ShipMonk Breach Exposes 14,000 Trezor Customer Records
TL;DR. A data breach at ShipMonk exposed personal shipping information for nearly 14,000 Trezor hardware wallet customers. - Hackers stole names, addresses, emails, and phone numbers via a vulnerability in the Metabase platform. - Trezor confirmed its internal systems and devices remain secure, but warned of potential sophisticated phishing attempts. - The incident impacts customers from multiple countries who ordered between May and August.
- ShipMonk data breach compromised 14,000 Trezor customer records.
- Stolen data includes names, addresses, emails, and phone numbers.
- Breach exploited a Metabase vulnerability, likely a SQL injection zero-day.
- Trezor's own systems and hardware wallets were not directly affected.
- Affected customers are advised to watch for phishing attempts.
Sources
- 14,000 Trezor Customers Impacted by Data Breach at ShipMonk — securityweek.com