Trezor
Disclosed Aug 13, 20266 weeks ago81,000 affectedConfirmed
Trezor customer data exposed via ShipMonk Metabase breach, 81,000 affected
Hardware wallet maker Trezor said attackers exploited a Metabase SQL injection flaw at shipping provider ShipMonk and extracted customer names, addresses, emails, phone numbers and order numbers. It first reported about 14,000 affected customers and later raised the count to 81,000.
What is known
| People affected | 81,000 (as reported by the organization) |
|---|---|
| Disclosed | Aug 13, 2026 |
| Attack | Vendor breach |
| Data exposed | Names, Addresses, Emails, Phone numbers, Other |
| Sector | Crypto · CZ |
| Status | Confirmed |
| Part of | Metabase (2026) |
Sources
| Source | |
|---|---|
| Recent customer data exposed in shipping provider incidenttrezor.io · Official notice | Official notice |
| Trezor data breach impact now reaches 81,000 customersbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Aug 13 | 81,000 |
Same campaign
| Organization | Affected | ||||
|---|---|---|---|---|---|
| Sep 33 weeks ago | Supply chain | Education | Unverified | 1.1M | |
| Aug 77 weeks ago | Supply chain | Tech | Unverified | Unknown |
History of this record
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.