Hardware wallet maker Trezor disclosed this week that a breach at ShipMonk, the third-party fulfilment provider it uses to pack and post orders, exposed the personal data of nearly 14,000 customers, including people in the UK. Attackers got in through a vulnerability in Metabase, an analytics tool ShipMonk connects to its systems, and made off with names, email addresses, phone numbers and, for over 11,000 of those customers, full shipping addresses. Orders placed between 10 May and 8 August were affected.
Trezor sells hardware devices specifically designed to store cryptocurrency securely. The uncomfortable irony is that this breach didn’t touch any of that security engineering — it went through a shipping partner’s analytics dashboard. And unlike most SaaS breaches, where the exposed data is an email address or a hashed password, this one ties a named individual to a home address and to the fact that they recently bought something valuable enough to need a hardware security device. That’s a materially different kind of risk: it moves from “your inbox might get more spam” to “someone now knows who to target and where to find them.”
Why this matters beyond crypto wallet buyers
Any UK business that ships physical products — especially anything valuable, easily resold, or personally identifiable as belonging to the buyer — carries a version of this same exposure. Jewellery, electronics, specialist equipment, even high-value gifts: if your fulfilment provider, courier integration, or warehouse management tool gets breached, you’re not just facing a data protection headline. You’re potentially handing someone a shopping list of named people and their addresses, tied to what they own.
Most SMEs think about vendor risk in terms of customer databases and CRM systems, the kind of breach that made headlines just this week with a separate CRM provider. Fulfilment and logistics partners get far less scrutiny, despite often holding exactly the combination of name, address and purchase detail that carries real-world physical risk, not just digital nuisance.
What to check if you ship physical goods
Ask your fulfilment or shipping provider what third-party tools they connect to your data. ShipMonk’s exposure came through Metabase, a tool many businesses wouldn’t think to ask about because it’s not customer-facing. Your logistics partner’s sub-vendors are your risk too.
Segment what shipping partners actually need to see. A courier integration rarely needs to know what the item is, only that a parcel of a given size and weight needs to move from A to B. If your systems are passing product descriptions alongside names and addresses when they don’t need to, that’s worth tightening.
Keep a record of which vendors hold which categories of customer data, and for how long. When a fulfilment partner has a breach, knowing immediately whether they held addresses, purchase history, or just tracking numbers determines how fast and how seriously you need to respond. Archive.Partners helps businesses keep exactly this kind of vendor and data-retention record in order, so you’re not scrambling to reconstruct it during an actual incident.
If a breach notice does land from one of your suppliers, having a response plan ready before it happens matters more than anything you do after. KeepSafe monitors for exactly these third-party incidents and helps businesses without an in-house security team respond properly.
The takeaway
The ShipMonk breach is a reminder that not all customer data carries the same weight — a name and home address tied to a specific valuable purchase is a different category of risk to an email address in a marketing list. If your business ships physical goods, your fulfilment and logistics vendors deserve the same scrutiny you’d give a CRM or payments provider, not less.