AI & TechCybersecurityFintechGadgetsNewswire

Trezor users targeted by phishing after shipping partner breach

▼ Summary

– Approximately 67,000 Trezor customers face increased phishing risks after their personal data was exposed in a breach at shipping partner ShipMonk.
– The breach occurred because ShipMonk failed to delete customer data as required by contract, despite receiving written assurances from SatoshiLabs that it had been done.
– Attackers exploited an SQL injection vulnerability in Metabase’s Cloud SaaS platform to access systems containing names, emails, phone numbers, and addresses.
– SatoshiLabs confirmed its own systems remain secure but is working on implementing anonymous delivery options to protect future customer privacy.
– Affected customers are advised to use anonymous emails, cryptocurrency payments, and P.O. Boxes to minimize exposure to potential physical security risks.

Trezor users face heightened security risks following a data breach at their shipping partner, ShipMonk. Approximately 67,000 additional customers of SatoshiLabs, the Czech-based manufacturer of Trezor hardware wallets, are now vulnerable to sophisticated phishing campaigns. The exposed data includes names, email addresses, phone numbers, and physical shipping addresses, creating potential avenues for both digital scams and physical threats.

“The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks,” the company stated in an update regarding the August 2026 incident. This disclosure highlights the severe consequences of compromised logistics data in the cryptocurrency sector, where possession of a hardware wallet often signals significant financial assets to criminals.

Logistics Partner Vulnerability

The root cause of this exposure lies with ShipMonk, the third-party firm responsible for distributing Trezor devices. On August 13, SatoshiLabs notified users that attackers had infiltrated ShipMonk’s systems. ShipMonk later attributed the intrusion to the exploitation of an SQL injection zero-day vulnerability within Metabase’s Cloud SaaS platform.

Although SatoshiLabs mandates that partners delete or anonymize customer data within 90 days of delivery, ShipMonk failed to adhere to this protocol for specific regions. Orders shipped to the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and August 8, 2026, were impacted, affecting 3,889 customers initially. However, subsequent investigations revealed a much larger scope of compromise.

In a follow-up update, SatoshiLabs confirmed that attackers also accessed full shipping records for roughly 67,000 US-based customers. These individuals placed orders between November 2019 and August 2021. The persistence of this data despite contractual obligations has drawn sharp criticism from the wallet maker.

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” SatoshiLabs reiterated.

Mitigation Strategies and Future Protocols

SatoshiLabs emphasized that its internal systems remain secure and that no Trezor devices themselves were compromised. Nevertheless, the company has initiated damage control measures by emailing affected customers to warn them against suspicious communications. The future of the partnership with ShipMonk remains uncertain as SatoshiLabs explores more secure distribution methods.

The company is currently developing an anonymous delivery option designed to protect user privacy. Proposed features include dedicated checkout processes, locker pickup services, neutral packaging, generic sender details, and the automatic deletion of shipping identifiers post-delivery. Until these measures are implemented, SatoshiLabs advises customers to take proactive steps to minimize exposure. Recommendations include using anonymous email addresses for orders, paying via cryptocurrency or disposable digital cards, and utilizing P. O. Boxes rather than residential addresses.

Escalating Physical Threats

The implications of this breach extend beyond digital fraud. Several users have reported receiving phishing attempts via phone calls and physical mail containing QR codes. This marks the first time since Trezor’s founding in 2013 that the company has faced a breach exposing such sensitive personal contact information.

“This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses. We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected,” the company acknowledged.

Blockchain analytics firm Chainalysis warns that the risk of physical violence against crypto holders is increasing alongside adoption rates. Criminals increasingly recognize that a single individual may hold millions of dollars accessible through a smartphone or hardware wallet.

“We estimate that violent criminals have successfully extracted more than $30 million from holders so far this year. If this pattern continues through H2, then 2026 will become the single-worst year for violent crypto attacks on record, surpassing 2025’s total of $58 million.”

To counter these threats, experts advise against publicly disclosing crypto holdings. Users are encouraged to employ decoy wallets, hidden wallets secured with passphrases, and multi-signature authorization setups to add layers of security to their assets.

(Source: Help Net Security)

Topics

data breach impact 98% third-party vendor risk 95% phishing threats 92% security vulnerabilities 88% privacy mitigation 85%
Show More