INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Trezor Warns Users of Email Provider Breach and Phishing Attacks
| 2026-09-10 06:56 CRITICAL LOW DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
On September 10, 2026, cryptocurrency hardware wallet maker Trezor warned customers of a phishing attack and data breach that targeted nearly 81,000 users in the United States, Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom. The attackers exploited a vulnerability in ShipMonk's Metabase analytics platform to gain administrator access and steal customer order data between May 10 and August 8, 2026. Trezor stated that it had taken down its third-party email provider domain to stop phishing attacks targeting customers with fake "Critical Security Alert" emails claiming a hardware microcontroller vulnerability in STM32 microcontrollers could expose their seeds to brute-force cracking.
Technical Mitigations AI-generated
• Block phishing emails from <a href="/auth/login?next=/detail/cPfQiqABGvYhsJJTdDnT" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> and any other suspicious email addresses.
• Use a secure password manager to generate strong, unique passwords for Trezor accounts.
• Regularly update the Metabase analytics platform to patch the critical SQL injection zero-day vulnerability.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
he•••@tr•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
NORDICS
NORDICS
cryptocurrencycryptocurrency
logisticslogistics
Incident Timeline
January 2024
Trezor disclosed a data breach after its third-party support ticketing portal was compromised, exposing approximately 66,000 users' names, usernames, and email addresses.
Click on any entity below to view its context and source!
tactic
Data Breach
In January 2024, Trezor
disclosed another data breach
after its third-party support ticketing portal was compromised and the attackers accessed data (e.g., names, usernames, and email addresses) from roughly 66,000 users.
victims
66,000 users
In January 2024, Trezor
disclosed another data breach
after its third-party support ticketing portal was compromised and the attackers accessed data (e.g., names, usernames, and email addresses) from roughly 66,000 users.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
August 8, 2026
Threat actors exploited a critical SQL injection zero-day vulnerability in the Metabase analytics platform to breach customer instances and steal data.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
BleepingComputer has also learned that ShipMonk received extortion emails from the ShinyHunters extortion gang after the breach.
organisation
BleepingComputer
While it didn't say how ShipMonk's systems were breached, breach notification emails seen by BleepingComputer said the attackers exploited a vulnerability in the Metabase analytics platform.
organisation
Metabase
While it didn't say how ShipMonk's systems were breached, breach notification emails seen by BleepingComputer said the attackers exploited a vulnerability in the Metabase analytics platform.
organisation
SQL
In early August,
Metabase said
the threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances, gain administrator access, and steal data.
between May 10 and August 8, 2026
Threat actors used phishing attacks to target customers of an email provider who received orders between May 10 and August 8, 2026.
Click on any entity below to view its context and source!
target_region
Brazil
As Trezor explained, the data breach also impacted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Colombia
As Trezor explained, the data breach also impacted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Italy
As Trezor explained, the data breach also impacted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Portugal
As Trezor explained, the data breach also impacted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Sweden
As Trezor explained, the data breach also impacted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
United Kingdom
As Trezor explained, the data breach also impacted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
tactic
Data Breach
As Trezor explained, the data breach also impacted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
2026/09/10
Threat actors who breached Trezor's third-party email provider are targeting users in phishing attacks.
Click on any entity below to view its context and source!
organisation
Trezor
Trezor warns users of email provider breach, phishing attacks.
organisation
ShipMonk
"We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain."
Trezor also
disclosed a data breach
in August after attackers hacked ShipMonk, its shipping and logistics provider, and stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers.
organisation
STM32
Affected customers received fake "critical security alert" emails from [email protected] claiming that a "hardware microcontroller vulnerability" in the STM32 microcontrollers used by Trezor cold storage wallets could expose their seeds to brute-force cracking.
victims
14,000 customers
While the company initially said the incident affected
nearly 14,000 customers
, a Friday update warned that a follow-up investigation found the breach affected
an additional 67,000 U.S. customers
, bringing the total to 81,000.
victims
67,000 additional U.S. customers
While the company initially said the incident affected
nearly 14,000 customers
, a Friday update warned that a follow-up investigation found the breach affected
an additional 67,000 U.S. customers
, bringing the total to 81,000.
Tactical Metrics
Metrics
victims
66,000
Users
Click for context!
In January 2024, Trezor
disclosed another data breach
after its third-party support ticketing portal was compromised and the attackers accessed data (e.g., names, usernames, and email addresses) from roughly 66,000 users.
Metrics
victims
14,000
Customers
While the company initially said the incident affected
nearly 14,000 customers
, a Friday update warned that a follow-up investigation found the breach affected
an additional 67,000 U.S. customers
, bringing the total to 81,000.
Metrics
victims
67,000
Additional U.S. Customers
While the company initially said the incident affected
nearly 14,000 customers
, a Friday update warned that a follow-up investigation found the breach affected
an additional 67,000 U.S. customers
, bringing the total to 81,000.
Intelligence Sources
BleepingComputer
2026-09-10
Trezor warns users of email provider breach, phishing attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:21
Comprehensive Tactical Telemetry
Highly Correlated Entities
7x
target region
Target Country
United States
country
7x
organisation
Identified Entity
ShipMonk
entity
3x
tactic
Cyber Operation Type
Phishing
tactic
3x
timeline
Temporal Reference
between May 10 and August 8, 2026
date
Contextual Telemetry
Context Block
7 METRICS
industry
Targeted Sector
Logistics
sector
threat actor
APT Group
ShinyHunters
actor
victims
Users
66,000
users
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
victims
Customers
14,000
customers
victims
Additional U.S. Customers
67,000
additional u.s. customers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.