Trezor‘s Trezor ShipMonk data breach, disclosed this week, has exposed the personal details of nearly 14,000 customers after attackers exploited a critical zero-day vulnerability in a third-party analytics platform used by its shipping provider. The breach did not touch Trezor’s own systems or devices, but the leaked information is precisely what a phishing campaign needs.
On 10 August 2026, Trezor published a blog post confirming that ShipMonk, its shipping and logistics provider, had informed the company of unauthorised access to systems containing customer order data. The affected records include full names, shipping addresses, email addresses, and phone numbers. Customers who received orders between 10 May and 8 August 2026 and are based in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal are among those affected.
Trezor broke the exposure down into two groups. 11,742 customers face full exposure, meaning name, email, phone number, and shipping address are all in attacker hands. A further 1,947 customers have partial exposure, limited to name, city, and email address. The company confirmed that its own operations and services were not disrupted, and that all Trezor devices remain secure.
How the Trezor ShipMonk data breach unfolded
The route in was not through ShipMonk’s own infrastructure directly. In breach notification emails sent to affected customers, ShipMonk told them that the attackers exploited a vulnerability in Metabase, a third-party analytics platform ShipMonk had integrated into its systems. ‘On August 6, 2026, Metabase informed us that an unauthorized party exploited a vulnerability in Metabase’s software to access data related to your account and your customers,’ ShipMonk wrote in the notification.
ShipMonk added that Metabase has since patched the vulnerability and invalidated all active sessions, and that ShipMonk itself launched a technical investigation with the assistance of external information technology experts.
Metabase has confirmed that the vulnerability is a critical SQL injection zero-day. Attackers exploited it to gain administrator access to compromised instances, then carried out data theft. According to Help Net Security, the vulnerability affects Metabase versions 58 and above, a detail that helps organisations assess their own exposure. ShipMonk is not the only victim: the same attack vector also led to data breach disclosures from laptop maker Framework and online form builder Tally.
For Framework for Business customers in particular, the scope of exposed data stretches further than a typical shipping breach. As BleepingComputer reported, that cohort’s records may also include company name, phone number, VAT number, EIN, and billing email address, turning a contact-data leak into something closer to a corporate identity file.
Phishing risk and Trezor’s previous breach
Trezor has been direct with affected customers about what to expect next. ‘Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor,’ the company warned. Anyone whose data was exposed should treat unsolicited contact requesting personal information with particular suspicion, regardless of how convincing the sender appears.
The concern is not hypothetical. In January 2024, Trezor disclosed a separate breach after threat actors gained access to its third-party support ticketing portal. That incident potentially exposed the names, usernames, and email addresses of 66,000 users who had interacted with Trezor Support since December 2021. Following that breach, attackers used the stolen data to launch phishing campaigns aimed at tricking recipients into revealing their 24-word wallet recovery seeds, meaning the playbook for what comes after a Trezor-adjacent data leak is already written.
Separately, Valve has also notified Steam hardware customers in Europe this week that their data was stolen after hackers compromised CEVA Logistics, its own shipping partner, suggesting the logistics supply chain has become a productive hunting ground for attackers targeting hardware companies and their customers.
Trezor says its systems were not compromised and all devices remain secure. The next thing to watch is whether the stolen contact data surfaces in active phishing campaigns, as it did after the 2024 support portal breach.

