Menu
Browse

Cyber Incident Victim: Trezor

Date

Aug 2026

Location

Czechia

Status

Unknown

Updated

2026-08-14 07:13

Timeline
Occurred
Aug 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

Trezor disclosed a data breach affecting nearly 14,000 customers after its shipping provider ShipMonk was compromised. The attackers accessed order data including names, addresses, emails, and phone numbers, with most records fully exposed and some partially exposed. The breach resulted from a vulnerability in the third‑party analytics platform Metabase that was exploited via a SQL injection zero‑day, leading to data theft and extortion attempts by the ShinyHunters group. The company stated its own systems and devices remained secure. A prior incident involving its support ticketing portal had exposed details of tens of thousands of users, which were later used in phishing attempts to obtain recovery seeds.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On August 10, 2026, ShipMonk notified Trezor of unauthorized access to its systems containing customer order data, prompting Trezor to disclose a data breach affecting nearly 14,000 customers. The exposed information included full names, shipping addresses, email addresses, and phone numbers for 11,742 customers with full exposure, while 1,947 customers had partial exposure consisting of name, city, and email address. The breach impacted customers located in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who had placed orders between May 10 and August 8, 2026. Trezor emphasized that its own systems were not compromised, its operations and services remained unaffected, and all Trezor devices remained secure. The company warned affected customers to be vigilant for messages requesting personal information, noting an increased risk of phishing attempts leveraging the leaked data. A Trezor spokesperson was not immediately available for comment when contacted by BleepingComputer for further details.

Cyber Incident Image

ShipMonk’s breach notification emails indicated that the attackers gained access through a vulnerability in the third‑party analytics platform Metabase. On August 6, 2026, Metabase informed ShipMonk that an unauthorized party had exploited a critical SQL injection zero‑day flaw in Metabase’s software to obtain administrator access to a compromised instance and exfiltrate customer data. ShipMonk stated that, based on Metabase’s representations, the vulnerability had been patched and all active sessions invalidated, and that it had launched a thorough technical investigation with the assistance of external IT experts. BleepingComputer reported that the same Metabase vulnerability had been exploited in breaches affecting other companies, including laptop maker Framework and online form builder Tally. Additionally, ShipMonk disclosed receiving extortion emails from the ShinyHunters gang following the incident.

Trezor’s disclosure referenced a prior incident in January 2024 when threat actors accessed its third‑party support ticketing portal, potentially exposing names, usernames, and email addresses of 66,000 users who had interacted with Trezor Support since December 2021; in that case, attackers used the stolen data to launch phishing attempts aimed at obtaining users’ 24‑word recovery seeds. For the August 2026 breach, Trezor reiterated that no Trezor devices were compromised and that the company’s internal systems remained secure. The firm’s response consisted of notifying affected customers, advising caution regarding unsolicited requests for personal data, and relying on ShipMonk’s remediation actions and investigation to address the root cause. The narrative concludes with the confirmed facts of the breach’s scope, origin, and Trezor’s stated position on device security and operational impact.

Sources
Sources available to members
1 source