If you own a Trezor device and are affected, be wary of phishing emails. You really should already be weary of phishing attempts and how to spot them. And beware the phone calls too, and don’t talk much or give any affirmations to be recorded. Or just don’t answer unknown calls, though I like hear them for intel. The AI voice masking delay is interesting, with probably an Indian on the other side. And my calls come through Google Voice, so I can mark them as SPAM and block them, and probably have a lot blocked already due to Google’s SPAM filters and other user reports. Consequently, my phone calls had to do with a Coinbase hack years ago, and I had only tested the service for a short time to see their high fees and what was a terrible product led by terrible people… Also, I already have credit monitoring with a credit freeze from AT&T being hacked, but you can also do fraud alerts with info below, and banks and credit card companies usually have a credit monitoring feature where you can see your credit report and track your credit score.
Also, you can do manual 1 year fraud alerts with the big three sharing the alert so you just need to do it with one of the majors. But there is a fourth credit reporting company, Innovis, which looks like they have an online fraud alert form now (I think you used to have to mail it in). There is also https://www.annualcreditreport.com/index.action, where you can get free credit reports from the majors once per year (good way to see all three).
By Sergiu Gatlan

Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked.
During the incident, the attackers gained access to customers’ order data, including their full names, shipping addresses, email addresses, and phone numbers.
As the company explained in a Thursday blog post, the resulting data breach affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026.
“On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data,” Trezor said. “The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).”
The company added that its operations or services were not impacted by the breach, that its systems were not compromised, and that all Trezor devices are secure.
It also warned affected customers to be wary of any messages requesting personal information, as they may see an increase in phishing attempts.
“To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts,” it noted. “Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor.”
A Trezor spokesperson was not immediately available for comment when contacted by BleepingComputer today for more information about the incident.

Metabase zero-day data theft attacks
While Trezor didn’t share how the shipping provider’s systems were breached, in breach notification emails sent to affected customers and reviewed by BleepingComputer, ShipMonk told customers that the attackers exploited a vulnerability in the third-party analytics platform Metabase.
“On August 6, 2026, Metabase informed us that an unauthorized party exploited a vulnerability in Metabase’s software to access data related
to your account and your customers,” ShipMonk said.
“Based on the vendor’s representations, we understand that the vendor has since patched the vulnerability and invalidated all active sessions. We also
initiated a thorough and detailed technical investigation with the assistance of external information technology experts.”
As BleepingComputer previously reported, Metabase revealed that the threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances and carry out data theft attacks after gaining administrator access to the compromised instance.
The list of affected companies also includes laptop maker Framework and online form builder Tally, which also notified customers of data breaches after their Metabase instances were hijacked.
Trezor disclosed another data breach in January 2024 after threat actors gained access to its third-party support ticketing portal.
The hardware cryptocurrency wallet vendor revealed at the time that 66,000 users who have interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed during the incident.
After the breach, Trezor confirmed that the attackers used the stolen information to launch phishing attacks, attempting to trick recipients into revealing the 24-word recovery seeds they were given when setting up their Trezor wallets.
Video game distribution giant Valve has also notified Steam hardware customers in Europe on Monday that hackers stole their data after hacking CEVA Logistics, its shipping partner.