Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Shipping partner breach exposes data of 14,000 Trezor customers

Дата публикации: 13-08-2026 19:30:57

Nearly 14,000 Trezor buyers had their names and contact details stolen after ShipMonk, the hardware wallet maker’s shipping partner, was hacked.  The people affected now face a heightened risk of phishing and, in some cases, theft at their home addresses, as French users have experienced. What details were exposed in the Trezor leak?  Trezor reported...

Основное содержимое страницы с новостью.

Nearly 14,000 Trezor buyers had their names and contact details stolen after ShipMonk, the hardware wallet maker’s shipping partner, was hacked. 

The people affected now face a heightened risk of phishing and, in some cases, theft at their home addresses, as French users have experienced.

What details were exposed in the Trezor leak? 

Trezor reported via its blog post that it became aware of the breach of the systems holding its order data when ShipMonk shared the information on Monday, August 10. 

Specifically, the orders shipped between May 10 and August 8 were affected, Trezor’s own infrastructure was untouched, and user wallets themselves remain secure. 

The company said there are 11,742 people whose names, email addresses, phone numbers, and shipping addresses were all taken, and another 1,947 who only had their names, cities, and email addresses taken. That puts the running total at 13,689 victims. 

Trezor revealed that the buyers spanned seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. 

The damage was slightly minimized due to ShipMonk’s policy of deleting or anonymizing order records three months after delivery. Trezor said that customers who bought through Amazon were spared as those orders moved through a different fulfillment channel.

The company has experienced similar incidents in the past, but Trezor said this was the first attack to expose customer phone numbers and shipping addresses. The company’s third-party support portal was breached in January 2024, affecting  66,000 users, and a separate 2022 event affected more than 106,000.  

How did the Trezor hack happen? 

ShipMonk said the attackers took advantage of a flaw in Metabase, an analytics platform it uses. Metabase publicly flagged the problem itself on August 6. 

The bug was a critical SQL injection zero-day that handed intruders administrator access, and the same campaign hit other companies, including laptop maker Framework and form builder Tally. 

Since then, despite Trezor saying it has no evidence the stolen records have been published, sold or used in any scam so far, ShipMonk has been receiving extortionary emails from the ShinyHunters group.

Ledger, Trezor’s main rival, saw a 2020 breach spill data on hundreds of thousands of users, and, as Cryptopolitan has reported, scammers were still mailing Ledger owners fake “Quantum Resistance Security Update” letters with malicious QR codes as recently as May 2026. Ledger disclosed a separate leak through its payment processor Global-e in January.

Worryingly, criminals have started using leaked personal data to pick targets for kidnappings and home invasions aimed at forcing victims to surrender their crypto. Chainalysis reported that more than $30 million was taken in violent attacks in the first half of 2026, and it is on track to pass 2025’s full-year figure of $58 million. 

Trezor said affected customers were notified by email. It is also promising a more private shipping option equipped with lockers, neutral packaging, and automatic deletion of address data after delivery, aiming to launch in the EU by September and in the U.S. by year’s end.

The smartest crypto minds already read our newsletter. Want in? Join them.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Trezor сообщил об утечке данных почти 14 тысяч владельцев криптокошельков018.1713-08-2026
2Security Leaders Discuss Texas Hunting, Fishing License Data Breach 0526-06-2026
3Så många berörs av dataintrånget mot Ryde01012-08-2026
4Password manager maker LastPass says hackers stole customer support case data during Klue breach-2523-06-2026
5Texas government data breach allowed hackers to steal 3 million driver’s licenses and passports-2618-06-2026
6Nearly 12,000 military Tricare beneficiaries warned of data breach013.6713-07-2026
7Хакеры украли биткойны на $86 млн из офлайн-криптокошельков027.6503-08-2026
8Massive cyber attack sees hackers steal half a million pieces of data from Department for Education05.229-07-2026
9NullReceiver ditches the burn address that made EtherHiding easy to spot01013-08-2026
10Kodak Breach Adds to ShinyHunters’ Growing Data Extortion Wave0717-06-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 10.09. Источник: www.cryptopolitan.com.