Hardware wallet maker Trezor disclosed that its shipping provider ShipMonk still had customer data years after Trezor says ShipMonk confirmed in writing that it had been deleted, exposing another 67,000 U.S. customers on top of 13,689 already reported.

Trezor says the breach traces to a critical SQL injection vulnerability, CVE-2026-72898, in Metabase, an analytics tool ShipMonk used internally. The exposed data covers customer names, email addresses, phone numbers, shipping addresses, and order numbers dating from November 2019 through August 2021. “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” Trezor said. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”

The original insight is that Trezor did the thing security teams are told to do, get contractual deletion commitments from vendors and follow up in writing, and it still did not prevent the exposure, because nothing verified the deletion actually happened. A signed assurance is not evidence of a completed action. Security and privacy teams managing third-party data-processing relationships should treat vendor deletion claims as unverified by default and build in an audit or attestation step, not just a paper confirmation, especially for any vendor holding years of historical order data with no ongoing business need for it.

Source: Trezor. Related: Aesto Health Discloses a 9.5 Million Person Breach and Nutex Health Now Faces an Extortion Threat Too.