INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Trezor Discloses Data Breach Affecting Nearly 14,000 Customers Worldwide

| 2026-08-13 15:13 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On August 10, 2026, Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked. The attackers gained access to customers' order data from May 10th to August 8th, 2026, including full names, shipping addresses, email addresses, and phone numbers. This incident affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. ShipMonk's systems were breached by exploiting a vulnerability in Metabase's software, which was later patched. The breach resulted in 11,742 customers experiencing full exposure of their data and 1,947 with partial exposure.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORDICS NORDICS NORTH_AMERICA NORTH_AMERICA cryptocurrencycryptocurrency logisticslogistics manufacturingmanufacturing
Incident Timeline
‎January 2024
Threat actors used a vulnerability in the Trezor Support system to potentially expose sensitive information of nearly 14,000 customers.
victims 66,000 users
‎August 6, 2026
Threat actors gained access to Trezor's third-party support ticketing portal, leading the company to disclose a data breach in January 2024.
threat_actor ShinyHunters
‎August 10, 2026
Threat actors exploited a vulnerability in Metabase's software to access data related to nearly 14,000 Trezor customers' accounts.
victims 11,742 customers
victims 1,947 customers
‎2026/08/13
Threat actors hacked ShipMonk, a shipping and logistics provider used by Trezor.
victims 14,000 customers
Tactical Metrics
Metrics
victims
14,000
Customers
Metrics
victims
66,000
Users
Metrics
victims
11,742
Customers
Metrics
victims
1,947
Customers
Intelligence Sources
BleepingComputer 2026-08-13