Hardware wallet manufacturer Trezor disclosed Friday that a data breach at its shipping partner ShipMonk compromised the personal information of an additional 67,000 U.S. customers. The exposure comes on top of 13,689 customers the company reported as affected last month, bringing the total impact of the incident to more than 80,000 users. The breach doesn't compromise the security of Trezor's hardware wallets themselves, but exposes users to phishing and social engineering risks.

The compromised data includes customer names, email addresses, phone numbers, shipping addresses, and order numbers spanning November 2019 through August 2021, according to Trezor. ShipMonk notified Trezor of unauthorized access to its systems on August 10, 2026. The attack exploited CVE-2026-72898, a critical SQL injection vulnerability in Metabase with a maximum severity score of 10.0, and enterprise blockchain security firm Holborn attributes the breach to the ShineyHunters extortion gang. Among the newly reported victims, 1,947 customers had more limited exposure—only names, cities, and email addresses were compromised, excluding full shipping addresses—and may include older orders predating the November 2019 timeframe.

Trezor said it "repeatedly requested and received written assurance confirming the deletion of the data" from ShipMonk in line with contractual obligations and the company's 90-day data retention policy. The company expressed disappointment that despite these confirmations, ShipMonk failed to delete customer information from its systems as agreed. Trezor maintains a 90-day retention window because "it is the shortest window that still covers the whole life of an order—delivery, returns, and any refund or replacement," after which it has no reason to retain addresses or phone numbers. ShipMonk has secured the affected systems and improved security measures following the intrusion, but hasn't publicly acknowledged the incident.

The breach illustrates how supply chain vulnerabilities can expose customer data even when companies follow their own security protocols. Holborn noted that attackers exploited the zero-day flaw in Metabase to breach multiple customers of the software, stealing sensitive information and extorting affected organizations—in Trezor's case, customer order details stored in a Metabase instance by ShipMonk. The security firm emphasized that organizations need complete visibility into third-party risk exposure to manage their overall security posture effectively. Trezor has warned affected customers to watch for social engineering attacks and scams, as the leaked information "could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks." Bad actors may impersonate the company through email communications or phone calls to trick targets into unintended actions. For cryptocurrency wallet users, this presents special danger: attackers armed with verified customer contact information can craft highly convincing phishing campaigns designed to steal wallet credentials or private keys, even though the hardware devices themselves remain secure. The lifecycle tension between operational needs and privacy protection will sharpen as regulators weigh whether vendor assurances alone satisfy data minimization requirements, particularly when downstream partners control deletion timelines.