Trezor vendor breaches compound: ShipMonk incident now affects 81,000 customers while Brevo email-provider hack fuels phishing to 347,000 users
Trezor (SatoshiLabs) says a breach at shipping partner ShipMonk, attributed to the ShinyHunters gang exploiting a Metabase SQL injection zero-day (CVE-2026-72898, CVSS 10.0), now affects about 81,000 customers, up 479% from the roughly 14,000 first disclosed,…
SatoshiLabs, maker of Trezor hardware wallets, says a breach at shipping partner ShipMonk, which informed Trezor of unauthorized access on August 10, 2026, now affects about 81,000 customers, a 479% increase over the roughly 14,000 initially disclosed on August 13, 2026. Sources disagree on the initial count: The Hacker News reported 13,689 customers, while Help Net Security reported 3,889. Trezor's September 4, 2026 update revealed ShipMonk had retained and exposed order data from November 2019 to August 2021, despite repeated written deletion assurances and a reported 90-day deletion requirement, adding roughly 67,000 additional US customers beyond the original May 10 to August 8, 2026 window. Exposed data includes names, email addresses, phone numbers, shipping addresses, and order numbers; no wallet credentials or recovery seed data were reported stolen, and Trezor's own systems, products, and devices were not compromised. The intrusion is attributed to attackers exploiting a SQL injection zero-day in Metabase, reported by The Hacker News as CVE-2026-72898 (CVSS 10.0) in the analytics software and described by Help Net Security as Metabase's Cloud SaaS platform, enabling admin access and data theft at customer instances. The ShinyHunters extortion gang reportedly sent extortion emails to ShipMonk, and the broader Metabase campaign has been linked to breaches at Tally and Framework. Sources disagree on ShipMonk's public stance: The Hacker News reported on September 5 that ShipMonk had not publicly acknowledged the incident, while Help Net Security reported that ShipMonk attributed the intrusion to the Metabase zero-day. Help Net Security reports affected orders shipped to the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor is considering legal action against ShipMonk over the false deletion assurances, warns customers of heightened phishing emails, scam calls, impersonation attempts, and QR-code phishing delivered via physical letters, and is accelerating anonymous delivery options; customers are advised to use decoy wallets and P.O. boxes. TechCrunch notes victims face crypto theft risk including physical 'wrench' attacks, and Help Net Security cites a Chainalysis estimate that violent crypto attacks extracted over $30 million from holders in 2026. Separately, threat actors breached Trezor's third-party marketing email provider Brevo on September 9, 2026 and sent fake 'Critical Security Alert: STM32 Entropy Vulnerability' emails from…
- ShipMonk breach now affects about 81,000 Trezor customers, a 479% increase over the roughly 14,000 initially disclosed on August 13, 2026; the initial count is reported as 13,689 (The Hacker News) or 3,889 (Help Net Security).
- Roughly 67,000 additional US customers were exposed, with orders dating November 2019 to August 2021, beyond the original May 10 to August 8, 2026 window; ShipMonk retained data despite written deletion assurances and a reported 90-day…
- Exposed fields: names, email addresses, phone numbers, shipping addresses, and order numbers; no wallet credentials or recovery seed data reported stolen; Trezor's own systems, products, and devices were not compromised.
- Attack attributed to ShinyHunters exploiting a Metabase SQL injection zero-day, reported as CVE-2026-72898 (CVSS 10.0), described as Metabase's Cloud SaaS platform; the campaign also hit Tally and Framework.
- Timeline: ShipMonk notified Trezor of unauthorized access August 10, 2026; Trezor disclosed August 13, 2026 and expanded the disclosure September 4, 2026.
- Disputed stance: The Hacker News (Sep 5) reported ShipMonk had not publicly acknowledged the incident, while Help Net Security (Sep 8) reported ShipMonk attributed it to the Metabase zero-day.
- Affected orders shipped to the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal (Help Net Security).
- Trezor is considering legal action against ShipMonk; warns of phishing emails, scam calls, impersonation, and QR-code phishing via physical letters; is accelerating anonymous delivery options; advises decoy wallets and P.O. boxes.
Coverage timelineoldest first · each row is one article
- · 10d agoTrezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
The Hacker News· 72
Trezor disclosed the ShipMonk breach exposed data of 67,000 additional US customers, reportedly by ShinyHunters exploiting a Metabase zero-day SQL injection, CVE-2026-72898.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-72898 | Unauthenticated SQL Injection in Metabase Grants Admin Access CVE-2026-72898 is a critical SQL injection flaw (CWE-89, CVSS 4.0 score of 10) in Metabase, a widely used open-source business intelligence platform. A remote, unauthenticated attacker can send crafted input to the '/reset_password' database endpoint to inject arbitrary SQL into the underlying database. Successful exploitation grants the attacker administrator access to the connected Metabase instance, with confidentiality, integrity, and availability impacts rated high in the CVSS 4.0 vector. Any organization running an affected Metabase instance, particularly one exposed to the internet, is at risk. The flaw is a zero-day being exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-11, and carries a 94.2% EPSS probability of exploitation within 30 days (100th percentile). Do: Upgrade promptly to the fixed Metabase release identified in the vendor's security advisory (no version numbers were provided in the available data), as the flaw is being exploited in the wild and is on CISA's KEV list under BOD 26-04. Until patched, restrict internet access to Metabase and limit reachability of the '/reset_password' endpoint to trusted networks. Hunt for compromise by reviewing access logs for anomalous requests to the reset-password endpoint and checking for unexpected administrator accounts or changed admin credentials. | 10.0 | 94% | KEV PoC |
| large≈10k–50k internet-exposed Metabase instances (tens of thousands) |