ShipMonk Breach Exposes Nearly 14,000 Trezor Customer Records

Nearly 14,000 Trezor customers had names, emails, phone numbers and shipping addresses accessed in a ShipMonk breach; Trezor says its systems remained secure.

Nearly 14,000 customers of hardware wallet maker Trezor had personal information exposed after a breach at ShipMonk, the third-party fulfillment provider used to deliver orders. Trezor says its own systems were not compromised.

Trezor was notified of the incident on Aug. 10. Customers who placed orders between May 10 and Aug. 8 were affected. The company identified 11,742 customers whose full names, phone numbers, email addresses and shipping addresses were accessed, and 1,947 customers whose names, cities and email addresses were exposed. Affected customers include people in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

Trezor shared customer details with ShipMonk only for delivery. The company points to a 90-day data retention policy it enforces with fulfillment partners as a factor that limited the number of records exposed. For the group with partial exposure, older orders may have been accessed.

Trezor has emailed all impacted customers and advised them to be wary of messages that request personal information or prompt immediate action. In its notification, Trezor wrote, “To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts.” The company also urged customers to ignore unsolicited requests for login credentials or seed phrases.

ShipMonk customers were reportedly told that attackers exploited a vulnerability in Metabase, a data analytics tool. Security investigators linked the issue to a SQL-injection zero-day that Metabase patched last week. An extortion group known as ShinyHunters has claimed responsibility for an attack on Metabase and published data that it says was taken from the provider.

ShipMonk has not publicly acknowledged the breach. Trezor says it is working directly with the fulfillment partner to establish a timeline and determine the full scope of the incident. Investigations are ongoing, and it is not yet clear whether other companies that used the same fulfillment service had customer data exposed.

Articles by this author