Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
81,000 Records: What ShipMonk's Deletion Failure RevealsIncident Management
3 min readFor TPRM Practitioners

81,000 Records: What ShipMonk's Deletion Failure Reveals

A data deletion clause is only effective if you enforce it. Trezor's breach shows the consequences of failing to do so: ShipMonk retained customer data for three years after confirming deletion, increasing the breach impact from 14,000 to 81,000 customers.

What Changed

Initially, the Trezor breach affected nearly 14,000 customers across six countries. Recently, the company revealed that an additional 67,000 U.S. customers were exposed from November 2019 to August 2021. This wasn't due to a new attack but because ShipMonk never deleted the data, despite repeated assurances.

Attackers exploited a vulnerability in Metabase, a third-party analytics platform, to access customer details like names, email addresses, phone numbers, shipping addresses, and order numbers. The ShinyHunters extortion gang claimed responsibility and sent demands to ShipMonk.

Key Findings

Written assurance doesn't equal compliance. Trezor repeatedly received written confirmation of data deletion from ShipMonk, yet the data remained. Your contract may require deletion, and your vendor may confirm it, but the data can still exist.

Retention amplifies downstream risk. The 67,000 additional records weren't needed for active fulfillment. When ShipMonk's Metabase instance was compromised, three years of unnecessary data became available to attackers. Each month of unauthorized retention increases your exposure.

Fourth and Nth Party Management failures cascade. ShipMonk used Metabase for analytics. When Metabase disclosed a critical SQL injection vulnerability, ShipMonk's instance was exploited, and Trezor's customer data was stolen. You're responsible for your vendor's sub-processor choices, even if you're unaware of those relationships.

Post-breach phishing is the real attack surface. Trezor warned customers about increased phishing risk. In January 2024, they disclosed a separate breach affecting 66,000 users, which was later used in phishing attacks targeting wallet recovery seeds. Breach notification is just the beginning of customer risk.

What This Means for Your Team

If you're relying on vendor attestations for data deletion, you're managing compliance theater, not data protection. The gap between contractual obligation and reality becomes visible during an incident, leaving you to explain to regulators why records that should've been deleted were exfiltrated.

Your Right to Audit clauses should cover data lifecycle verification, not just security controls. You need evidence of deletion: system logs, database purge confirmations, backup tape destruction certificates. An email saying "We deleted it" isn't evidence.

Your Criticality Classification process should consider data retention duration, not just sensitivity. A vendor processing sensitive data for 90 days may pose less risk than one processing moderately sensitive data indefinitely. ShipMonk's failure turned historical data into a current breach.

Action Items by Priority

Immediate: Audit your deletion clauses and enforcement mechanisms. Review contracts with vendors who've processed customer data in the past three years. Identify agreements with data deletion timelines, written confirmation requirements, and audit rights to verify deletion. If you can't verify deletion, assume the data still exists.

Within 30 days: Map your sub-processor exposure for critical vendors. Request Sub-Processor Disclosure lists from vendors handling sensitive data. Determine what data each sub-processor accesses, what platforms they use, and whether your vendor has verified their security posture. ShipMonk's use of Metabase was a fourth-party relationship Trezor may not have known about until the breach.

Within 90 days: Build deletion verification into your Continuous Monitoring of Active Arrangements. Don't wait for contract renewal to confirm deletion. For vendors with time-bound data retention obligations, schedule quarterly or semi-annual verification reviews. Request system logs showing data purge activity. If they can't produce logs, escalate through your Incident Escalation, failure to demonstrate deletion is a control failure.

Ongoing: Update your Vendor Breach Management playbook for retention failures. Your breach response shouldn't assume the compromised data set matches current processing scope. When a vendor reports a breach, your first question should be: "What data did you retain that should have been deleted?" Your notification timeline and regulatory reporting obligations change significantly if the breach includes data from terminated relationships.

Strategic: Negotiate deletion verification rights before contract signature. Your Pre-Contractual Assessment should include specific language granting you the right to request and review deletion evidence on demand. For high-risk vendors, consider requiring automated deletion with system-generated audit trails. If a vendor pushes back on verification rights, that's a risk signal worth escalating.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like