Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Editor's note: No structured primary vendor advisory from Trezor or ShipMonk is available. Reporting relies on cybersecurity editorial sources and Trezor communications via third parties.
Trezor updated its August data breach estimate on September 4, 2026: victims total 81,000 customers, not 14,000. The case reveals a failure in third-party data management where a logistics provider retained personal data despite repeated written assurances.
The incident originated with fulfillment provider ShipMonk, not Trezor systems. Hardware devices remain intact. The damage lies in the exposure of names, emails, phone numbers, shipping addresses, and order numbers of crypto customers.
- The Trezor data breach affects 81,000 total customers, including 67,000 additional U.S. customers discovered in September with orders dated November 2019 through August 2021.
- ShipMonk failed to delete data despite repeated written assurances, violating its contract and Trezor's 90-day retention policy for eShop orders.
- The attack exploited CVE-2026-72898, a critical CVSS 10.0 SQL injection zero-day in Metabase, characterized by Holborn as a supply chain attack.
- Trezor systems were not compromised and hardware wallets remain secure; the documented risk from Trezor involves phishing, social engineering, and potential physical risks tied to exposed addresses.
Two Breach Counts: From 14,000 to 81,000 in Three Weeks
Trezor initially disclosed on August 13, 2026 that approximately 14,000 customers were affected, with orders placed between May 10 and August 8, 2026, concentrated in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom. The September 4, 2026 update expanded the incident's scope: an additional 67,000 U.S. customers, with orders placed between November 10, 2019 and August 8, 2021, were exposed.
According to The Hacker News, the initial count was 13,689 customers, with a further 1,947 customers having partial exposure limited to name, city, and email without shipping address. Trezor has not publicly explained the delay in discovering the additional 67,000 records.
The Mechanism: SQL Injection Zero-Day in Metabase
Access to ShipMonk systems occurred via CVE-2026-72898, a SQL injection vulnerability in Metabase rated CVSS 10.0 CRITICAL. The Hacker News describes it as zero-day exploitation: the attacker gained administrative access to the logistics provider's Metabase instance, reaching customer data for several of its clients, including Trezor.
Holborn, cited by The Hacker News, framed the incident as a supply chain attack: "The Trezor breach was the result of a supply chain attack beginning with a zero-day vulnerability... By finding and exploiting the SQL injection flaw in Metabase, the attackers were able to exploit several of its customers." ShipMonk received extortion emails from the ShinyHunters group. The group appears documented as the sender of the extortion demands; attribution as the initial attacker comes from Holborn.
Data Retained Beyond the Contract
The distinctive element of this case is contractual. Trezor stated, via BleepingComputer:
"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."
Trezor's retention policy requires deletion of eShop order data within 90 days. The 67,000 additional U.S. customers have orders dating back to 2021: for these records, the retention threshold was exceeded by years, not days. Trezor indicated it received only written assurances, without the ability to directly verify the vendor's systems.
No public ShipMonk advisory appears in available sources, nor is it clear whether Trezor will pursue legal action.
Risk for Hardware Wallet Owners
The exposed data — name, email, phone number, shipping address, order number — does not include private keys or wallet access credentials. Trezor emphasized that hardware devices remain secure and company systems were not compromised.
In the customer notification, cited by BleepingComputer, Trezor warned: "Be aware of the increased risk of phishing. The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks." The physical risk, documented by Trezor as potential, links real identities to crypto asset ownership via exposed shipping addresses.
What to Do Now
- Verify the source of any communication citing Trezor, past orders, or security updates: exposed data enables personalized phishing with references to real order numbers.
- Do not interact with links or attachments in emails, SMS, or calls demanding urgent action on wallets or devices: Trezor does not require updates via direct communications of this type.
- Contact Trezor support exclusively through official site channels, not by responding to incoming communications.
- Evaluate physical security measures if the shipping address is known to be associated with significant crypto asset holdings.
Context: A Precedent in January 2024
In January 2024, Trezor suffered another breach of 66,000 users via a third-party support portal. The two incidents involve different vectors: the 2024 breach via a support provider, the 2026 breach via a logistics provider. No analysis linking them as a systemic pattern is available in the brief.
Frequently Asked Questions
Were Trezor wallets compromised?
No. Hardware devices and Trezor systems were not breached. The incident concerns personal data managed by ShipMonk.
Has ShipMonk publicly confirmed the incident?
No public ShipMonk advisory appears in available sources. Trezor reported receiving notification from ShipMonk on August 10, 2026.
What data was exposed?
Name, email, phone number, shipping address, and order number. No private keys, seed phrases, or access credentials.
Who attacked ShipMonk?
The ShinyHunters group sent extortion emails to ShipMonk. Attribution as the initial attacker, via exploitation of CVE-2026-72898, comes from Holborn as cited by The Hacker News.
Why was 2019-2021 data still available?
ShipMonk had not deleted it despite repeated written assurances, in violation of its contract with Trezor.
Information is based on cited editorial sources. No structured primary vendor advisory from Trezor or ShipMonk is available.
Information has been verified against cited sources and is current as of publication.
Sources
- https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/
- https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html
- https://we-fix-pc.com/2026/09/07/trezor-data-breach-impact-now-reaches-81000-customers/
- https://blog.netmanageit.com/trezor-data-breach-impact-now-reaches-81-000-customers/
- https://www.hendryadrian.com/trezor-data-breach-impact-now-reaches-81000-customers/
- https://www.secnews.gr/en/731174/trezor-shipmonk-diarroi-81000-pelates/
- https://www.bleepingcomputer.com/
- https://www.bleepingcomputer.com/tutorials/
- https://www.bleepingcomputer.com/download/
- https://deals.bleepingcomputer.com/
- https://www.bleepingcomputer.com/vpn/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.