HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Shipping Partner Breach Exposes 67,000 Trezor Customer Records, Triggers Phishing Campaigns

A zero‑day SQL injection in Metabase’s Cloud SaaS platform allowed attackers to steal personal data of ~67 000 Trezor customers from the shipping partner ShipMonk. The exposed data is now being used for phishing calls, emails and physical letters, highlighting the need for robust third‑party risk oversight and continuous control‑assurance evidence.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
helpnetsecurity.com

Shipping Partner Breach Exposes 67,000 Trezor Customer Records, Triggers Phishing Campaigns

What Happened – Attackers exploited a zero‑day SQL injection in Metabase’s Cloud SaaS platform to gain access to ShipMonk’s systems. The breach exposed names, email addresses, phone numbers and shipping addresses of roughly 67 000 Trezor customers, leading to a wave of phishing calls, emails and physical letters.

Why It Matters for Trust & Control Assurance

  • This incident illustrates the exact scenario a continuous third‑party risk‑management program is built to prevent: unverified data‑handling practices by a logistics vendor that create a downstream phishing risk.
  • Demonstrable oversight—contractual data‑deletion clauses, regular attestations, and real‑time monitoring of vendor controls—provides the audit‑ready evidence needed to show due diligence under a control‑assurance framework.

Who Is Affected – Crypto‑hardware manufacturers, logistics providers, and the 67 000 affected customers (primarily in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal).

Recommended Actions

  1. Review and tighten third‑party contracts to include enforceable data‑retention and deletion requirements, with penalties for non‑compliance.
  2. Deploy continuous monitoring of vendor security postures (e.g., automated evidence collection of data‑deletion attestations).
  3. Notify affected individuals promptly and provide clear guidance on phishing detection.
  4. Consider anonymous delivery options (neutral packaging, locker pickup) to reduce future exposure.

Technical Notes – The breach stemmed from an SQL injection zero‑day in Metabase’s Cloud SaaS platform used by ShipMonk. No compromise of Trezor’s own hardware or firmware was reported. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/08/trezor-shipping-partner-breach-phishing-attacks/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →