Shipping Partner Breach Exposes 67,000 Trezor Customer Records, Triggers Phishing Campaigns
What Happened – Attackers exploited a zero‑day SQL injection in Metabase’s Cloud SaaS platform to gain access to ShipMonk’s systems. The breach exposed names, email addresses, phone numbers and shipping addresses of roughly 67 000 Trezor customers, leading to a wave of phishing calls, emails and physical letters.
Why It Matters for Trust & Control Assurance –
- This incident illustrates the exact scenario a continuous third‑party risk‑management program is built to prevent: unverified data‑handling practices by a logistics vendor that create a downstream phishing risk.
- Demonstrable oversight—contractual data‑deletion clauses, regular attestations, and real‑time monitoring of vendor controls—provides the audit‑ready evidence needed to show due diligence under a control‑assurance framework.
Who Is Affected – Crypto‑hardware manufacturers, logistics providers, and the 67 000 affected customers (primarily in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal).
Recommended Actions –
- Review and tighten third‑party contracts to include enforceable data‑retention and deletion requirements, with penalties for non‑compliance.
- Deploy continuous monitoring of vendor security postures (e.g., automated evidence collection of data‑deletion attestations).
- Notify affected individuals promptly and provide clear guidance on phishing detection.
- Consider anonymous delivery options (neutral packaging, locker pickup) to reduce future exposure.
Technical Notes – The breach stemmed from an SQL injection zero‑day in Metabase’s Cloud SaaS platform used by ShipMonk. No compromise of Trezor’s own hardware or firmware was reported. Source: Help Net Security