DEFENCE / RADAR

Public snapshot

Trezor·Crypto / Web3·

Customer personal information was compromised.

Trezor said ShipMonk unauthorized access exposed names, contact details, and shipping addresses for nearly 14,000 customers. The attached record does not establish the complete downstream scope.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: SQL injection flaw in Metabase password-reset endpoint
Consequence
Reported: Customer personal information was compromised.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Trezor
Industry
Crypto / Web3
Disclosed
Third party
ShipMonk
Affected asset
Trezor customer order data
Product / vendor
Metabase
Data involved
Personal data
Reported impact
Data exposure
Attached evidence
8 independent domains · 8 sources

2)Evidence-backed incident path

  1. 01

    Reported cause

    SQL injection flaw in Metabase password-reset endpoint

    ConfidenceSecondary
    Exact excerpt

    an SQL injection flaw in the platform’s /reset_password endpoint

    halborn.com · Aug 26
    E1
  2. 02

    Third party

    ShipMonk

    ConfidenceSecondary
    Exact excerpt

    one of our shipping providers, ShipMonk

    bleepingcomputer.com · Aug 13
    E2
  3. 03

    Affected product

    Metabase

    ConfidenceSecondary
    Exact excerpt

    the third-party analytics platform Metabase

    bleepingcomputer.com · Aug 13
    E3
  4. 04

    Reached

    Trezor customer order data

    ConfidenceSecondary
    Exact excerpt

    attackers gained access to customers' order data

    bleepingcomputer.com · Aug 13
    E4
  5. 05

    Observed

    Customer personal information was compromised.

    ConfidenceProbable
    Exact excerpt

    personal information of nearly 14,000 people was compromised

    securityweek.com · Aug 14
    E5

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • Regulatory action or customer remediation is not established
  • That a Defence review would have prevented this incident

4)Relevance to your product

Third-party access can inherit more reach than the product team intended.

This pattern applies when…

  • Products that share order or customer data with fulfillment providers.
  • Teams that assess vendor access to customer records.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Crypto / Web3

126 incident threads in the 365-day public record
  1. 0 incident threads
  2. 1 incident threads
  3. 1 incident threads
  4. 0 incident threads
  5. 15 incident threads
  6. 15 incident threads
  7. 6 incident threads
  8. 15 incident threads
  9. 17 incident threads
  10. 14 incident threads
  11. 16 incident threads
  12. 26 incident threads
Same incident family
6
Supply chain / third party
Confirmed share
14%
18 confirmed · 108 reported
Display family
Supply chain
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Crypto / Web3 in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

8 attached sources across 8 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E5
    securityweek.com14000 Trezor Customers Impacted by Data Breach at ...Specialist reporting · Aug 14 · Cited
    Specialist reportingCited
    Exact excerpt
    personal information of nearly 14,000 people was compromised
  2. E1
    halborn.comExplained: The Trezor/ShipMonk Breach (August 2026)Other public report · Aug 26 · Cited
    Other public reportCited
    Exact excerpt
    tracked as CVE-2026-72898
  3. E2, E3, E4
    bleepingcomputer.comTrezor discloses data breach affecting nearly ...Specialist reporting · Aug 13 · Cited
    Specialist reportingCited
    Exact excerpt
    full names, shipping addresses, email addresses, and phone numbers
  4. S4
    coindesk.comThird-party breach exposes shipping addresses of 14,000 Trezor buyersEstablished press · Aug 13 · Attached
    Established pressAttached
  5. S5
    coesecurity.com14,000 Trezor Customers Impacted by a ShipMonk Data Breach: A Warning About Third Party Cyber Risk - Cybersecurity | COE SecurityOther public report · Aug 14 · Attached
    Other public reportAttached
  6. S6
    cryip.coTrezor's Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak WaveOther public report · Aug 14 · Attached
    Other public reportAttached
Show all 8 sourcesShow the first six sources
  1. S7
    meterpreter.orgTrezor Breach: 13,689 Exposed via Metabase Zero-DayOther public report · Aug 15 · Attached
    Other public reportAttached
  2. S8
    rescana.comTrezor Data Breach Analysis: 14,000 Customers Exposed in ShipMonk Metabase SQL Injection Incident – RescanaOther public report · Aug 17 · Attached
    Other public reportAttached
    Exact excerpt
    culminated in the theft of sensitive customer information

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →