September 7, 2026
Your Vendor Swore the Data Was Deleted. It Wasn't.
A fulfillment vendor kept customer data it promised to delete for five years. Then it was breached. What 80,000 exposed records teach about vendor risk.
Chris Archer Sales & Marketing Director
Reviewed by Reade Taylor, Founder & President A vendor swore the data was deleted. Then it showed up in a breach.
Hardware wallet maker Trezor spent last week delivering a second round of bad news to its customers. ShipMonk, the Fort Lauderdale based fulfillment company that ships Trezor’s products in the US, turned out to have exposed roughly 67,000 more American customers in the breach it first reported to Trezor in August. That comes on top of the 13,689 customers in the initial disclosure, which puts the total past 80,000.
Here’s the part that should bother every business owner who has ever signed a vendor agreement. The newly exposed records cover orders placed between November 2019 and August 2021. Trezor’s policy requires fulfillment partners to delete order data within 90 days. In its statement, Trezor said it “repeatedly requested and received written assurance confirming the deletion of the data.”
The vendor put the promise in writing. The data sat on their systems anyway, for five years or more, until someone stole it.
How the attackers got in
The breach itself, discovered on August 10, traces back to CVE-2026-72898, a SQL injection flaw in Metabase, an analytics dashboard tool that many companies run facing the open internet. The vulnerability scored a 10.0 on the CVSS scale, as bad as the rating system goes. Attackers used it to create admin level sessions and pull data in bulk. The breach has been attributed to ShinyHunters, an extortion crew with a long list of corporate victims.
The stolen records include names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor’s own systems were never touched. Every lost record walked out through the vendor. Trezor still gets to spend the next year dealing with angry customers, phishing campaigns aimed at those customers, and the reputational bill.
That’s how third party breaches work. The vendor has the incident. You have the problem.
Stuck on something like this right now?
Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.
Book a Free Strategy SessionYou have more vendors holding your data than you think
It’s tempting to read this as a crypto industry story. It isn’t. It’s a story about what happens when a business hands customer data to an outside company and takes deletion promises on faith.
Think about who holds your data right now. A trucking or distribution company has load boards, ELD platforms, and freight brokers holding driver and customer records. A law firm has e-discovery vendors and client intake tools. A property manager has tenant screening services with applicants’ personal details. A medical or accounting practice has a shredding company, a billing service, an answering service. Most small businesses we talk to around Orlando and Tampa can name their top three software vendors. Almost none can say which vendors still hold data from 2019.
And contracts alone did not protect Trezor. A 90 day deletion clause existed. Written confirmations existed. What didn’t exist was verification.
Questions worth asking your vendors this month
You don’t need a compliance department to do the basics of third party risk management. You need a list of vendors and an afternoon. For each vendor that touches customer, employee, or financial data, get answers to five questions.
What data of ours do you hold, exactly? How long do you keep it, and what happens at the end of that window? Can you show evidence of deletion, not just attest to it? Which of your systems are reachable from the internet, and who patches them? If you’re breached, how fast do we hear about it, and from whom?
A vendor that answers slowly, vaguely, or defensively is telling you something. The 80,000 exposed customers never knew Metabase existed, let alone that their five year old order data was sitting behind it.
At Cyber Command we run this exercise as part of vendor risk reviews for clients across industries from logistics to law. The point is not to fire every imperfect vendor. It’s to know what you’re exposed to before an attacker turns the answer into a disclosure letter.
The same rule applies to your IT provider
There’s an uncomfortable version of this question that most businesses never ask: what does your own IT company hold, and what would offboarding them actually look like?
Your IT provider likely has domain admin credentials, remote access tools on every machine, copies of your backups, and documentation of your entire network. That’s necessary for the job. It also means a sloppy or hostile handover when you leave creates exactly the kind of untracked data ShipMonk was sitting on. We’ve written before about what a clean provider transition looks like, including credential handoff, documented offboarding, and verifying that the old provider no longer has access. If your current provider can’t explain their own offboarding process, that’s worth knowing before you need it.
Deletion and access promises are cheap. Proof takes work. Insist on proof, from software vendors, from fulfillment partners, and from whoever runs your IT.
Where to start
If you can’t name which vendors hold your customer data, start there. Build the list, send the five questions, and read the answers with a skeptical eye. If you’d rather have help, our cybersecurity team runs vendor risk reviews, monitors for exposed credentials, and builds incident response plans designed to shorten the gap between a vendor’s breach and your response. Real humans answer, 24/7, no phone trees, whether you’re in Orlando, Tampa Bay, or Jacksonville.
Call us at (407) 587-0089 or reach out here. Bring your vendor list. We’ll bring the questions.
#CyberSecurity #ManagedIT #VendorRisk #DataBreach #SmallBusiness #Logistics
This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.