Trezor: ShipMonk (~67k) plus Brevo phishing wave (347k emails / ~2.5k clicks)
Trezor's blog (original 13 August 2026; updated 4 September 2026) says ShipMonk, a shipping provider, suffered unauthorized access. On 2 September 2026 Trezor was told the breach also held order data from prior cooperation (November 2019–August 2021) that ShipMonk had repeatedly assured in writing had been deleted. That tranche affects about 67,000 further US customers with full exposure of name, email, phone, shipping address and order number; all were emailed from privacy@satoshilabs.com. Hardware wallets are not affected; phishing and physical-security risk rise for exposed addresses. Earlier August disclosures covered customers who ordered to US/UK/Sweden/Colombia/Brazil/Italy/Portugal between 10 May and 8 August 2026 (about 11,742 in the original summary, with later August clarifications). Reporting ties ShipMonk's break-in to exploitation of Metabase CVE-2026-72898 (CVSS 10.0 SQLi) and names ShinyHunters as a claimed extortion actor — treat that attribution as third-party reporting, not a Trezor confirmation. Primary: Trezor blog update. UPDATE 11 September 2026: Trezor’s Brevo blog says on 9 September 2026 Brevo (newsletter platform) had a security incident affecting 120 Brevo accounts; an unauthorised actor sent mail from customer accounts including Trezor’s. About 347,000 opt-in newsletter addresses were exposed for further phishing risk; no other Trezor systems were touched and the Brevo account was suspended. Phishing used subject “Critical Security Alert: STM32 Entropy Vulnerability,” linking to a fake app that asked for wallet backups. Trezor took the phishing domain down at DNS within ~20 minutes, limiting clicks to about 2,500 people, and notified customers. Do not enter seed phrases from email links. Primary Brevo post: trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider; wire: BleepingComputer (11 Sep).
- Exploited in Australia?
- unknown
Primary: Trezor blog — ShipMonk incident (updated 4 Sep 2026) · Vendor: Trezor (vendor) · CVE: CVE-2026-72898 · Trezor — Brevo incident (10 Sep 2026); also BleepingComputer 11 Sep
