HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

ShipMonk Shipping Provider Breach Exposes Personal Data of 67,000 Trezor Customers

Trezor disclosed that its logistics partner ShipMonk suffered a breach that exposed names, emails, phone numbers, shipping addresses, and order numbers of 67,000 U.S. customers collected between 2019 and 2021. While wallet keys remain safe, the incident highlights the need for continuous vendor oversight and audit‑ready evidence of third‑party controls.

Verisq™ Intelligence · 📅 September 06, 2026 · 📰 thehackernews.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

ShipMonk Shipping Provider Breach Exposes Personal Data of 67,000 Trezor Customers

What Happened – Trezor disclosed that its third‑party logistics partner ShipMonk suffered a breach that exposed the names, email addresses, phone numbers, shipping addresses, and order numbers of 67,000 U.S. customers collected between November 2019 and August 2021. The incident does not compromise the cryptographic security of Trezor’s hardware wallets.

Why It Matters for Trust & Control Assurance

  • This is a textbook example of a supply‑chain data exposure that a continuous control‑assurance program is built to detect, document, and remediate.
  • Effective third‑party risk management requires ongoing monitoring, evidence collection, and audit‑ready documentation of vendor security controls.
  • Demonstrating that you have verified your vendors’ data‑handling practices satisfies a core control objective that maps to multiple frameworks (e.g., NIST CSF 2.0 “Supply Chain Risk Management”).

Who Is Affected – Cryptocurrency hardware‑wallet users (financial‑services‑oriented customers) and any organization that relies on third‑party logistics or fulfillment services for handling personally identifiable information (PII).

Recommended Actions

  • Inventory all third‑party service providers that process PII and classify them by risk.
  • Verify that each vendor maintains documented security controls, incident‑response procedures, and regular audit evidence.
  • Integrate continuous monitoring of vendor security posture into your control‑assurance platform to produce defensible audit trails.

Source: The Hacker News

Technical Notes – The breach originated from ShipMonk’s internal systems; no specific vulnerability or CVE was disclosed. Exposed data includes customer names, email addresses, phone numbers, shipping addresses, and order numbers. No wallet private keys or cryptocurrency holdings were compromised.

📰 Original Source
https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →