Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: third-party-breach (5 articles)Clear

Trezor says shipping partner breach exposed data of nearly 14,000 buyers

Hardware wallet maker Trezor said a breach at its shipping provider ShipMonk exposed personal data of nearly 14,000 customers who ordered devices between May and early August. About 11,700 had full details exposed, including name, email, phone number, and shipping address, while roughly 1,900 had partial data taken. Trezor stressed that its own systems were not compromised and its devices remain secure, but warned customers to expect phishing. Exposed home addresses tied to cryptocurrency ownership carry an added risk, as physical attacks on crypto holders have risen this year. The company said it is introducing an anonymous delivery option in response.

Check
Affected Trezor customers should be alert to phishing and impersonation using their real order details, never enter a wallet recovery phrase in response to any message, and be mindful of address exposure.
Affected
Nearly 14,000 Trezor customers whose names, emails, phone numbers, and shipping addresses were exposed through the ShipMonk breach; the data enables convincing phishing and, tying addresses to crypto ownership, physical risk.
Fix
Treat unexpected wallet-related messages as suspicious, keep recovery phrases entirely offline, and for organizations, hold shipping and fulfillment vendors to the same data-protection and breach-notification standards as internal systems.

Valve warns Steam hardware buyers of data breach at its shipping partner

Valve is notifying European Steam hardware customers that their personal data was likely exposed in a cyberattack on CEVA Logistics, the partner that ships Steam devices in the region. Attackers had access to CEVA systems between July 29 and August 1, reaching the delivery details CEVA keeps for up to ninety days: name, street address, postal code, city, country, phone number, the email tied to the Steam account, and the hardware ordered and its price. No Steam passwords, Steam Guard codes, or payment data were exposed, since CEVA never held them. Valve warned customers to expect phishing and delivery-impersonation scams and to treat such messages as fake.

Check
If you ordered Steam hardware in Europe recently, expect phishing by email, text, or phone impersonating Valve or a courier, and treat requests for fees, signatures, or confirmations as fraudulent.
Affected
European Steam hardware customers whose name, address, phone number, email, and order details were exposed through the CEVA breach; no passwords or payment data were affected, but the data enables convincing scams.
Fix
No need to change your Steam password, but stay alert to delivery-themed phishing, verify courier requests through official channels, and hold logistics vendors to the same breach standards as internal systems.

Ernst and Young says client tax documents were stolen from a support platform

Ernst & Young is notifying clients of a breach at a third-party IT service management platform used by staff supporting its tax practice. Support tickets submitted through the platform could include attached documents containing client tax information, and the firm says an unauthorized third party accessed the platform between March 28 and April 12 and downloaded documents belonging to a number of clients. EY detected the activity on April 23, roughly two weeks after it stopped, and filed breach notifications with the California Attorney General in July. The exposed data includes personal and financial information used to prepare tax filings.

Check
EY tax clients should watch for a notification letter, monitor financial accounts and credit, and treat unexpected messages referencing their tax filings or the firm as likely phishing.
Affected
EY tax clients whose documents were attached to support tickets; personal and financial information used to prepare tax filings was downloaded, which supports identity theft and convincing targeted phishing.
Fix
Affected clients should consider a credit freeze and monitor accounts. Organizations should limit what sensitive data staff attach to helpdesk tickets, set retention limits on attachments, and assess vendor security.

Lidl notifies online shop customers of breach at a service provider

Discount supermarket chain Lidl has notified online shop customers in Germany, Belgium, and the Netherlands of a data breach that stemmed from a hack at one of its service providers rather than Lidl's own systems. According to the company, the exposed information involves customer contact and order-related details, while payment card data was not affected. The incident is another example of third-party or supply-chain risk, where attackers compromise a vendor to reach a larger brand's customer data. Even without financial data, the exposed details can fuel convincing phishing and scams that impersonate Lidl, especially messages referencing real orders to make fraudulent requests look legitimate to shoppers who recently used the online shop.

Check
Lidl online shop customers in the affected countries should watch for the notification, be wary of messages referencing Lidl or their orders, and avoid clicking links or sharing details in unsolicited messages.
Affected
Lidl online shop customers in Germany, Belgium, and the Netherlands whose contact and order details were exposed through a hacked service provider; payment card data was not affected.
Fix
Treat Lidl-themed messages with caution and verify through official channels. Organizations should assess vendors' security, limit the customer data third parties hold, and require breach-notification and security commitments in supplier contracts.

Nintendo employee survey data stolen via third-party HR tool TinyPulse

Nintendo of America has confirmed that attackers stole internal employee data through TinyPulse, a third-party employee-survey service run by WebMD Health Services, after a threat actor calling itself SHADOWBYT3$ posted the haul and demanded a $2 million ransom. Nintendo says its own systems were not breached, no customer or financial data was touched, and the exposure is limited to internal survey content for a small subset of employees, mostly several years old. The attacker, however, claims to hold more, including bank statements and tax forms. The incident is a textbook third-party vendor breach affecting a major brand.

Check
Review which third-party HR and survey tools hold employee data, what they store, and how access is secured, and watch for phishing aimed at employees referencing surveys or HR programs.
Affected
Nintendo of America employees whose internal survey responses were exposed via the TinyPulse service; the threat actor claims additional data, which Nintendo has not confirmed.
Fix
Inventory and risk-assess third-party tools holding employee data, require strong authentication and least-privilege access for vendor integrations, and minimize the sensitive data shared with such services.