Trezor disclosed that a breach at shipping provider ShipMonk exposed personal data for another 67,000 U.S. customers, including names, email addresses, phone numbers, shipping addresses, and order numbers. The incident, linked to a zero-day exploit in Metabase and attributed to the ShinyHunters extortion gang, did not affect the security of Trezor hardware wallets but may fuel phishing, impersonation, and scam attempts. #Trezor #ShipMonk #ShinyHunters #Metabase #CVE-2026-72898
Keypoints
- Trezor says 67,000 more U.S. customers were affected in a ShipMonk breach.
- Exposed data included names, emails, phone numbers, shipping addresses, and order numbers.
- The breach did not compromise the security of Trezor hardware wallets.
- The attack involved zero-day exploitation of CVE-2026-72898 in Metabase.
- Trezor warned customers about phishing, fake calls, and impersonation scams.
Read More: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html