Shipping Provider Breach Exposes Personal Data of ~14,000 Trezor Customers
What Happened — Trezor disclosed that its shipping and logistics partner, ShipMonk, suffered a cyber‑attack that exposed order data for nearly 14,000 customers. Attackers accessed full names, shipping addresses, email addresses and phone numbers; 11,742 records were fully exposed and 1,947 partially exposed. The breach stemmed from a zero‑day SQL injection vulnerability in Metabase, the analytics platform used by ShipMonk.
Why It Matters for Compliance & Audit Readiness
- This incident is a textbook example of a third‑party data‑exposure scenario that SOC 2 vendor‑management controls are designed to prevent and document.
- Continuous monitoring of vendor security posture provides audit‑ready evidence that you’ve exercised due diligence over the supply chain.
- Mapping the breach to the SOC 2 CC6.1 (Third‑Party Risk Management) control helps demonstrate that you’ve identified, assessed and mitigated the risk of a provider’s compromise.
Who Is Affected — Hardware‑wallet manufacturers, cryptocurrency service providers, and any fintech firms that rely on third‑party logistics or analytics platforms for order fulfillment.
Recommended Actions
- Conduct an immediate third‑party risk reassessment of all logistics, analytics and shipping providers; verify that they have patched the Metabase vulnerability and have robust incident‑response processes.
- Update your SOC 2 vendor‑management policy to require continuous security monitoring and evidence collection (e.g., quarterly security attestations, penetration‑test reports).
- Notify affected customers, provide phishing‑awareness guidance, and monitor for credential‑theft attempts.
Source: BleepingComputer
Technical Notes
- Attack vector: exploitation of a critical SQL‑injection zero‑day in Metabase, leading to unauthorized access to ShipMonk’s customer database.
- Data types compromised: full name, email, phone number, shipping address (full exposure) and name, city, email (partial exposure).
Source: BleepingComputer