Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Trezor Data Breach at ShipMonk Affects 67,000 U.S. Customers

Trezor Data Breach at ShipMonk Affects 67,000 U.S. Customers

Posted on September 5, 2026 By CWS

On Friday, Trezor, the hardware wallet maker, announced the exposure of data for 67,000 U.S. customers following a breach at its shipping partner, ShipMonk. This incident, affecting customers between November 2019 and August 2021, involved leaked names, email addresses, phone numbers, shipping details, and order numbers. Fortunately, Trezor clarified that the security of its hardware wallets remains intact.

Details of the Breach

Trezor emphasized its dissatisfaction with ShipMonk, stating that they had repeatedly secured written confirmations regarding the deletion of customer data in compliance with their contractual and data policies. Despite these assurances, the data was not removed from ShipMonk’s systems. This revelation follows a previous disclosure affecting 13,689 customers, where data exposure was said to be limited by a 90-day data retention policy.

ShipMonk notified Trezor of the breach on August 10, 2026, attributing it to unauthorized access. Among the affected were 1,947 customers whose data exposure was confined to names, cities, and email addresses, excluding shipping addresses. Trezor reiterated its policy of deleting or anonymizing customer data 90 days post-purchase, a period covering the lifecycle of an order.

Security Measures and Responses

ShipMonk has not yet publicly addressed the breach. However, reports suggest that the company has fortified its systems in response to the security lapse. The breach exploited a zero-day vulnerability, identified as CVE-2026-72898, a severe SQL injection flaw in Metabase, which carries a CVSS score of 10.0.

The ShinyHunters extortion group is believed to be behind this intrusion, according to Holborn, a security firm specializing in blockchain. In response, Trezor has informed affected customers and cautioned them against potential social engineering tactics aimed at exploiting the leaked data.

Implications and Future Outlook

Trezor warns that the exposed information could lead to phishing attacks, fraudulent communications, and personal security risks. Users should remain vigilant against emails, calls, or letters that might attempt to impersonate the company to deceitfully extract further information.

Holborn highlighted the breach as an example of the vulnerabilities within software supply chains, urging organizations to enhance their oversight of third-party risks. The breach underscores the critical need for comprehensive visibility and management of security postures to prevent similar incidents.

As companies continue to rely on third-party service providers, the Trezor breach serves as a stark reminder of the importance of robust security frameworks and the constant evaluation of third-party vulnerabilities.

The Hacker News Tags:customer data, Cybersecurity, data breach, extortion gang, Holborn, Metabase, Phishing, security risk, ShinyHunters, ShipMonk, SQL injection, supply chain attack, third-party risk, Trezor, Vulnerability

Post navigation

Previous Post: Critical Flaw in Elementor Pro Exploited by Hackers
Next Post: Critical Security Breach: JetBrains Cadence Users Urged to Act

Related Posts

Microsoft Alerts on Active Exploitation of Defender Vulnerabilities Microsoft Alerts on Active Exploitation of Defender Vulnerabilities The Hacker News
CISA Highlights Four Actively Exploited Security Vulnerabilities CISA Highlights Four Actively Exploited Security Vulnerabilities The Hacker News
Attackers Abuse Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 Tunneling Attackers Abuse Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 Tunneling The Hacker News
Identity Security Has an Automation Problem—And It’s Bigger Than You Think Identity Security Has an Automation Problem—And It’s Bigger Than You Think The Hacker News
Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security The Hacker News
iPhone Spyware, Microsoft 0-Day, TokenBreak Hack, AI Data Leaks and More iPhone Spyware, Microsoft 0-Day, TokenBreak Hack, AI Data Leaks and More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act
  • Trezor Data Breach at ShipMonk Affects 67,000 U.S. Customers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act
  • Trezor Data Breach at ShipMonk Affects 67,000 U.S. Customers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark