ZeroHour
Story · 1 source · 1 articlefirst updated ()

Trezor hit by two vendor breaches: ShipMonk data exposure grows to 81,000 customers while Brevo hack fuels phishing of 347,000

mediumData breachimportance 65
What's new: The story escalated on two fronts: Trezor's September 4 update expanded the ShipMonk breach from roughly 14,000 to 81,000 affected customers by adding about 67,000 US customers whose 2019–2021 order data was stolen, and on September 9, 2026 a separate breach of email provider Brevo enabled a phishing campaign that reached 347,000 Trezor newsletter subscribers.
Merged summary · glm-5.3 · rewritten as coverage arrives

Trezor says a breach at shipping partner ShipMonk now affects 81,000 customers (up from roughly 14,000 first reported), while a separate September 9, 2026 breach of email provider Brevo let attackers send fake 'STM32 Entropy Vulnerability' phishing emails to…

Trezor maker SatoshiLabs is contending with two third-party breaches. At shipping partner ShipMonk, attackers exploited a SQL injection zero-day in Metabase's Cloud SaaS platform and stole data covering orders from November 2019 to August 2021 — well beyond the May 10 to August 8, 2026 window first disclosed on August 13 — raising the affected-customer count from roughly 14,000 to 81,000, a 479% increase (Help Net Security cites 3,889 customers as the initial figure). Exposed fields include names, emails, phone numbers, shipping addresses, and order numbers; no wallet credentials or recovery seed data were reported stolen. Trezor says ShipMonk retained data past a 90-day deletion requirement despite repeated written deletion assurances, is considering legal action, and notes the ShinyHunters gang sent extortion emails to ShipMonk; affected orders shipped to the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Separately, on September 9, 2026 attackers compromised marketing email provider Brevo — Brevo says the intruder created an account, enabled SAML SSO, and accessed 138 accounts (one report says 120), exfiltrating contacts from 43 — and sent fake 'Critical Security Alert: STM32 Entropy Vulnerability' emails from [email protected] to 347,000 opted-in newsletter subscribers, claiming wallet seeds were exposed to brute-force attacks and luring victims to enter their wallet backup. About 2,500 users clicked the malicious link before Trezor took the phishing domain down within 20 minutes; potential fund losses are unknown. Swiss wallet maker BitBox and crypto tax tool CoinTracking also appear affected by the Brevo compromise. Trezor stresses its own products, wallets, and account systems were unaffected in both incidents, but warns of ongoing phishing calls, QR-code scam letters, and physical security risks, and is accelerating anonymous delivery options.

  • ShipMonk breach impact was revised from roughly 14,000 to 81,000 customers (a 479% increase, adding about 67,000 US customers) after stolen data covering November 2019 to August 2021 orders was discovered; Help Net Security reports the…
  • Attackers exploited a SQL injection zero-day in Metabase's Cloud SaaS platform to access ShipMonk data, and the ShinyHunters extortion gang sent emails to ShipMonk after the breach.
  • Exposed ShipMonk data includes names, emails, phone numbers, shipping addresses, and order numbers; no wallet credentials or recovery seed data were reported stolen.
  • ShipMonk retained data past a 90-day deletion requirement despite repeated written deletion assurances; Trezor is considering legal action against ShipMonk.
  • Affected orders shipped to the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
  • On September 9, 2026, attackers breached email provider Brevo, abusing SAML SSO to access 138 accounts and exfiltrate contacts from 43 of them; one report puts the figure at 120 accounts.
  • The Brevo attackers sent fake 'Critical Security Alert: STM32 Entropy Vulnerability' emails from [email protected] to 347,000 opted-in newsletter subscribers, luring victims to enter their wallet backup; 2,500 users clicked before the…
  • BitBox and CoinTracking also appear affected by the Brevo breach.

Coverage timeline

  1. · 8d ago
    Infosecurity Magazine· 55
    Trezor Supply Chain Breach Now Impacts 81,000 Customers

    Trezor says a breach at shipping partner ShipMonk exposed data of 81,000 customers, 67,000 more than first reported, including orders back to 2019.