CuraSec

Plan active

Trezor data breach via ShipMonk logistics vendor affects 14K customers

2026-08-14 11:54 UTC · BleepingComputer · read the source ↗ #data-breach#vendor-risk#supply-chain
  • Engineer — Skip
  • SOC/IR — Learn: Third-party logistics provider compromise exposing customer data is a useful reminder that vendor integrations extend the attack surface; no IOCs or TTPs published to act on.
  • Leader — Plan: Review whether any logistics or fulfillment vendors your organization uses have similar access to customer PII, and verify contractual breach-notification obligations with those third parties.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.