ISO27K

Trezor's supplier breach keeps growing, and it was never Trezor's system

September 15, 2026. From issue 6 of The Compliance Brief, one story for teams running an ISO 27001 or ISO 42001 management system.

Last reviewed 2026-09-15Written by Jacob Masse, TrazTech Inc.

Issue 6 of The Compliance Brief went to subscribers on September 15, 2026. One of its 5 stories bears on ISO 27001, ISO 42001 and supplier risk, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Infosecurity

Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers. Separately, Trezor warned that attackers who breached its third-party email provider are using the data for phishing.

Our take, in short

This is the fourth-party problem that vendor questionnaires handle badly. You list your subprocessors, your customer's reviewer ticks the box, and nobody asks what the fulfilment house or the email delivery vendor is doing with customer contact data.

Read the full take on traztech.ca

Also in issue 6

Outside ISO 27001, ISO 42001 and supplier risk, but in the same email:

Older: issue 5 All issues on ISO27K Newer: issue 7