What happened
Crypto hardware wallet maker Trezor disclosed on August 13 that one of its shipping providers, ShipMonk, suffered a breach exposing the personal data of nearly 14,000 Trezor customers. ShipMonk notified Trezor on August 10 that attackers had accessed systems holding customer data. The tally: 11,742 customers had their full name, email, phone number, and shipping address exposed, and another 1,947 had partial data leaked, affecting orders delivered between May 10 and August 8 across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. The attackers got in by exploiting a critical SQL-injection zero-day in Metabase, a popular analytics tool, which gave them administrator access to data. The same Metabase flaw was used in breaches disclosed by laptop maker Framework and form-builder Tally, and CISA added it to its Known Exploited Vulnerabilities catalog on August 11. ShipMonk has reportedly received extortion emails from the ShinyHunters gang. Trezor stressed that its devices and customer funds were not affected, but warned customers to expect targeted phishing.
Why it matters for your business
This is a textbook third-party breach: Trezor's own systems were never touched, yet Trezor owns the customer notifications, the reputational hit, and the phishing fallout, because a vendor's analytics tool had a hole in it. Small businesses in the DMV live in the same web of dependencies, from fulfillment partners and marketing platforms to the reporting dashboards bolted onto them. Your customers will not distinguish between your breach and your vendor's breach. And for anyone who buys a crypto hardware wallet, a leaked home address attached to that purchase is exactly the data a scammer or thief wants, which is why the follow-on phishing wave is often worse than the leak itself.
What to do about it
- Keep a simple list of every vendor that stores your customer data, including the tools your vendors use for analytics and reporting.
- Check contracts for breach-notification clauses so you hear about incidents in days, not months.
- If a vendor breach hits you, notify customers quickly and plainly; speed buys trust.
- Train your team to treat emails referencing a recent order or delivery with extra suspicion, since that is exactly how leaked shipping data gets weaponized.
