ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Trezor hit by back-to-back vendor breaches: ShipMonk data theft grows to 81,000 customers while Brevo hack fuels phishing to 347,000

mediumData breachexploited in the wildimportance 70
What's new: August 13, 2026: Trezor disclosed the ShipMonk breach, initially affecting roughly 14,000 customers (one report cited 3,889) with orders from May 10–August 8, 2026. September 4, 2026: Trezor raised the total to 81,000 customers after discovering stolen order data from November 2019–August 2021 (+67,000 US customers) and said it is considering legal action against ShipMonk over false deletion…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Trezor (SatoshiLabs) disclosed two third-party breaches: shipping partner ShipMonk, exploited via a Metabase SQL injection zero-day, exposed data of 81,000 customers (up from an initial ~14,000 estimate) and drew ShinyHunters extortion emails; then attackers…

Trezor maker SatoshiLabs has disclosed two separate supply-chain incidents. First, a breach at shipping partner ShipMonk, disclosed on August 13, 2026 and initially estimated at about 14,000 customers (one report cited 3,889), was revised in a September 4 update to 81,000 customers — a 479% increase — after attackers were found to have stolen order data from November 2019 to August 2021, adding roughly 67,000 US customers to the original May 10–August 8, 2026 window. Attackers exploited a Metabase SQL injection zero-day (in Metabase's Cloud SaaS platform) to gain admin access to customer instances and steal names, emails, phone numbers, shipping addresses, and order numbers; no wallet credentials or recovery seeds were reported stolen. ShipMonk had retained the data past a 90-day deletion requirement despite repeated written deletion assurances, and Trezor is considering legal action. The ShinyHunters gang sent extortion emails to ShipMonk, and the broader Metabase campaign also hit Tally and Framework. Second, attackers breached Trezor's marketing email provider Brevo on September 9, 2026, creating an account, enabling SAML SSO, and using their own identity provider to access 138 accounts (one report said 120), exfiltrating contacts from 43 of them. They sent emails from [email protected] with the subject 'Critical Security Alert: STM32 Entropy Vulnerability' to 347,000 opted-in newsletter subscribers, falsely claiming wallet seeds were exposed to brute-force attacks and linking to a malicious app that asked users to enter their wallet backup; 2,500 users clicked before the phishing domain was taken down within 20 minutes of detection. Swiss wallet maker BitBox and crypto tax calculator CoinTracking also appear affected. Trezor says its own systems, products, wallets, and account systems were unaffected, and warns customers of ongoing phishing emails, scam calls, QR-code phishing delivered by physical letters, and physical security risks.

  • ShipMonk breach disclosed August 13, 2026; initial estimate was roughly 14,000 customers (one report cited 3,889), within a May 10–August 8, 2026 order window.
  • Trezor's September 4, 2026 update raised the affected total to 81,000 customers, a 479% increase, after theft of order data from November 2019–August 2021 was discovered, adding about 67,000 US customers.
  • Attack vector: a Metabase SQL injection zero-day in Metabase's Cloud SaaS platform, which enabled admin access to and data theft from customer instances (no CVE id was stated in the reports).
  • Exposed ShipMonk data: names, emails, phone numbers, shipping addresses, and order numbers; no wallet credentials or recovery seed data were reported stolen. Affected orders shipped to the US, UK, Sweden, Colombia, Brazil, Italy, and…
  • ShinyHunters sent extortion emails to ShipMonk; the same Metabase exploitation campaign also hit Tally and Framework.
  • ShipMonk retained data past a 90-day deletion requirement despite repeated written deletion assurances; Trezor is considering legal action.
  • Brevo, Trezor's marketing email provider, was breached on September 9, 2026: the attacker created an account, enabled SAML SSO, and used their own identity provider to access 138 accounts (one report said 120), exfiltrating contacts from…
  • Phishing emails sent from [email protected] with subject 'Critical Security Alert: STM32 Entropy Vulnerability' reached 347,000 opted-in Trezor newsletter subscribers, claiming an STM32 microcontroller flaw exposed wallet seeds to brute-force…

Coverage timeline

  1. · 9d ago
    BleepingComputer· 70
    Trezor data breach impact now reaches 81,000 customers

    Trezor's ShipMonk breach now affects 81,000 customers, adding 67,000 US customers after Metabase exploitation by ShinyHunters-linked attackers.