INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Trezor Discloses Data Breach Affecting Nearly 14,000 Customers Worldwide
| 2026-08-13 15:13 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On August 10, 2026, Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked. The attackers gained access to customers' order data from May 10th to August 8th, 2026, including full names, shipping addresses, email addresses, and phone numbers. This incident affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. ShipMonk's systems were breached by exploiting a vulnerability in Metabase's software, which was later patched. The breach resulted in 11,742 customers experiencing full exposure of their data and 1,947 with partial exposure.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORDICS
NORDICS
NORTH_AMERICA
NORTH_AMERICA
cryptocurrencycryptocurrency
logisticslogistics
manufacturingmanufacturing
Incident Timeline
January 2024
Threat actors used a vulnerability in the Trezor Support system to potentially expose sensitive information of nearly 14,000 customers.
Click on any entity below to view its context and source!
victims
66,000 users
The hardware cryptocurrency wallet vendor revealed at the time that 66,000 users who have interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed during the incident.
August 6, 2026
Threat actors gained access to Trezor's third-party support ticketing portal, leading the company to disclose a data breach in January 2024.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
BleepingComputer has since learned that ShipMonk has also received extortion emails from the ShinyHunters extortion gang.
August 10, 2026
Threat actors exploited a vulnerability in Metabase's software to access data related to nearly 14,000 Trezor customers' accounts.
Click on any entity below to view its context and source!
victims
11,742 customers
"The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).
victims
1,947 customers
"The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).
2026/08/13
Threat actors hacked ShipMonk, a shipping and logistics provider used by Trezor.
Click on any entity below to view its context and source!
victims
14,000 customers
Trezor discloses data breach affecting nearly 14,000 customers.
Tactical Metrics
Metrics
victims
14,000
Customers
Click for context!
Trezor discloses data breach affecting nearly 14,000 customers.
Metrics
victims
66,000
Users
The hardware cryptocurrency wallet vendor revealed at the time that 66,000 users who have interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed during the incident.
Metrics
victims
11,742
Customers
"The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).
Metrics
victims
1,947
Customers
"The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).
Intelligence Sources
BleepingComputer
2026-08-13
Trezor discloses data breach affecting nearly 14,000 customers
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T12:18
Comprehensive Tactical Telemetry
Highly Correlated Entities
8x
timeline
Temporal Reference
between May 10th and August 8th, 2026
date
8x
organisation
Identified Entity
ShipMonk
entity
7x
target region
Target Country
United States
country
4x
tactic
Cyber Operation Type
Data Breach
tactic
3x
victims
Customers
14,000
customers
2x
industry
Targeted Sector
Logistics
sector
Contextual Telemetry
Context Block
8 METRICS
tactic
MITRE ATT&CK Technique
T1592.001 - Hardware
technique
general metric
Breach
14,000
breach
source region
Origin Region
EUROPE
region
threat actor
APT Group
ShinyHunters
actor
general metric
Word
24
word
victims
Users
66,000
users
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.