Trezor discloses data breach affecting nearly 14,000 customers
AI Summary
Trezor disclosed a data breach affecting nearly 14,000 customers due to a compromise of its shipping provider, ShipMonk, which was breached via a zero-day SQL injection vulnerability in the analytics platform Metabase. The attackers accessed customer order data including names, email addresses, phone numbers, and shipping addresses. ShipMonk confirmed the breach stemmed from exploitation of a critical vulnerability in Metabase, which was also used to attack other companies like Framework and Tally. Trezor emphasized that its own systems were not compromised and device security remains intact, but warned affected users of increased phishing risks. The ShinyHunters extortion group has claimed responsibility, sending extortion emails to ShipMonk.
AI-extracted · verify before operational use