Trezor's supplier breach keeps growing, and it was never Trezor's system
September 15, 2026. From issue 6 of The Compliance Brief, 2 stories for companies buying a SOC 2 audit.
Issue 6 of The Compliance Brief went to subscribers on September 15, 2026. 2 of its 5 stories bear on SOC 2 audits, auditors and vendor reviews, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for companies buying a SOC 2 audit.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: Infosecurity
Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers. Separately, Trezor warned that attackers who breached its third-party email provider are using the data for phishing.
Our take, in short
This is the fourth-party problem that vendor questionnaires handle badly. You list your subprocessors, your customer's reviewer ticks the box, and nobody asks what the fulfilment house or the email delivery vendor is doing with customer contact data.
Read the full take on traztech.ca
Revolut gave customer data to someone posing as a government agency
Source: BleepingComputer
Revolut disclosed a breach after sharing customer data with a threat actor impersonating a government agency. The exposed information included financial details and passports.
Our take, in short
No exploit, no malware, a request that looked official enough to get answered. Every fintech I work with has an inbox that receives subpoenas, police requests and regulator letters, and almost none of them have a written procedure for verifying who sent one before data goes out the door.
Read the full take on traztech.ca
Related on GetSOC2
- What if we say no to a SOC 2 request?
- A customer asked for our SOC 2 report
- Complementary user entity controls (CUECs)
- How to read a SOC 2 report you received
Also in issue 6
Outside SOC 2 audits, auditors and vendor reviews, but in the same email:
- Passkey enrolment is the new phishing target
- Artifactory auth bypasses are now on the exploited list
- Delaware amends its privacy and breach notification laws
Older: issue 5 All issues on GetSOC2 Newer: issue 7
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.