← All security news

Vendor Breach Exposes Data It Said Was Deleted

A shipping package icon splitting open with customer records spilling out, next to a document stamped DELETED that is crossed out, representing a fulfillment vendor breach that exposed customer data years after the vendor had confirmed it was deleted

Trezor, the hardware crypto wallet maker, disclosed on 5 September that a breach at its shipping and fulfillment partner ShipMonk exposed the personal data of a further 67,000 U.S. customers — on top of nearly 13,700 already disclosed in August, pushing the total past 80,000 people. The exposed fields are the usual fulfillment set: names, email addresses, phone numbers, shipping addresses and order numbers. ShipMonk says the intrusion exploited a critical SQL injection flaw, CVE-2026-72898 (CVSS 10.0), in Metabase, the analytics platform it used internally to query customer and order data. Metabase notified ShipMonk of the compromise on 6 August; ShipMonk reported unauthorized access to Trezor on 10 August. Researchers have linked the intrusion to the ShinyHunters extortion group, which has run a string of similar campaigns against fulfillment and data-broker platforms this year.

The detail that makes this more than a routine vendor breach: the newly disclosed batch covers orders placed between 2019 and 2021. Trezor's contract requires fulfillment partners to delete or anonymize order data 90 days after delivery, and Trezor says it "repeatedly requested and received written assurance" from ShipMonk that those older records had been deleted. They hadn't been — years-old orders were still sitting in ShipMonk's systems when the attacker got in, and got swept up in the same breach as recent orders. ShipMonk has said it secured the affected systems and improved its security posture, but has not publicly commented on the incident itself.

What this means for your business

Almost every business hands customer data to outside vendors — fulfillment houses, email platforms, payment processors, CRMs, analytics tools — and most of those relationships run on the same thing Trezor's did: a written assurance that old data gets deleted. This case is a reminder that an assurance is not a control. This week, it's worth listing the vendors who hold your customers' personal data and checking two things for each: does your contract actually specify a retention/deletion period, and have you ever asked for proof of deletion rather than just a confirmation email — a deletion log, an audit report, anything you didn't have to take on faith. If your own team uses an internal analytics or BI tool (Metabase or otherwise) to query customer data, make sure it's patched and that access to raw customer records is limited to people who need it, since these dashboards are an increasingly common way in for attackers, not just a reporting convenience. And because the breached data here was old, unused data that had outlived its purpose, it's also worth asking whether you're holding customer records you no longer have a business reason to keep — data you don't have can't be breached.

Questions about your own setup? contact@techleetsolutions.com
Sources: The Hacker News, Decrypt, Cybersecurity News