Find notable cyber news and cases, enriched with sources, timelines, and signals.

ShipMonk hit by network compromise

Incident
First reported
Last updated
Happening score
H score 43
1 unique sources, 1 articles

Summary

Hide ▲

ShipMonk suffered unauthorized access to systems containing customer data, creating a compromise event that exposed information tied to Trezor orders. The provider breach affected order data for nearly 14,000 customers and raised the risk of follow-on phishing and impersonation attempts. Trezor said its own systems were not compromised, but the third-party incident exposed sensitive customer contact and shipping details.

Related Happenings

SafePal customer order data breach and sale claim

Data Leak
H score39 First: 17.08.2026 02:47 Last: 17.08.2026 02:47 Sources 1

About this happening: SafePal disclosed a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and the stolen dataset is now being of...

Latest development: 18.08.2026 12:10

A threat actor advertised a SafePal order dataset on a cybercrime forum on August 16 and offered to share order IDs and shipping countries so prospective buyers could check them against SafePal's own verification tool.

Trezor customers customer data exposed after ShipMonk breach

Data Leak
H score44 First: 13.08.2026 18:13 Last: 13.08.2026 18:13 Sources 1

How related: "The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email)."

About this happening: A ShipMonk breach exposed Trezor customer order data for 11,742 fully exposed records and 1,947 partially exposed records, increasing the risk of phishing and impe...

Texas Parks and Wildlife Department license system vendor hit by network compromise

Incident
H score59 First: 19.06.2026 19:12 Last: 19.06.2026 19:12 Sources 1

About this happening: The Texas Parks and Wildlife Department license system vendor suffered an intrusion that led to unauthorized access and exposed customer records for millions of licens...

ShinyHunters widespread Okta SSO data theft campaign

Campaign
H score43 First: 03.04.2026 20:41 Last: 03.04.2026 20:41 Sources 1

About this happening: ShinyHunters is tied to a widespread Okta SSO identity-theft campaign that uses fake SSO pages, vishing, and lookalike .claims domains to capture credentials a...

Latest development: 24.08.2026 18:17

ShinyHunters targeted ReliaQuest employees with a social engineering campaign using a fake ReliaQuest single sign-on (SSO) page hosted on the lookalike domain reliaquest.claims and a real security employee's name during vishing attempts. One employee entered credentials and approved an MFA push notification, giving the attacker temporary, view-only access to ReliaQuest's identity dashboard, but device-trust controls blocked further access and ReliaQuest says no customer data, applications, or systems were accessed.

Timeline

  1. 13.08.2026 18:13 1 articles · 13d ago

    ShipMonk reports unauthorized access to customer data systems

    Exploitation Observed

    On Monday, August 10, 2026, ShipMonk informed Trezor that unauthorized access had reached systems containing customer data, marking the compromise that later exposed Trezor order records.

    Show sources
  2. 13.08.2026 18:13 2 articles · 13d ago

    Trezor discloses customer order data exposure affecting nearly 14,000 buyers

    Victim Impact Update

    Trezor disclosed that the ShipMonk compromise exposed order data for 11,742 customers with full exposure and 1,947 customers with partial exposure, affecting buyers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal; the leaked data included names, shipping addresses, email addresses, and phone numbers, while Trezor said its systems were not compromised and its operations or services were not impacted.

    Show sources