2026 ShipMonk — Metabase vulnerability path; unauthorized access to customer/order data (Trezor notices)
Data compromised
Order/customer fulfillment data held for merchant clients. Trezor-attested subset: 13,689 hardware-wallet buyers (names, emails, phones, shipping addresses / partial city-level). Broader multi-merchant census not published at indexing — recordsAffected uses Trezor-confirmed floor.
Technical writeup
Company-confirmed fulfillment-platform incident (via merchant/customer notices) — ShipMonk told Trezor on August 10, 2026 of unauthorized access to systems containing customer data. BleepingComputer reported reviewing ShipMonk breach emails stating that on August 6 Metabase informed ShipMonk an unauthorized party exploited a Metabase software vulnerability to access data related to ShipMonk’s account and customers. ShipMonk reportedly secured affected systems afterward. Public attested individual count at indexing is driven by Trezor’s 13,689-customer disclosure; other ShipMonk merchants may be affected but had not published matching censuses in sources reviewed. Related merchant impact row: trezor-shipmonk2026.
Root cause
Unauthorized party exploited a vulnerability in Metabase analytics software to access data related to ShipMonk’s account and customers (per ShipMonk notices cited by BleepingComputer; Metabase informed ShipMonk ~Aug 6, 2026).