Overview
- Trezor said the breach grew after investigators found ShipMonk retained older order records, adding roughly 67,000 U.S. customers to an earlier disclosure and bringing the total affected to about 81,000.
- Stolen fields include full names, email addresses, phone numbers, shipping addresses and order numbers, data that can be used to craft convincing scams or locate customers in person.
- Security reporting links the intrusion to a critical SQL‑injection zero‑day in the Metabase analytics platform that has been used against multiple companies and was followed by extortion messages tied to the ShinyHunters group.
- Trezor says its own systems and hardware wallets were not compromised and that it is notifying victims, accelerating anonymous delivery options, and evaluating legal action against ShipMonk.
- The incident highlights supplier data‑retention failures and raises the risk of targeted phishing, SIM‑swap and physical attacks for customers while increasing scrutiny of vendor controls across the hardware‑wallet industry.