Cybersecurity firm Trezor has disclosed a data breach that affects nearly 14,000 of its customers. The incident occurred when ShipMonk, Trezor’s shipping and logistics provider, was hacked by attackers who exploited a vulnerability in the third-party analytics platform Metabase. As a result, customers’ order data, including their full names, shipping addresses, email addresses, and phone numbers, were accessed.
The breach is significant because it highlights the importance of security not just for companies themselves but also for their partners and vendors. Trezor’s operations or services were not impacted by the breach, but its customers’ sensitive information was compromised. The company has warned affected customers to be wary of any messages requesting personal information, as they may see an increase in phishing attempts.
Trezor’s data breach is just one of several incidents that have involved Metabase being exploited by attackers. In a recent report, it was revealed that threat actors used a critical SQL injection zero-day vulnerability to breach customer instances and carry out data theft attacks after gaining administrator access to the compromised instance. Other companies that have been affected by this vulnerability include laptop maker Framework and online form builder Tally.
It’s worth noting that Trezor has had issues with security in the past. In January 2024, the company disclosed a data breach after threat actors gained access to its third-party support ticketing portal. At the time, it was revealed that 66,000 users who have interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed during the incident.
The incident also highlights the importance of security in supply chain management. Companies often rely on third-party vendors to provide services such as shipping and logistics, but these vendors can be vulnerable to cyber attacks if they do not have robust security measures in place. As a result, companies must carefully vet their vendors and ensure that they have adequate security controls in place.
In the wake of this incident, Trezor is advising affected customers to be vigilant about any suspicious activity related to their accounts. This includes being cautious of emails or phone calls requesting personal information, as well as monitoring their credit reports for any signs of identity theft. By taking these precautions, customers can minimize the risk of falling victim to phishing attacks or other forms of cybercrime.
Ultimately, this incident serves as a reminder that cybersecurity is not just an individual responsibility but also a collective one. Companies must work together with their vendors and partners to ensure that they have robust security measures in place to protect against cyber threats. By doing so, we can create a safer online environment for everyone.
Source: Bleeping Computer — 2026-08-13