INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Trezor suffers data breach impacting 81,000 customers worldwide immediately

| 2026-09-07 12:16 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On August 13, 2026, cryptocurrency hardware wallet maker Trezor disclosed that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers. The breach affected an additional 67,000 U.S. customers who ordered between November 2019 and August 2021, bringing the total number of affected customers to 81,000. The attackers exploited a vulnerability in Metabase's third-party analytics platform, gaining administrator access to compromised instances before carrying out data theft attacks. Customers from Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026 were also affected.
Technical Mitigations AI-generated
• Patch Metabase to address the critical SQL injection zero-day vulnerability exploited by attackers. • Block or hunt for ShinyHunters extortion gang emails and messages requesting personal information from affected customers. • Use a secure third-party analytics platform that has not been compromised, such as Google Analytics.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA NORDICS NORDICS cryptocurrencycryptocurrency logisticslogistics
Incident Timeline
‎between November 2019 and
Threat actors exposed personal data of approximately 67,000 US customers who ordered between November 2019 and August 2021.
target_region United States
victims 67,000 customers
‎August 2021
Threat actors exploited a critical SQL injection zero-day vulnerability in the third-party analytics platform Metabase to breach customer instances and carry out data theft attacks.
target_region United States
victims 67,000 customers
organisation Metabase
threat_actor ShinyHunters
organisation BleepingComputer
organisation SQL
organisation Framework
‎January 2024
Threat actors compromised Trezor's third-party support ticketing portal, accessing data from approximately 66,000 users in January 2024.
tactic Data Breach
victims 66,000 users
organisation The Blue Report 2026
‎August 8, 2026
Threat actors exploited a vulnerability in the Trezor wallet software to gain unauthorized access, resulting in the exposure of sensitive customer data.
‎August 13
Threat actors accessed the data of nearly 14,000 Trezor customers on August 13.
victims 81,000 customers
victims 14,000 customers
‎between May 10 and August 8, 2026
Threat actors targeted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region Brazil
target_region Colombia
target_region Italy
target_region Portugal
target_region Sweden
target_region United Kingdom
‎2026/09/07
Threat actors exploited a vulnerability in ShipMonk's systems to steal sensitive data, which was then used by Trezor to breach an additional 67,000 U.S. customers' accounts.
victims 67,000 customers
organisation ShipMonk
organisation Trezor
victims 81,000 customers
Tactical Metrics
Metrics
victims
67,000
Customers
Metrics
victims
81,000
Customers
Metrics
victims
66,000
Users
Metrics
victims
14,000
Customers
Intelligence Sources
BleepingComputer 2026-09-07