INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data
| 2026-09-05 14:17 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
On September 5, 2026, a digital break-in occurred at ShipMonk's shipping systems, involving the zero-day exploitation of CVE-2026-72898 (CVSS score: 10.0), a critical SQL injection flaw in Metabase, which exposed data from approximately 67,000 U.S. customers between November 2019 and August 2021; this breach was attributed to the ShinyHunters extortion gang by enterprise blockchain security firm Holborn. The affected entities include customer names, email addresses, phone numbers, shipping addresses, and order numbers, with Trezor stating that the data does not affect its hardware wallets' security. Following the incident, ShipMonk secured its systems and improved its security; however, it has yet to acknowledge the breach publicly, prompting Trezor to notify affected customers directly and warn users of potential social engineering attacks.
Technical Mitigations AI-generated
• Patch the Metabase version vulnerable to CVE-2026-72898 (SQL injection flaw with CVSS score: 10.0)
• Implement a robust third-party risk assessment and monitoring process for supply chain attacks
• Use email address scrubbing techniques to prevent phishing emails from being sent using leaked customer data
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
CVE-2026-72898CVE-2026-72898
Target & Sectors
Global Scope
cryptocurrencycryptocurrency
logisticslogistics
manufacturingmanufacturing
technologytechnology
Incident Timeline
November 2019
Threat actors used social engineering tactics to target ShipMonk, a cryptocurrency wallet provider, resulting in the exposure of approximately 67,000 U.S. customers' data between November 2019 and August 2021.
August 2021
Trezor Says ShipMonk breach exposed approximately 67,000 U.S. customers' data between November 2019 and August 2021.
2026/08/06
Threat actors used unknown means to expose an additional 53,311 U.S. customers' data on top of the previously disclosed 13,689 customers.
Click on any entity below to view its context and source!
victims
13,689 customers
"
The exposure is in addition to 13,689 customers the company
disclosed
last month as having had their data either fully or partially exposed.
August 10, 2026
Threat actors, identified as the ShinyHunters extortion gang, exploited a critical SQL injection flaw in Metabase (CVE-2026-72898) to gain unauthorized access to ShipMonk's systems.
Click on any entity below to view its context and source!
organisation
SQL
The logistics company is said to have secured the affected systems and improved its security after the digital break-in, which involved the zero-day exploitation of
CVE-2026-72898
(CVSS score: 10.0), a critical SQL injection flaw in Metabase.
threat_actor
ShinyHunters
According to enterprise blockchain security firm Holborn, the ShinyHunters extortion gang is said to be behind the breach.
organisation
Metabase
"
"In Trezor's case, this meant the exposure of customer order details that were stored in a Metabase instance by ShipMonk."
victims
1,947 customers
Subsequently, it revealed that the 1,947 customers whose exposure was limited only to names, cities, and email addresses (excluding the shipping addresses) may include older orders.
Sep 05, 2026
Threat actors used phishing attacks to target ShipMonk, a cryptocurrency wallet provider, resulting in the exposure of approximately 67,000 U.S. customers' data that was previously reported as deleted.
2026/09/05
Trezor disclosed that 67,000 U.S. customers' data was exposed in a breach at its shipping provider ShipMonk.
Click on any entity below to view its context and source!
organisation
Data Breach / Vulnerability
Ravie Lakshmanan
Sep 05, 2026
Data Breach / Vulnerability
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
organisation
ShipMonk
Ravie Lakshmanan
Sep 05, 2026
Data Breach / Vulnerability
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
victims
67,000 customers
Ravie Lakshmanan
Sep 05, 2026
Data Breach / Vulnerability
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data
organisation
Trezor
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data
organisation
U.S. Customers' Data
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data
Tactical Metrics
Metrics
victims
67,000
Customers
Click for context!
Ravie Lakshmanan
Sep 05, 2026
Data Breach / Vulnerability
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data
Metrics
victims
13,689
Customers
"
The exposure is in addition to 13,689 customers the company
disclosed
last month as having had their data either fully or partially exposed.
Metrics
victims
1,947
Customers
Subsequently, it revealed that the 1,947 customers whose exposure was limited only to names, cities, and email addresses (excluding the shipping addresses) may include older orders.
Intelligence Sources
The Hacker News
2026-09-05
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:05
Comprehensive Tactical Telemetry
Highly Correlated Entities
7x
timeline
Temporal Reference
2026
date
6x
organisation
Identified Entity
SQL
entity
5x
tactic
Cyber Operation Type
Data Breach
tactic
3x
victims
Customers
67,000
customers
Contextual Telemetry
Context Block
5 METRICS
industry
Targeted Sector
Logistics
sector
vulnerability
Exploited CVE
CVE-2026-72898
cve
tactic
MITRE ATT&CK Technique
T1592.001 - Hardware
technique
general metric
Sep
5
sep
threat actor
APT Group
ShinyHunters
actor
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.