2026 Heatbit — ShipMonk fulfillment breach; customer names/emails/phones/addresses (Aug notices)
Data compromised
Per Heatbit customer email (Aug 2026): name, email address, phone number, shipping address, order number for affected orders held by ShipMonk; no Heatbit device/account compromise stated
Technical writeup
Verified merchant customer notice — August 19, 2026. Heatbit (Bitcoin-mining heater/air-purifier hardware vendor) emailed affected customers stating that in August 2026 ShipMonk identified unauthorized access to its systems and provided Heatbit a list of affected order records. Heatbit’s email (quoted on X by NordicMiner and TheDesertLynx, Aug 19) says Heatbit’s own store, accounts, internal systems, and devices were not involved; likely accessed fields include name, email, phone, shipping address, and order number. This is downstream impact from the same ShipMonk/Metabase fulfillment incident that Trezor disclosed on August 13 (13,689 customers). Heatbit had not published a standalone web notice or attested individual count at indexing; recordsAffected 0 pending Heatbit census. Canonical platform row: shipmonk-metabase2026.
Root cause
Third-party breach at fulfillment partner ShipMonk (Metabase vulnerability path per broader ShipMonk incident); Heatbit store/devices not compromised per customer email
References
- https://x.com/NordicMiner/status/2090044564228751832
- https://x.com/TheDesertLynx/status/2090070863567523944
- https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident
- https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/
- https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/