Trezor Discloses Breach of 67,000 U.S. Customers via ShipMonk Vulnerability
AI-generated from multiple sources. Verify before acting on this reporting.
PRAGUE, Sept. 5 (AP) — Trezor, a leading manufacturer of hardware cryptocurrency wallets, disclosed on Friday that personal and order data belonging to approximately 67,000 customers in the United States was exposed following a cyberattack on its logistics partner, ShipMonk.
The breach was attributed to the ShinyHunters extortion gang, which exploited a critical zero-day vulnerability identified as CVE-2026-72898. The flaw involved a SQL injection attack targeting Metabase, an analytics platform used by ShipMonk for data storage and management. Trezor stated that the compromised information includes names, shipping addresses, email addresses, and order details for affected U.S. customers.
Trezor confirmed that no private keys or seed phrases were stored on ShipMonk's systems and therefore remain secure. The company emphasized that the breach did not compromise the cryptographic security of the wallets themselves, but rather exposed logistical data associated with product deliveries. "We are working closely with ShipMonk to investigate the full scope of the incident and have implemented additional security measures," a Trezor spokesperson said in a statement released late Friday.
ShipMonk, a third-party logistics provider that handles fulfillment for numerous technology companies, acknowledged the intrusion but has not yet provided a detailed timeline of how long the attackers maintained access to its systems. The company reportedly patched the SQL injection vulnerability after the initial discovery, halting further data exfiltration.
The ShinyHunters group, known for targeting supply chain vulnerabilities to demand ransom payments, claimed responsibility for the attack shortly after Trezor's public announcement. The group has historically targeted logistics and e-commerce firms, leveraging exposed customer data to pressure companies into paying ransoms in cryptocurrency. In this instance, it remains unclear whether ShinyHunters is actively seeking payment or if the data was released publicly as part of a broader extortion campaign.
Cybersecurity experts have flagged CVE-2026-72898 as a significant threat to organizations relying on Metabase for internal reporting and data visualization. The vulnerability allows attackers to inject malicious SQL commands, potentially granting them unauthorized access to sensitive databases. Security firms are urging companies using the affected software versions to apply emergency patches immediately.
Trezor has advised affected customers to monitor their financial accounts and be vigilant against potential phishing attempts that may use the exposed personal information. The company is also offering credit monitoring services to those impacted by the data leak.
As of Friday afternoon, federal authorities have not announced a formal investigation into the incident. Questions remain regarding whether other clients of ShipMonk were similarly affected and if the attackers retained copies of the stolen data before the vulnerability was patched. Trezor and ShipMonk are expected to provide further updates as the investigation continues.