← All stories
● Covered by 4 sources · 6 reportsMedium impact6 negative

Trezor Discloses ShipMonk Breach Exposed Data of 67,000 U.S. Customers

🔄 Updated 20d ago — new reporting from SecurityWeek, TechCrunch
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 67,000 U.S. Trezor customers affected by ShipMonk data breach.
  • Exposed data includes names, emails, phone numbers, shipping addresses, order numbers.
  • Trezor had received written assurances from ShipMonk that data was deleted.
  • ShinyHunters gang is reportedly behind the breach, exploiting a critical Metabase flaw.
  • Trezor data breach now affects 81,000 customers.
  • Additional 67,000 U.S. customers affected ordered between November 2019 and August 2021.
  • Customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom were affected.
  • Affected customers received orders between May 10 and August 8, 2026.
  • Trezor warned customers about phishing attacks from a breached third-party email provider.
  • Phishing emails claim a "hardware microcontroller vulnerability" in STM32 microcontrollers.
  • Trezor took down the domain help@trezor.io to stop phishing attacks.
  • Phishing attacks targeted 347,000 email addresses.
  • 2,500 users clicked malicious links in the phishing attacks.
  • Trezor suspended its Brevo account.
  • Trezor took down the phishing domain within 20 minutes.
  • Brevo suffered a security incident on September 9, 2026.
  • The Brevo incident affected 120 Brevo accounts.
  • Brevo attacker exploited a SAML Single Sign-On vulnerability.
  • Attacker accessed 138 Brevo accounts.
  • Attacker exfiltrated contacts from 43 Brevo accounts.
  • Phishing emails asked for wallet backup passwords.
  • One phishing email subject line was "Critical Security Alert: STM32 Entropy Vulnerability".

Customer Data Exposed in ShipMonk Breach

Trezor, a hardware wallet manufacturer, revealed that 67,000 U.S. customers were impacted by a data breach at its shipping partner, ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers for orders placed between November 2019 and August 2021. This incident does not compromise the security of Trezor's hardware wallets themselves.

Failure to Delete Data Despite Assurances

Trezor stated that it had repeatedly requested and received written confirmation from ShipMonk regarding the deletion of customer data, in accordance with their contract and data policy. Despite these assurances, the data was not deleted from ShipMonk's systems, leading to its exposure. This breach adds to a previous disclosure of 13,689 customers whose data was partially or fully exposed.

Breach Details and Attacker Attribution

ShipMonk informed Trezor of the breach on August 10, 2026, following unauthorized access to its systems. The logistics company has reportedly secured the affected systems and improved its security. The breach involved the zero-day exploitation of CVE-2026-72898, a critical SQL injection flaw in Metabase. Enterprise blockchain security firm Holborn attributes the breach to the ShinyHunters extortion gang.

Customer Notification and Security Warnings

Trezor has directly notified affected customers. The company also issued a warning for users to be vigilant against social engineering attacks and scams. Bad actors could use the leaked information to send phishing emails, make fraudulent calls, or impersonate Trezor in communications to trick targets into unintended actions.

Updates

🕒 2026-09-11 · new reporting from SecurityWeek, TechCrunch
  • Brevo attacker exploited a SAML Single Sign-On vulnerability.
  • Attacker accessed 138 Brevo accounts.
  • Attacker exfiltrated contacts from 43 Brevo accounts.
  • Phishing emails asked for wallet backup passwords.
  • One phishing email subject line was "Critical Security Alert: STM32 Entropy Vulnerability".
🕒 2026-09-11 · new reporting from BleepingComputer
  • Phishing attacks targeted 347,000 email addresses.
  • 2,500 users clicked malicious links in the phishing attacks.
  • Trezor suspended its Brevo account.
  • Trezor took down the phishing domain within 20 minutes.
  • Brevo suffered a security incident on September 9, 2026.
  • The Brevo incident affected 120 Brevo accounts.
🕒 2026-09-10 · new reporting from BleepingComputer
  • Trezor warned customers about phishing attacks from a breached third-party email provider.
  • Phishing emails claim a "hardware microcontroller vulnerability" in STM32 microcontrollers.
  • Trezor took down the domain help@trezor.io to stop phishing attacks.
🕒 2026-09-07 · new reporting from BleepingComputer
  • Trezor data breach now affects 81,000 customers.
  • Additional 67,000 U.S. customers affected ordered between November 2019 and August 2021.
  • Customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom were affected.
  • Affected customers received orders between May 10 and August 8, 2026.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Hardware crypto wallet maker Trezor reported that a cyberattack on its marketing email provider, Brevo, led to approximately 347,000 phishing emails being sent to Trezor customers. These emails contained malicious links designed to steal wallet backup passwords, marking the second data breach affecting Trezor customers in recent months.

Trezor, a cold cryptocurrency storage provider, announced that approximately 347,000 of its customers received phishing emails due to a security breach at Brevo, a third-party marketing platform it uses. The attacker exploited a SAML Single Sign-On vulnerability in Brevo to access user accounts and send malicious emails, potentially leading to fund loss for users who clicked the phishing link.

Trezor customers were targeted in phishing attacks after its third-party email provider, Brevo, suffered a security incident. The attacks affected 347,000 email addresses, with 2,500 users clicking malicious links, prompting Trezor to suspend its Brevo account and take down the phishing domain.

Trezor, a cryptocurrency hardware wallet manufacturer, has warned customers about phishing attacks originating from a breach of its third-party email provider. The attackers are sending fake security alerts to compromise user data, marking another security incident for Trezor following previous data breaches involving its shipping provider and support portal.

Trezor's data breach, originating from its shipping provider ShipMonk, has expanded to affect 81,000 customers, including 67,000 additional U.S. customers. This expansion occurred because ShipMonk failed to delete customer data as contractually required, leading to further exposure of personal information. The incident highlights supply chain security risks and the importance of data deletion policies.

Hardware wallet manufacturer Trezor announced that 67,000 U.S. customers had their personal data exposed due to a breach at its shipping provider, ShipMonk. This incident is significant because it adds to previously disclosed exposures and highlights the risks associated with third-party data handling, even after assurances of data deletion.