Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
- ID
- 21809
- Status
- summarized
- Published
- 05 Sep 2026, 10:17 PM
- Fetched
- 06 Sep 2026, 1:09 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 06 Sep 2026, 1:11 AM
- Tags
- Audience
- developerssaas_founders
What happened
Trezor disclosed that 67,000 additional U.S. customers had their data exposed in a breach at shipping provider ShipMonk, on top of 13,689 disclosed last month. ShipMonk was breached via CVE-2026-72898, a CVSS 10.0 SQL injection zero-day in Metabase, attributed to the ShinyHunters extortion gang. Trezor says it had repeatedly received written confirmation from ShipMonk that customer data had been deleted per their 90-day retention policy, but the data was still present in ShipMonk's systems.
Why it matters
If you run Metabase, patch CVE-2026-72898 immediately — it's a CVSS 10.0 SQL injection being actively exploited in the wild. Beyond that, the story is a concrete reminder that vendor deletion assurances are not proof of deletion; if your business relies on third-party logistics or SaaS providers handling customer PII, contractual deletion clauses without verification are insufficient.
Discussion angle
The Metabase CVE-2026-72898 is the actionable item — check if anyone in your stack runs Metabase and whether it's patched. The broader lesson about vendor data retention promises is worth a brief mention but is not new information.