Trezor, a hardware wallet manufacturer, revealed that 67,000 U.S. customers were impacted by a data breach at its shipping partner, ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers for orders placed between November 2019 and August 2021. This incident does not compromise the security of Trezor's hardware wallets themselves.
Trezor stated that it had repeatedly requested and received written confirmation from ShipMonk regarding the deletion of customer data, in accordance with their contract and data policy. Despite these assurances, the data was not deleted from ShipMonk's systems, leading to its exposure. This breach adds to a previous disclosure of 13,689 customers whose data was partially or fully exposed.
ShipMonk informed Trezor of the breach on August 10, 2026, following unauthorized access to its systems. The logistics company has reportedly secured the affected systems and improved its security. The breach involved the zero-day exploitation of CVE-2026-72898, a critical SQL injection flaw in Metabase. Enterprise blockchain security firm Holborn attributes the breach to the ShinyHunters extortion gang.
Trezor has directly notified affected customers. The company also issued a warning for users to be vigilant against social engineering attacks and scams. Bad actors could use the leaked information to send phishing emails, make fraudulent calls, or impersonate Trezor in communications to trick targets into unintended actions.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Hardware crypto wallet maker Trezor reported that a cyberattack on its marketing email provider, Brevo, led to approximately 347,000 phishing emails being sent to Trezor customers. These emails contained malicious links designed to steal wallet backup passwords, marking the second data breach affecting Trezor customers in recent months.
Trezor, a cold cryptocurrency storage provider, announced that approximately 347,000 of its customers received phishing emails due to a security breach at Brevo, a third-party marketing platform it uses. The attacker exploited a SAML Single Sign-On vulnerability in Brevo to access user accounts and send malicious emails, potentially leading to fund loss for users who clicked the phishing link.
Trezor customers were targeted in phishing attacks after its third-party email provider, Brevo, suffered a security incident. The attacks affected 347,000 email addresses, with 2,500 users clicking malicious links, prompting Trezor to suspend its Brevo account and take down the phishing domain.
Trezor, a cryptocurrency hardware wallet manufacturer, has warned customers about phishing attacks originating from a breach of its third-party email provider. The attackers are sending fake security alerts to compromise user data, marking another security incident for Trezor following previous data breaches involving its shipping provider and support portal.
Trezor's data breach, originating from its shipping provider ShipMonk, has expanded to affect 81,000 customers, including 67,000 additional U.S. customers. This expansion occurred because ShipMonk failed to delete customer data as contractually required, leading to further exposure of personal information. The incident highlights supply chain security risks and the importance of data deletion policies.
Hardware wallet manufacturer Trezor announced that 67,000 U.S. customers had their personal data exposed due to a breach at its shipping provider, ShipMonk. This incident is significant because it adds to previously disclosed exposures and highlights the risks associated with third-party data handling, even after assurances of data deletion.