Trezor data breach impact now reaches 81,000 customers

A major cryptocurrency hardware wallet maker has revealed that a recent data breach at its shipping and logistics provider has affected an additional 67,000 U.S. customers, bringing the total number of impacted individuals to 81,000. The incident highlights the need for companies to prioritize data protection and vigilance in their supply chains.

The breach occurred at ShipMonk, which provides shipping and logistics services to Trezor. According to Trezor, attackers accessed customer data, including full names, shipping addresses, email addresses, and phone numbers. This information was exposed due to a vulnerability in the third-party analytics platform Metabase, which was used by ShipMonk.

The incident is particularly concerning because it demonstrates how a single weak link in a company’s supply chain can compromise sensitive customer data. Trezor had repeatedly requested that ShipMonk delete the exposed data from its systems, but the request was not fulfilled. As a result, the breach has had far-reaching consequences for affected customers.

Trezor is urging its customers to be cautious of potential phishing attacks, which could exploit the leaked information to trick individuals into revealing sensitive details or handing over control of their wallets. The company’s warning comes as part of a broader trend of companies and organizations falling victim to data breaches, often due to vulnerabilities in third-party software.

The Metabase campaign has already resulted in multiple data breaches at other companies, including online form-building platform Tally and laptop maker Framework. Meanwhile, ShipMonk itself has received extortion emails from the ShinyHunters gang, further highlighting the risks associated with data breaches.

Trezor’s experience is a stark reminder of the importance of robust cybersecurity measures, not just for individual companies but also for their supply chains. By prioritizing data protection and collaboration with partners, organizations can reduce the risk of data breaches and minimize their impact on customers.

For individuals who may be affected by this breach, it’s essential to remain vigilant and take proactive steps to protect themselves from potential phishing attacks. This includes being wary of unsolicited messages requesting personal information or login credentials. By staying informed and taking necessary precautions, you can reduce your risk of falling victim to a data breach-related scam.

In light of the Trezor breach, it’s crucial for individuals to prioritize their own cybersecurity, particularly when it comes to sensitive financial information. By being aware of potential vulnerabilities in third-party software and supply chains, you can take proactive steps to protect yourself from data breaches.


Source: Bleeping Computer — 2026-09-07