INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Trezor suffers data breach impacting 81,000 customers worldwide immediately
| 2026-09-07 12:16 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On August 13, 2026, cryptocurrency hardware wallet maker Trezor disclosed that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers. The breach affected an additional 67,000 U.S. customers who ordered between November 2019 and August 2021, bringing the total number of affected customers to 81,000. The attackers exploited a vulnerability in Metabase's third-party analytics platform, gaining administrator access to compromised instances before carrying out data theft attacks. Customers from Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026 were also affected.
Technical Mitigations AI-generated
• Patch Metabase to address the critical SQL injection zero-day vulnerability exploited by attackers.
• Block or hunt for ShinyHunters extortion gang emails and messages requesting personal information from affected customers.
• Use a secure third-party analytics platform that has not been compromised, such as Google Analytics.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
NORDICS
NORDICS
cryptocurrencycryptocurrency
logisticslogistics
Incident Timeline
between November 2019 and
Threat actors exposed personal data of approximately 67,000 US customers who ordered between November 2019 and August 2021.
Click on any entity below to view its context and source!
target_region
United States
"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed,"
Trezor said
.
victims
67,000 customers
"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed,"
Trezor said
.
August 2021
Threat actors exploited a critical SQL injection zero-day vulnerability in the third-party analytics platform Metabase to breach customer instances and carry out data theft attacks.
Click on any entity below to view its context and source!
target_region
United States
"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed,"
Trezor said
.
victims
67,000 customers
"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed,"
Trezor said
.
organisation
Metabase
Metabase campaign linked to ShinyHunters extortion gang
While the company has yet to share how ShipMonk's systems were breached, breach notification emails sent to affected customers and seen by BleepingComputer said the attackers exploited a vulnerability in the third-party analytics platform Metabase.
threat_actor
ShinyHunters
Metabase campaign linked to ShinyHunters extortion gang
While the company has yet to share how ShipMonk's systems were breached, breach notification emails sent to affected customers and seen by BleepingComputer said the attackers exploited a vulnerability in the third-party analytics platform Metabase.
BleepingComputer has also learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang.
organisation
BleepingComputer
Metabase campaign linked to ShinyHunters extortion gang
While the company has yet to share how ShipMonk's systems were breached, breach notification emails sent to affected customers and seen by BleepingComputer said the attackers exploited a vulnerability in the third-party analytics platform Metabase.
organisation
SQL
As
BleepingComputer previously reported
, Metabase revealed that the threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances and carry out data theft attacks after gaining administrator access to the compromised instance.
organisation
Framework
The list of affected companies in the Metabase campaign includes online form-building platform Tally and laptop maker Framework, which have also notified customers of data breaches after their instances were hijacked.
January 2024
Threat actors compromised Trezor's third-party support ticketing portal, accessing data from approximately 66,000 users in January 2024.
Click on any entity below to view its context and source!
tactic
Data Breach
In January 2024, Trezor
disclosed another data breach
after threat actors compromised its third-party support ticketing portal and accessed data (e.g., names, usernames, and email addresses) from roughly 66,000 users.
victims
66,000 users
In January 2024, Trezor
disclosed another data breach
after threat actors compromised its third-party support ticketing portal and accessed data (e.g., names, usernames, and email addresses) from roughly 66,000 users.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
August 8, 2026
Threat actors exploited a vulnerability in the Trezor wallet software to gain unauthorized access, resulting in the exposure of sensitive customer data.
August 13
Threat actors accessed the data of nearly 14,000 Trezor customers on August 13.
Click on any entity below to view its context and source!
victims
81,000 customers
In total, the breach has affected 81,000 customers after
Trezor initially disclosed
on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers.
victims
14,000 customers
In total, the breach has affected 81,000 customers after
Trezor initially disclosed
on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers.
between May 10 and August 8, 2026
Threat actors targeted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
Click on any entity below to view its context and source!
target_region
Brazil
As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Colombia
As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Italy
As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Portugal
As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Sweden
As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
United Kingdom
As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
2026/09/07
Threat actors exploited a vulnerability in ShipMonk's systems to steal sensitive data, which was then used by Trezor to breach an additional 67,000 U.S. customers' accounts.
Click on any entity below to view its context and source!
victims
67,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.
organisation
ShipMonk
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.
organisation
Trezor
Trezor data breach impact now reaches 81,000 customers.
victims
81,000 customers
Trezor data breach impact now reaches 81,000 customers.
Tactical Metrics
Metrics
victims
67,000
Customers
Click for context!
"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed,"
Trezor said
.
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.
Metrics
victims
81,000
Customers
Trezor data breach impact now reaches 81,000 customers.
In total, the breach has affected 81,000 customers after
Trezor initially disclosed
on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers.
Metrics
victims
66,000
Users
In January 2024, Trezor
disclosed another data breach
after threat actors compromised its third-party support ticketing portal and accessed data (e.g., names, usernames, and email addresses) from roughly 66,000 users.
Metrics
victims
14,000
Customers
In total, the breach has affected 81,000 customers after
Trezor initially disclosed
on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers.
Intelligence Sources
BleepingComputer
2026-09-07
Trezor data breach impact now reaches 81,000 customers
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:58
Comprehensive Tactical Telemetry
Highly Correlated Entities
7x
target region
Target Country
Brazil
country
7x
organisation
Identified Entity
ShipMonk
entity
6x
timeline
Temporal Reference
between May 10 and August 8, 2026
date
3x
victims
Customers
67,000
customers
3x
tactic
Cyber Operation Type
Data Breach
tactic
Contextual Telemetry
Context Block
6 METRICS
industry
Targeted Sector
Logistics
sector
threat actor
APT Group
ShinyHunters
actor
victims
Users
66,000
users
general metric
Word
24
word
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.