HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Shipping Provider Breach Exposes Personal Data of ~14,000 Trezor Customers

Trezor disclosed that its logistics partner ShipMonk was hacked, leaking names, addresses, emails and phone numbers of nearly 14,000 customers across multiple countries. The incident underscores the need for robust vendor‑risk management and SOC 2 controls over third‑party data handling.

LiveThreat™ Intelligence · 📅 August 14, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Shipping Provider Breach Exposes Personal Data of ~14,000 Trezor Customers

What Happened — Trezor disclosed that its shipping and logistics partner, ShipMonk, suffered a cyber‑attack that exposed order data for nearly 14,000 customers. Attackers accessed full names, shipping addresses, email addresses and phone numbers; 11,742 records were fully exposed and 1,947 partially exposed. The breach stemmed from a zero‑day SQL injection vulnerability in Metabase, the analytics platform used by ShipMonk.

Why It Matters for Compliance & Audit Readiness

  • This incident is a textbook example of a third‑party data‑exposure scenario that SOC 2 vendor‑management controls are designed to prevent and document.
  • Continuous monitoring of vendor security posture provides audit‑ready evidence that you’ve exercised due diligence over the supply chain.
  • Mapping the breach to the SOC 2 CC6.1 (Third‑Party Risk Management) control helps demonstrate that you’ve identified, assessed and mitigated the risk of a provider’s compromise.

Who Is Affected — Hardware‑wallet manufacturers, cryptocurrency service providers, and any fintech firms that rely on third‑party logistics or analytics platforms for order fulfillment.

Recommended Actions

  • Conduct an immediate third‑party risk reassessment of all logistics, analytics and shipping providers; verify that they have patched the Metabase vulnerability and have robust incident‑response processes.
  • Update your SOC 2 vendor‑management policy to require continuous security monitoring and evidence collection (e.g., quarterly security attestations, penetration‑test reports).
  • Notify affected customers, provide phishing‑awareness guidance, and monitor for credential‑theft attempts.

Source: BleepingComputer

Technical Notes

  • Attack vector: exploitation of a critical SQL‑injection zero‑day in Metabase, leading to unauthorized access to ShipMonk’s customer database.
  • Data types compromised: full name, email, phone number, shipping address (full exposure) and name, city, email (partial exposure).

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →