Executive Summary
In August 2026, cryptocurrency hardware wallet maker Trezor disclosed a significant data breach at its third-party shipping provider ShipMonk, initially affecting 14,000 customers across multiple countries. The breach expanded dramatically when it was revealed that ShipMonk had failed to delete historical customer data as contractually required, ultimately exposing personal information of 81,000 customers including names, addresses, email addresses, and phone numbers. The attack exploited a critical SQL injection zero-day vulnerability in the Metabase analytics platform, with the ShinyHunters extortion gang later claiming responsibility and sending extortion demands to ShipMonk.
This incident highlights the persistent vulnerability of third-party supply chains and the critical importance of data retention policies in an era where cryptocurrency adoption is accelerating and regulatory scrutiny is intensifying. The breach demonstrates how a single compromised analytics platform can cascade across multiple organizations, affecting everything from hardware manufacturers to online service providers.
Why This Matters Now
Third-party data breaches are escalating as organizations increasingly rely on external vendors for critical operations, while cryptocurrency users face heightened targeting from sophisticated threat actors exploiting supply chain vulnerabilities to access high-value targets.
Attack Path Analysis
Attackers exploited a critical SQL injection zero-day vulnerability in Metabase analytics platform used by ShipMonk to gain initial access. They escalated privileges to administrator access within the compromised Metabase instance, then moved laterally to access customer databases containing Trezor shipping data. The threat actors established persistent command and control, exfiltrated data on 81,000 customers including names, addresses, emails and phone numbers. The ShinyHunters extortion gang sent extortion emails to ShipMonk, threatening to release the stolen data and causing reputational damage to both ShipMonk and Trezor.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited a critical SQL injection zero-day vulnerability in the third-party Metabase analytics platform used by ShipMonk
Related CVEs
CVE-2023-38646
CVSS 9.8A critical SQL injection vulnerability in Metabase allows remote attackers to execute arbitrary code and gain administrator access to compromised instances.
Affected Products:
Metabase Metabase – < 0.46.6.1, < 0.45.4.3, < 1.46.6.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Phishing
Valid Accounts
Data from Information Repositories
Exfiltration Over Web Service
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
GDPR – Security of Processing
Control ID: Article 32
PCI DSS 4.0 – Third-Party Service Provider Management
Control ID: 12.8.2
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.11
CISA ZTMM 2.0 – Data Security and Governance
Control ID: Data Pillar
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Cryptocurrency wallet data breaches expose customer financial information, triggering regulatory compliance requirements and enabling targeted phishing attacks against financial assets.
Computer Software/Engineering
Metabase SQL injection vulnerability demonstrates critical security gaps in analytics platforms, requiring enhanced egress controls and zero trust segmentation implementations.
Logistics/Procurement
ShipMonk breach reveals third-party logistics vulnerabilities in data retention policies, exposing customer shipping information and highlighting supply chain security risks.
Consumer Electronics
Hardware wallet manufacturer data exposure affects device security reputation and customer trust, despite core product security remaining intact during breach.
Sources
- Trezor data breach impact now reaches 81,000 customershttps://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/Verified
- Recent customer data exposed in shipping provider incidenthttps://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incidentVerified
- Critical SQL injection vulnerability in Metabasehttps://nvd.nist.gov/vuln/detail/CVE-2023-38646Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained the attacker's lateral movement from the compromised Metabase instance to customer databases, reducing the scope of data exposure across ShipMonk's infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial SQL injection attack would likely have succeeded, but CNSF visibility would have detected anomalous behavior patterns and unauthorized database queries from the compromised Metabase instance
Control: Zero Trust Segmentation
Mitigation: Administrator privileges would likely have been contained within the Metabase workload segment, preventing the escalated access from reaching other critical systems and databases
Control: East-West Traffic Security
Mitigation: Lateral movement from Metabase to customer databases would likely have been blocked or significantly constrained, limiting attacker access to additional systems containing sensitive shipping data
Control: Multicloud Visibility & Control
Mitigation: Persistent command and control channels would likely have been detected and disrupted through anomalous traffic pattern analysis across the multicloud environment
Control: Egress Security & Policy Enforcement
Mitigation: Large-scale data exfiltration would likely have been constrained or blocked entirely, reducing the volume of customer data that could be extracted from ShipMonk systems
While extortion attempts would still occur, the reduced scope of compromised data would likely have limited the effectiveness of subsequent phishing campaigns and decreased reputational damage
Impact at a Glance
Affected Business Functions
- Customer Data Management
- Order Processing
- Customer Support Services
- Marketing Operations
Estimated downtime: N/A
Estimated loss: N/A
Personal information of 81,000 cryptocurrency hardware wallet customers including full names, shipping addresses, email addresses, phone numbers, and order numbers spanning from November 2019 to August 2026. Data retained by third-party logistics provider ShipMonk despite contractual deletion requirements.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate third-party analytics platforms and prevent lateral movement from compromised instances to customer databases
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts from analytics platforms to external destinations
- • Establish Multicloud Visibility & Control to monitor anomalous database queries and suspicious data access patterns in real-time across all third-party integrations
- • Enable Threat Detection & Anomaly Response to baseline normal Metabase behavior and alert on privilege escalation or unusual administrative actions
- • Apply Inline IPS (Suricata) inspection to detect and block SQL injection attempts and known exploit patterns targeting analytics platforms



