{Hardware} pockets producer Trezor has disclosed a knowledge breach affecting near 14,000 clients after ShipMonk, the corporate’s transport and logistics supplier, was hacked.
What was uncovered
Attackers gained entry to buyer order information, together with full names, transport addresses, e-mail addresses, and cellphone numbers.
In a weblog publish printed Thursday, Trezor stated the incident hit clients in the USA, the UK, Sweden, Colombia, Brazil, Italy, and Portugal who obtained orders between Might 10 and August 8, 2026.
The corporate wrote:
“On Monday, August 10, 2026, considered one of our transport suppliers, ShipMonk, knowledgeable us of unauthorized entry to their methods containing buyer information. The incident impacts 11,742 clients with full publicity (identify, e-mail, cellphone quantity, transport tackle) and 1,947 clients with partial publicity (identify, metropolis, e-mail).”
Phishing danger for pockets homeowners
Trezor burdened that its personal methods have been untouched and that operations, providers, and gadgets stay safe, however warned that leaked transport information makes affected consumers prime targets for social engineering.
The corporate famous:
“Scammers can use the leaked info to ship faux emails, make faux cellphone calls, ship fraudulent letters, or doubtlessly impersonate banks, crypto exchanges, and even Trezor.”
In notification emails to clients, ShipMonk stated the attackers exploited a vulnerability within the third-party analytics platform Metabase, which has since been patched with all lively periods invalidated.
Metabase beforehand confirmed {that a} crucial SQL injection zero-day was used to achieve administrator entry to buyer cases, with laptop computer maker Framework and type builder Tally additionally caught up in the identical marketing campaign.
This isn’t Trezor’s first incident of this type.
In January 2024, a breach of its third-party assist ticketing portal uncovered information on 66,000 customers, and attackers later used that info in phishing makes an attempt geared toward tricking victims into handing over their 24-word restoration seeds.