Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Trezor disclosed on September 4, 2026 that an additional 67,000 U.S. customers were exposed in the data breach at its logistics provider ShipMonk, bringing the estimated total past 80,000. This is not a new attack but the discovery that ShipMonk had retained data it had repeatedly certified as deleted. The records cover orders placed between November 2019 and August 2021, well beyond the 90-day retention window stipulated in the contract.
The disclosure expands the initial August notification, when Trezor reported the exposure of 13,689 customers. ShipMonk had notified Trezor of the intrusion on August 10, 2026, citing unauthorized access to its systems. The source does not specify whether the two customer groups partially overlap or are entirely distinct.
- An additional 67,000 U.S. customers exposed in the September 4, 2026 disclosure, on top of 13,689 in August; secondary sources place the estimated total above 80,000
- Exposed data includes names, emails, phone numbers, shipping addresses, and order numbers for purchases between November 2019 and August 2021
- ShipMonk provided "repeated written assurances" of compliant deletion under the 90-day policy, but the data remained in its systems
- Unauthorized access exploited CVE-2026-72898, a critical SQL injection in Metabase with a CVSS 10.0 score; according to Holborn, the ShinyHunters extortion group is behind the attack
Compliance That Deleted Nothing
The core failure is not technical in Trezor's wallet but the disconnect between ShipMonk's documented governance and operational reality. Trezor stated it had "repeatedly requested and received written assurances" confirming data deletion, in line with the contract, company policy, and prior communications. The retention policy is 90 days, after which, Trezor said, "we have no reason to retain your address or phone number."
The exposed data, however, spans nearly two years, from November 2019 to August 2021. Trezor expressed explicit dissatisfaction: "We are very disappointed that, despite this confirmation, the data had not been deleted from their systems." The public rebuke of a vendor by its client signals a significant relational rupture and a possible prelude to legal action not yet documented.
The Technical Vector: Metabase and CVE-2026-72898
Unauthorized access to ShipMonk's systems occurred through the zero-day exploitation of CVE-2026-72898, a critical SQL injection vulnerability in the Metabase business intelligence platform, with a CVSS 3.1 score of 10.0. The attack vector is classified as network-accessible, with low complexity, no privilege requirements, no user interaction, and high impact on confidentiality, integrity, and availability.
The dossier contains no independent technical details on the vulnerability nor verification of its presence in the official CVE database. According to the primary source, security firm Holborn linked the breach to the ShinyHunters extortion group. This attribution is not corroborated by multiple sources in the dossier.
ShipMonk stated it had "secured the affected systems and enhanced security" following the intrusion. The dossier does not specify the technical nature of these enhancements nor whether they have been independently verified.
"After 90 days we delete or anonymize all customer data related to a purchase on our Trezor eShop. After that we have no reason to retain your address or phone number." — Trezor, via The Hacker News
From Phishing to Physical Threat
Trezor called this the first breach since the company's founding in 2013 to expose customer phone numbers and shipping addresses. The shift is not marginal: previous breaches primarily involved email addresses, which enable phishing campaigns but do not geographically identify the victim.
The combination of name, physical address, phone number, and order history for hardware crypto wallets turns customers into precisely identifiable targets. Trezor warned that "the leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical safety risks." The dossier does not quantify or document concrete cases of verified physical threats.
The risk of "wrench attacks" — physical coercion to extract private keys — is highlighted in the sector context by secondary sources citing Chainalysis data, but these data are not independently verifiable in the dossier. The logic is straightforward: anyone buying a hardware wallet is by definition a holder of digital assets, and knowledge of the shipping address lowers the cost of victim reconnaissance for potential attackers.
Why It Matters
The case exposes a systemic pattern in the logistics supply chain: data deletion certifications are often documentary procedures lacking technical verification. Trezor received written guarantees that proved unreliable, without an audit mechanism to verify actual removal from the provider's systems. The source does not specify whether Trezor conducted independent verifications before the incident, nor whether ShipMonk has publicly acknowledged the breach — the primary source states that ShipMonk "has not yet acknowledged" the event.
The dossier does not document specific remedial measures or legal actions taken by Trezor. The company said it is working on introducing anonymous delivery to reduce personal data collection, but provides no timelines or implementation details. It is unknown whether the data was actually exfiltrated by the attacker or merely rendered accessible during the intrusion.
The central methodological limitation remains the lack of independent verifiability: Trezor customers must rely on vendor and provider statements without public technical evidence of the data custody chain. The breach did not compromise Trezor's systems, devices, private keys, or wallet backups — but that technical comfort does not mitigate the physical and identifying exposure of hardware wallet holders.
Trezor has directly notified affected customers. For anyone who placed orders between November 2019 and August 2021, the exposure is documented as real, regardless of uncertainties around attack attribution and actual exfiltration.
Information is based on the cited source and current as of publication.
Sources
- https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html
- https://newscord.org/article/trezor-says-shipmonk-breach-exposed-67000-more-us-customers-total-reaches-80700--Story_20260904_Trezorsaysdatabreach1d08c850
- https://www.cryptotimes.io/2026/09/05/trezor-breach-explodes-as-67000-more-u-s-customers-are-exposed/
- https://cryptoadventure.com/trezor-shipmonk-breach-expands-to-67000-more-u-s-customers/
- https://cryptorank.io/news/feed/25d0d-trezor-shipmonk-data-breach-67000-customers
- https://unchainedcrypto.com/trezor-says-shipping-partner-kept-customer-data-it-certified-as-deleted-exposing-67000-more/
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html
- https://thehackernews.com/search/label/Threat%20Intelligence
- https://thehackernews.com/search/label/Vulnerability
- https://thehackernews.com/search/label/Cyber%20Attack
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.