Trezor said a breach at shipping provider ShipMonk exposed personal and order data for another 67,000 U.S. customers, even though Trezor had been told the older records were deleted. The newly disclosed set includes names, email addresses, phone numbers, shipping addresses, and order numbers from purchases between November 2019 and August 2021.
The intrusion at ShipMonk was tied to zero-day exploitation of CVE-2026-72898, a critical SQL injection flaw in Metabase. In plain terms, the attacker was able to query the backend database through the analytics app and pull data the shipper still held, so Trezor's deletion policy did not eliminate the copy that mattered once ShipMonk was breached.
The exposure sits with any company that hands customer data to processors and assumes a retention promise equals removal. If a vendor keeps historical records longer than the contract suggests, a later breach can widen the blast radius long after the brand thinks that data is gone.