Particle.news
Download on the App Store

Trezor Says 67,000 More U.S. Customers Exposed After ShipMonk Kept Old Records

The disclosure highlights vendor retention failures traced to a Metabase SQL‑injection exploit, raising the risk of targeted phishing, impersonation and physical threats.

Overview

  • Trezor announced Friday that ShipMonk’s breach added about 67,000 U.S. customers to an earlier count, bringing the known total to roughly 80,700 affected accounts.
  • The newly identified records cover orders placed between November 2019 and August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers.
  • Investigators link the intrusion to a critical SQL‑injection flaw in the Metabase analytics tool that let attackers access ShipMonk systems, and Trezor says ShipMonk had repeatedly given written assurances that older data had been deleted.
  • Trezor says its own systems and hardware wallets were not compromised and has emailed newly identified victims while accelerating anonymous delivery options to reduce future exposure.
  • The incident underscores wider supply‑chain risk for hardware‑wallet makers because exposed customer metadata can fuel convincing scams, SIM‑swap attempts and physical targeting and may prompt legal and regulatory scrutiny of vendor practices.