Security

ShipMonk was breached. Its client brands are hearing it late.

Published Aug 16, 20264 sources · 3 independent

A fulfilment provider lost names, phone numbers and shipping addresses for nearly 14,000 of one client's customers, and has said nothing publicly.

If a third party packs and ships your orders, it holds your customers' home addresses — and one of the larger ones has just lost a batch of them. Hardware wallet maker Trezor says its fulfilment provider, ShipMonk, told it on 10 August 2026 that an unauthorised party had reached customer data sitting in ShipMonk's systems.

What went out the door

Trezor puts the count at 13,689 people. For 11,742 of them the exposed fields were name, email address, phone number and shipping address. The other 1,947 lost name, city and email address. The affected orders fall between 10 May and 8 August 2026, and the customers are in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor attributes the narrow window to a 90-day deletion policy: older order data had already gone.

The same zero-day, one link further down the chain

ShipMonk told its clients that the attacker exploited a flaw in Metabase, the business intelligence tool, and that the vendor has since patched it. That is the same Metabase zero-day that already cost Tally and n8n account records. What changes is the payload. A leaked email address invites phishing; a leaked shipping address is a physical location tied to a named purchase. BleepingComputer reports that ShipMonk has also received extortion mail from the ShinyHunters group.

The part worth watching is disclosure. Trezor published a notice and emailed affected customers. SecurityWeek reported that ShipMonk had not acknowledged the incident publicly, and that it is not known how many of its other client brands were caught by the same intrusion. If you are one of them, word may reach you through an account manager, or not at all.

What to do

  • Ask your 3PL directly which analytics and reporting tools can read your order table, and whether your data was in scope. A public statement may never come.
  • Check your own retention. Trezor's exposure was bounded at 90 days because it deletes. An open-ended order history parked at a logistics partner is an open-ended liability.
  • Warn customers before the phishing does. A mail quoting a real order, a real name and a real address is convincing, and your brand is the one it will impersonate.

Why it matters

Your fulfilment partner holds the one dataset your own security cannot protect: where your customers live. Ask what tooling touches it, and delete order history you no longer need.

Reported by Software Crit from the sources above. Every story is confirmed against at least two independent publishers before publication.

Get the weekly roundup

Honest reviews, practical comparisons and the tool news that actually changes your stack.