INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data

| 2026-09-05 14:17 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
On September 5, 2026, a digital break-in occurred at ShipMonk's shipping systems, involving the zero-day exploitation of CVE-2026-72898 (CVSS score: 10.0), a critical SQL injection flaw in Metabase, which exposed data from approximately 67,000 U.S. customers between November 2019 and August 2021; this breach was attributed to the ShinyHunters extortion gang by enterprise blockchain security firm Holborn. The affected entities include customer names, email addresses, phone numbers, shipping addresses, and order numbers, with Trezor stating that the data does not affect its hardware wallets' security. Following the incident, ShipMonk secured its systems and improved its security; however, it has yet to acknowledge the breach publicly, prompting Trezor to notify affected customers directly and warn users of potential social engineering attacks.
Technical Mitigations AI-generated
• Patch the Metabase version vulnerable to CVE-2026-72898 (SQL injection flaw with CVSS score: 10.0) • Implement a robust third-party risk assessment and monitoring process for supply chain attacks • Use email address scrubbing techniques to prevent phishing emails from being sent using leaked customer data
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters CVE-2026-72898CVE-2026-72898
Target & Sectors
Global Scope cryptocurrencycryptocurrency logisticslogistics manufacturingmanufacturing technologytechnology
Incident Timeline
‎November 2019
Threat actors used social engineering tactics to target ShipMonk, a cryptocurrency wallet provider, resulting in the exposure of approximately 67,000 U.S. customers' data between November 2019 and August 2021.
‎August 2021
Trezor Says ShipMonk breach exposed approximately 67,000 U.S. customers' data between November 2019 and August 2021.
‎2026/08/06
Threat actors used unknown means to expose an additional 53,311 U.S. customers' data on top of the previously disclosed 13,689 customers.
victims 13,689 customers
‎August 10, 2026
Threat actors, identified as the ShinyHunters extortion gang, exploited a critical SQL injection flaw in Metabase (CVE-2026-72898) to gain unauthorized access to ShipMonk's systems.
organisation SQL
threat_actor ShinyHunters
organisation Metabase
victims 1,947 customers
‎Sep 05, 2026
Threat actors used phishing attacks to target ShipMonk, a cryptocurrency wallet provider, resulting in the exposure of approximately 67,000 U.S. customers' data that was previously reported as deleted.
‎2026/09/05
Trezor disclosed that 67,000 U.S. customers' data was exposed in a breach at its shipping provider ShipMonk.
organisation Data Breach / Vulnerability
organisation ShipMonk
victims 67,000 customers
organisation Trezor
organisation U.S. Customers' Data
Tactical Metrics
Metrics
victims
67,000
Customers
Metrics
victims
13,689
Customers
Metrics
victims
1,947
Customers
Intelligence Sources