需建立独立的第三方安全评估机制,定期审计供应商的数据处理实践
  • 数据最小化与生命周期管理:即使采用90天数据保留策略,也需确保供应商严格执行,并建立可验证的数据删除机制(如审计日志、第三方验证)
  • 零日漏洞的连锁风险:单一第三方组件的漏洞可能影响整个供应链,企业应建立供应商漏洞响应流程,及时评估和缓解相关风险

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全