Cryptocurrency hardware wallet maker Trezor says a breach at shipping provider ShipMonk has exposed information belonging to 81,000 customers. The total increased after the company discovered that another 67,000 US customers were affected.
Trezor initially reported the incident on August 13. At that point, the company believed attackers had accessed the personal information of almost 14,000 customers.
The exposed data may help criminals create convincing phishing messages, fraudulent calls and letters. Moreover, the inclusion of home addresses could place some cryptocurrency owners at physical risk.
ShipMonk retained data it should have deleted
The additional 67,000 customers placed orders in the United States between November 2019 and August 2021. Exposed information includes names, email addresses, phone numbers, shipping addresses and order numbers.
According to Trezor, ShipMonk should have deleted this information under its contract and data retention policy.
Trezor said it had repeatedly asked the logistics provider to remove the records. ShipMonk reportedly gave written confirmation that it had completed the deletion. However, the information remained stored in its systems and became accessible during the breach.
The initial disclosure covered customers who received orders between May 10 and August 8, 2026. Those affected lived in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom.
Their exposed information included full names, email addresses, phone numbers and delivery addresses.
Trezor devices and services remain secure
Trezor stressed that attackers did not compromise its own systems. The breach also had no impact on its operations or services.
In addition, the incident did not affect Trezor hardware wallets or the cryptocurrency stored on them. Nevertheless, the stolen customer information creates a serious social engineering risk.
Attackers could use accurate order and contact details to impersonate Trezor or a delivery company. Consequently, messages may appear more convincing than ordinary cryptocurrency scams.
Trezor warned customers to distrust any communication that asks for private information. Users should never share wallet recovery seeds, private keys, passwords or authentication codes.
Attackers reportedly exploited Metabase flaw
Trezor has not publicly explained exactly how attackers entered ShipMonk’s systems. However, breach notifications sent to customers linked the incident to a vulnerability in the Metabase analytics platform.
Metabase previously disclosed attacks involving a critical SQL injection zero-day vulnerability. Threat actors exploited the flaw to gain administrator access to customer instances and steal stored data.
The campaign has also affected online form platform Tally and laptop manufacturer Framework. Both companies notified customers after attackers compromised their Metabase instances.
ShipMonk also reportedly received extortion emails from the ShinyHunters cybercrime group. However, Trezor has not publicly attributed the breach to a specific attacker.
Previous breach led to recovery seed phishing
This is not the first third-party incident to expose Trezor customer information. In January 2024, attackers compromised the company’s external support ticketing portal.
That breach exposed names, usernames and email addresses belonging to around 66,000 users. Criminals later used the stolen data in phishing attacks.
Those messages attempted to trick recipients into revealing their 24-word wallet recovery seeds. Anyone who obtains such a seed can potentially take control of the associated cryptocurrency wallet.
Customers affected by the latest Trezor data breach should therefore remain cautious of personalized emails, phone calls, letters and delivery-related messages. They should verify communications through official channels and never disclose their recovery seed.


0 responses to “Trezor data breach now affects 81,000 customers”