Wire · technology
Trezor ShipMonk Breach Exposes 67,000 U.S. Customer Records via Metabase Zero-Day ...
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 6 September 2026 · Fusion42 review
A zero-day SQL injection vulnerability in the Metabase analytics platform used by ShipMonk exposed sensitive data of approximately 67,000 U.S. Trezor customers, including personal and shipping information, increasing risks of phishing and physical targeting. The breach highlights critical weaknesses in third-party risk management and data deletion verification.
This Wire brief sits within Fusion42's coverage of Cybersecurity, and 2 sources have reported it between 5 Sep 2026 and 6 Sep 2026.
◆ ◆ The Wire takeaway
You must urgently verify and technically audit your third-party data deletion promises or lose control of critical customer information to breaches. The attackers exploited an infrastructure blind spot that exposes your users to phishing and physical risk.
◆ Coverage
2 sources · first reported 5 Sep 2026 · latest 6 Sep 2026
◆ Related on Wire
◆ Topics