High cybersecurity update: Trezor discloses data breach affecting nearly 14,000 customers. NetworkFix reviewed the available source material to summarize the security issue, its potential impact and the defensive actions administrators should prioritize.
What Happened
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked […] Trezor discloses data breach affecting nearly 14,000 customers Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked. During the incident, the attackers gained access to customers' order data, including their full names, shipping addresses, email addresses, and phone numbers. As the company explained in a Thursday blog post, the resulting data breach affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026. "On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data," Trezor said . "The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email)." The company added that its operations or services were not impacted by the breach, that its systems were not compromised, and that all Trezor devices are secure. It also warned affected customers to be wary of any messages requesting personal information, as they may see an increase in phishing attempts. "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," it noted. "Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor." A Trezor spokesperson was not immediately available for comment when contacted by BleepingComputer today for more information about the incident.
Technical Details
While Trezor didn't share how the shipping provider's systems were breached, in breach notification emails sent to affected customers and reviewed by BleepingComputer, ShipMonk told customers that the attackers exploited a vulnerability in the third-party analytics platform Metabase. "On August 6, 2026, Metabase informed us that an unauthorized party exploited a vulnerability in Metabase's software to access data related to your account and your customers," ShipMonk said. "Based on the vendor's representations, we understand that the vendor has since patched the vulnerability and invalidated all active sessions. We also initiated a thorough and detailed technical investigation with the assistance of external information technology experts." As BleepingComputer previously reported , Metabase revealed that the threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances and carry out data theft attacks after gaining administrator access to the compromised instance. The list of affected companies also includes laptop maker Framework and online form builder Tally, which also notified customers of data breaches after their Metabase instances were hijacked. BleepingComputer has since learned that ShipMonk has also received extortion emails from the ShinyHunters extortion gang. Trezor disclosed another data breach in January 2024 after threat actors gained access to its third-party support ticketing portal. The hardware cryptocurrency wallet vendor revealed at the time that 66,000 users who have interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed during the incident. After the breach, Trezor confirmed that the attackers used the stolen information to launch phishing attacks, attempting to trick recipients into revealing the 24-word recovery seeds they were given when setting up their Trezor wallets.
Security Impact
Organizations using the affected technology should treat the report according to its high severity classification. Video game distribution giant Valve has also notified Steam hardware customers in Europe on Monday that hackers stole their data after hacking CEVA Logistics, its shipping partner. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Valve notifies Steam hardware customers of a data breach Unlimited Technology Systems breach impacts 3.8 million people Levi Strauss & Co. says hackers stole corporate data in cyberattack Canadian pleads guilty to Snowflake cloud data-theft attacks ExfilSquad hackers leak info of over 100,000 UK police officers, staff Sergiu Gatlan Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees LexisNexis shuts down services after suspicious activity on servers Overdue a password health-check?
Recommended Actions
- Identify whether the affected product, service or software is present in the environment.
- Review the original vendor or research advisory and verify affected versions before making configuration changes.
- Apply vendor-provided security updates or mitigations as soon as operationally practical.
- Review relevant security logs and monitoring alerts for signs of suspicious activity associated with the reported issue.
- Use the CVE identifiers, where available, to validate exposure through vulnerability-management and asset-inventory tools.
Security Details
- Severity: High
- Original source: BleepingComputer
Why This Matters
Cybersecurity teams should use reports like this as an input to risk-based vulnerability and threat management rather than relying on headline severity alone. Exposure depends on whether the affected technology is deployed, reachable by an attacker and protected by compensating controls. Confirming asset ownership, affected versions and available vendor fixes helps teams prioritize remediation while avoiding unnecessary emergency changes.
Original Report
NetworkFix recommends reviewing the complete original report from BleepingComputer for the authoritative technical context, affected versions, indicators and vendor-specific remediation details: Read the original report.