Trezor Discloses Data Breach Affecting Nearly 14,000 Customers
Hardware wallet maker Trezor has disclosed a data breach affecting nearly 14,000 customers after its shipping provider, ShipMonk, was compromised via a critical SQL injection zero-day in Metabase, a third-party analytics platform ShipMonk uses. Roughly 11,742 customers had names, email addresses, phone numbers, and shipping addresses fully exposed, with another 1,947 partially exposed (names, cities, emails). Trezor was explicit that wallet information and passwords were not exposed and device firmware/private keys remain secure — but the company itself is warning customers that the real danger now is targeted phishing and social engineering, since attackers can use the leaked personal details to convincingly impersonate Trezor, banks, or crypto exchanges. See BleepingComputer's full report for details.
This is a textbook setup for the kind of attack PurpleTrain's Phishing Awareness module trains people to catch. The module teaches learners to scrutinize unexpected messages even when they contain accurate personal details — a name, an order history, a phone number — because a breach like this one hands attackers exactly that ammunition to make a lure feel legitimate. The lesson isn't "watch out for badly-written scam emails," it's "a message that knows real things about you is not automatically a message you can trust"; recognizing that gap is precisely what turns a targeted, well-informed phishing attempt into a failed one.