← Radar

Incident case file

Sign in to watch

Trezor/ShipMonk — Customer Data Breach (13,689 Clients Exposed)

Incident date 2026-08-12Last updated Aug 20, 2026

7 views

ContainedOff-chainSupply chain attack — third-party data breach (Metabase SQL injection zero-day)Cluster: TRZ-SUP-2026-08

Estimated loss

$0

Victims identified

13689
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

MISSING — not publicly identified. ShinyHunters ransomware/extortion group sent emails to ShipMonk demanding payment after the breach (per BleepingComputer). ShinyHunters connection not formally confirmed by Trezor or ShipMonk as of Aug 20, 2026. Trezor hardware devices and seed phrases are NOT compromised — breach is limited to shipping/logistics data.

Funds moved to

N/A — no cryptocurrency stolen. Data breach only: names, emails, phone numbers, and physical shipping addresses of 11,742 customers fully exposed; names, city, and emails of 1,947 additional customers partially exposed. Total: 13,689 affected. Countries: US, UK, Sweden, Colombia, Brazil, Italy, Portugal. Orders from May 10 – August 8, 2026 (Trezor's 90-day data retention policy). Primary risk: targeted phishing, impersonation, and physical 'wrench attack' exposure for hardware wallet owners

Linked

N/A (no on-chain component). Technical context: ShipMonk uses Metabase (business intelligence / analytics tool) for order management. A critical SQL injection zero-day in Metabase was exploited by the attacker to access ShipMonk's order database. ShipMonk notified Trezor on August 10, 2026. Trezor disclosed publicly on August 13. Customers who purchased Trezor hardware via Amazon are NOT affected (Amazon handles fulfillment independently). Trezor hardware wallets themselves and seed phrases are

Chronology

10 beats
  1. August 13, 2026 — Trezor, the hardware wallet manufacturer, publicly disclosed that ShipMonk — one of its e-commerce fulfillment partners — had suffered a data breach exposing the personal information of 13,689 Trezor customers.

  2. Root cause: A critical SQL injection zero-day vulnerability in Metabase, the business intelligence and analytics tool used by ShipMonk for order management, was exploited by an attacker to gain unauthorized access to ShipMonk's customer order database.

  3. August 6, 2026: Metabase zero-day exploited. Attacker gains access to ShipMonk's order management systems. ShinyHunters extortion group sends emails to ShipMonk demanding payment in exchange for not publishing the stolen data.

  4. August 10, 2026: ShipMonk notifies Trezor of the data breach. Data exposed: order information for customers who purchased Trezor products between May 10 and August 8, 2026 (90-day retention window).

  5. August 13, 2026: Trezor publishes official disclosure: 'We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data.' Trezor sends email notifications to all 13,689 affected customers. Customers who purchased via Amazon are confirmed unaffected. Trezor states no evidence of misuse, sharing, or sale of the data at the time of disclosure.

  6. Data exposed — Full data (11,742 customers): name, email address, phone number, shipping address. Partial data (1,947 customers): name, city, email address. Countries affected: US, UK, Sweden, Colombia, Brazil, Italy, Portugal.

  7. Trezor hardware wallets and seed phrases are NOT compromised. The breach is entirely external to Trezor's systems and devices.

  8. Primary risk for affected customers: targeted phishing (attackers now know who owns a Trezor and their contact information), impersonation (fake Trezor support), and physical 'wrench attacks' (home address exposure for known hardware wallet owners).

  9. Trezor confirms: developing an 'Anonymous Delivery' feature to reduce personal data required for future orders. No compensation announced. No evidence of misuse confirmed as of August 20, 2026. ShinyHunters not formally confirmed as responsible party.

  10. Precedent: Ledger/Global-e breach (January 2026) exposed 292,000 customers via Shopify — same pattern of manufacturer-secure, fulfillment-partner-breached attack.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)