AI Weekly Malaysia

Back to items Summaries

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

ID
21809
Status
summarized
Published
05 Sep 2026, 10:17 PM
Fetched
06 Sep 2026, 1:09 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
06 Sep 2026, 1:11 AM
Tags
Audience
developerssaas_founders

What happened

Trezor disclosed that 67,000 additional U.S. customers had their data exposed in a breach at shipping provider ShipMonk, on top of 13,689 disclosed last month. ShipMonk was breached via CVE-2026-72898, a CVSS 10.0 SQL injection zero-day in Metabase, attributed to the ShinyHunters extortion gang. Trezor says it had repeatedly received written confirmation from ShipMonk that customer data had been deleted per their 90-day retention policy, but the data was still present in ShipMonk's systems.

Why it matters

If you run Metabase, patch CVE-2026-72898 immediately — it's a CVSS 10.0 SQL injection being actively exploited in the wild. Beyond that, the story is a concrete reminder that vendor deletion assurances are not proof of deletion; if your business relies on third-party logistics or SaaS providers handling customer PII, contractual deletion clauses without verification are insufficient.

Discussion angle

The Metabase CVE-2026-72898 is the actionable item — check if anyone in your stack runs Metabase and whether it's patched. The broader lesson about vendor data retention promises is worth a brief mention but is not new information.

Top