TTO-2026-0905-106 · September 5, 2026 Data BreachVendor Incident

Trezor Discloses Sixfold Expansion of Vendor Breach at ShipMonk — 67,000 More U.S. Customers Exposed

trezor.ioShipMonk vendor breach~80,000 customers totalMetabase platform flawWallets and private keys not affected

Summary

Hardware wallet maker Trezor disclosed on September 4, 2026 that a breach at its former shipping and fulfillment vendor, ShipMonk, has grown sixfold in scope. Roughly 67,000 additional U.S. customers had contact and order data exposed after years-old records — which ShipMonk had repeatedly assured Trezor in writing were deleted — remained in the vendor's systems and were accessed without authorization. Combined with an initial August 13 disclosure covering roughly 13,689 fully exposed and 1,947 partially exposed customers, the total now stands at approximately 80,000 affected people, though Trezor has not published a single combined, de-duplicated figure. Trezor states the breach did not affect the security of its hardware wallets, recovery seeds, or private keys — this is a contact-and-order-data exposure at a third-party vendor, not a wallet-security compromise.

Timeline

DateEvent
Aug 10, 2026ShipMonk informs Trezor of unauthorized access, traced to a Metabase platform vulnerability
Aug 13, 2026Trezor's initial disclosure: 13,689 customers fully exposed, 1,947 partially exposed
Sept 2, 2026ShipMonk informs Trezor that older, supposedly-deleted order records (Nov 2019 – Aug 2021) were also exposed
Sept 4, 2026Trezor discloses ~67,000 additional affected U.S. customers; running total approx. 80,000

What Happened

ShipMonk informed Trezor of unauthorized access on August 10, 2026, tracing the intrusion to a vulnerability in Metabase, a third-party analytics platform ShipMonk used internally. The flaw reportedly allowed an attacker to create a session tied to an administrator account and download data tables in bulk. Trezor's initial disclosure covered orders placed between May 10 and August 8, 2026. On September 2, ShipMonk informed Trezor that the incident also exposed older order records — from November 2019 through August 2021 — that Trezor believed had already been purged under a contractual 90-day retention policy.

Trezor said in its update: "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." Exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor has emailed all affected customers directly and is warning of an elevated risk of phishing, fraudulent mail, and other social-engineering attempts referencing the exposed data.

Domain Intelligence

trezor.io — 61.76

Score sits in the low-trust range described in WarmBadge's published tiering. One contributing signal reflects thin corroboration from the network-topology layer — a documented coverage artifact in WarmBadge's own validation framework, not itself an indication of a trust problem. A separate signal notes that one threat-intelligence source flagged an item that has not yet been independently corroborated by other sources; per WarmBadge's methodology, an uncorroborated single-source flag does not reduce the published score on its own.

WarmBadge withheld ShipMonk's network score because the current topology evidence for shipmonk.com did not meet the threshold required for publication. ShipMonk remains part of the factual record above as the vendor where the underlying vulnerability and data-retention failure occurred.
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 5, 2026