Executive Summary
In August 2026, hardware wallet manufacturer Trezor disclosed that 67,000 U.S. customers had their personal data exposed through a breach at shipping provider ShipMonk. The ShineyHunters extortion gang exploited CVE-2026-72898, a critical SQL injection vulnerability in Metabase with a CVSS score of 10.0, to gain unauthorized access to ShipMonk's systems. The exposed data included customer names, email addresses, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021, despite Trezor's repeated requests for data deletion per their 90-day retention policy. This supply chain attack highlights how third-party vulnerabilities can impact customer data even when primary security measures are robust.
This incident demonstrates the growing threat of supply chain compromises targeting logistics and fulfillment providers, with attackers increasingly exploiting zero-day vulnerabilities in business intelligence platforms to access customer databases across multiple organizations simultaneously.
Why This Matters Now
Supply chain attacks are escalating as threat actors target third-party vendors to access multiple customer bases simultaneously, making vendor risk management and data retention policies critical security priorities for organizations handling sensitive customer information.
Attack Path Analysis
ShinyHunters gang exploited CVE-2026-72898, a critical SQL injection vulnerability in Metabase used by ShipMonk, to gain initial access and escalate privileges within the database system. The attackers moved laterally through ShipMonk's systems to access customer data stored across multiple databases, established persistent command and control channels, and exfiltrated sensitive customer information from 67,000 Trezor customers. The breach resulted in exposure of names, email addresses, phone numbers, shipping addresses, and order data, creating significant privacy impact and enabling future social engineering attacks against affected customers.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-72898, a critical SQL injection vulnerability (CVSS 10.0) in Metabase software used by ShipMonk logistics provider
Related CVEs
CVE-2023-38646
CVSS 9.8A critical SQL injection vulnerability in Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allows attackers to execute arbitrary commands on the server.
Affected Products:
Metabase Metabase – < 0.46.6.1, Enterprise < 1.46.6.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Phishing: Spearphishing Attachment
Valid Accounts
Data from Information Repositories: Sharepoint
Exfiltration Over C2 Channel
Exfiltration Over Web Service
Data Encrypted for Impact
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
GDPR – Processor Obligations
Control ID: Article 28
PCI DSS 4.0 – Third-party Service Provider Management
Control ID: 12.8.4
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
DORA – ICT Third-party Risk Monitoring
Control ID: Article 28
CISA ZTMM 2.0 – Data Categorization and Protection
Control ID: Data Pillar
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Hardware
Hardware manufacturers face supply chain vulnerabilities exposing customer data through third-party logistics providers, requiring enhanced vendor security oversight and data retention policies.
Logistics/Procurement
Logistics providers storing customer data become high-value targets for SQL injection attacks, demanding Zero Trust segmentation and encrypted traffic protection for client information.
Financial Services
Cryptocurrency and financial hardware sectors must implement egress security controls and multicloud visibility to prevent customer data exfiltration through compromised shipping partners.
E-Learning
Organizations using Metabase for data analytics face critical SQL injection vulnerabilities requiring immediate patching, threat detection capabilities, and secure hybrid connectivity implementation.
Sources
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deletedhttps://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.htmlVerified
- Trezor Blog: Recent Customer Data Exposed in Shipping Provider Incidenthttps://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incidentVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Halborn Security: Explained: The Trezor-ShipMonk Breachhttps://www.halborn.com/blog/post/explained-the-trezor-shipmonk-breach-august-2026Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have reduced the blast radius of this ShinyHunters attack by constraining lateral movement between database systems and limiting data exfiltration paths. The segmented architecture could have contained the SQL injection breach to fewer customer records.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial SQL injection compromise would likely still occur, but CNSF visibility controls may have enabled faster detection of the database exploitation and unauthorized query patterns.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have limited the scope of privilege escalation by restricting administrative access to specific database segments rather than allowing system-wide elevation.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have constrained lateral movement between database instances, potentially limiting attacker access to fewer customer data repositories and reducing the overall breach scope.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls may have detected persistent command channels and unauthorized communication patterns, potentially limiting the attackers' ability to maintain coordinated control over multiple database systems.
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely have constrained large-scale data exfiltration by blocking unauthorized outbound transfers and limiting the volume of customer records that could be extracted.
Even with CNSF controls, some customer data exposure would likely remain, but the scope of privacy violations could be significantly reduced from 67,000 affected customers to a smaller, more contained breach footprint.
Impact at a Glance
Affected Business Functions
- Customer Data Management
- Supply Chain Operations
- E-commerce Fulfillment
- Customer Communications
Estimated downtime: N/A
Estimated loss: N/A
Personal identifiable information of 67,000 U.S. customers including names, email addresses, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021. Additional 13,689 customers had partial data exposure including names, cities, and email addresses.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate third-party systems and prevent lateral movement between customer data repositories
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts from database systems
- • Enable Multicloud Visibility & Control to monitor anomalous database access patterns and repeated data extraction activities
- • Establish Threat Detection & Anomaly Response capabilities to identify SQL injection attempts and database privilege escalation activities
- • Enforce Encrypted Traffic (HPE) for all data in transit between systems to protect customer information during legitimate data transfers



