Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Trezor disclosed that a breach at its shipping provider ShipMonk exposed 67,000 U.S. customers' personal data, including names, emails, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021. ShipMonk had previously provided written assurances that customer data was deleted per contract and data policy, but the data remained in their systems despite those confirmations. The breach was caused by the exploitation of CVE-2026-72898, a critical SQL injection zero-day
Analysis
TL;DR
- Trezor disclosed that a breach at its shipping provider ShipMonk exposed 67,000 U.S. customers' personal data, including names, emails, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021.
- ShipMonk had previously provided written assurances that customer data was deleted per contract and data policy, but the data remained in their systems despite those confirmations.
- The breach was caused by the exploitation of CVE-2026-72898, a critical SQL injection zero-day vulnerability in Metabase (CVSS score: 10.0), attributed to the ShinyHunters extortion gang.
- The exposure is in addition to 13,689 customers disclosed in a prior breach, bringing the total affected to approximately 80,689 customers.
- Trezor emphasized that its hardware wallets remain secure, but warned affected users about potential social engineering, phishing, and physical security risks stemming from the leaked data.
Why It Matters
This incident underscores the critical importance of third-party and supply chain risk management in cybersecurity. Organizations relying on external logistics and data processing partners must enforce contractual data deletion obligations and validate compliance through independent audits rather than accepting assurances at face value. The breach also highlights how a single unpatched vulnerability in a widely used analytics platform like Metabase can cascade across multiple customer organizations.
Technical Details
- The attack vector was CVE-2026-72898, a critical SQL injection zero-day flaw in Metabase (CVSS 10.0), which ShipMonk exploited to gain unauthorized access to its systems and the stored customer data of its clients, including Trezor.
- The exposed dataset spans over 21 months (November 2019 to August 2021) and includes highly sensitive personally identifiable information (PII): full names, email addresses, phone numbers, shipping addresses, and order numbers.
- Trezor operates a 90-day data retention policy for its eShop, after which customer data is supposed to be deleted or anonymized, covering the full order lifecycle including delivery, returns, and refunds.
- ShipMonk failed to honor its contractual and policy obligations to delete this data, retaining it despite repeated written confirmations provided to Trezor.
- The breach was carried out by the ShinyHunters extortion gang, which typically targets organizations through supply chain vulnerabilities to steal data and demand ransom.
Industry Insight
- Organizations must treat third-party data handling relationships as a security extension of their own infrastructure; contractual clauses and written assurances are insufficient without continuous verification and audit mechanisms.
- The Metabase SQL injection vulnerability demonstrates the compounding risk of widely deployed analytics tools across multiple enterprises—patching and vulnerability monitoring for third-party software should be treated as a critical security priority.
- Companies should proactively communicate breach details to affected customers with specific guidance on social engineering threats, as leaked PII is frequently weaponized for targeted phishing and physical security threats well after the initial incident.
Disclaimer: The above content is generated by AI and is for reference only.