Trezor
August 13, 2026
49 days ago
81.0K
Estimated
Unknown
Manufacturing
A breach at Trezor's shipping and logistics provider ShipMonk, where attackers exploited a vulnerability in the third-party analytics platform Metabase on August 6, 2026, exposed customer order data including full names, shipping addresses, email addresses and phone numbers. Trezor first disclosed nearly 14,000 affected customers (orders May 10 - August 8, 2026) on August 13, then a further ~67,000 U.S. customers from November 2019 - August 2021 orders that ShipMonk had been asked to delete, bringing the total to approximately 81,000. No customer funds or crypto assets were affected.
View source