ShipMonk

ShipMonk

Global e-commerce order fulfillment and warehousing

Customer Service Representative

Full-TimePosted on 9/29/2026
No salary listed
Junior, Mid
Bachelor's
Pittston, PA, USA
In Person

About the job

Requirements
  • 1-2 years of experience in a customer service position.
  • 1-2 years of experience in logistics, supply chain, or e-commerce.
  • A bachelor's degree or equivalent work experience.
Responsibilities
  • Serve as the primary point of contact for merchants to facilitate timely issue resolution.
  • Manage the daily queue of incoming merchant contacts through phone, chat, and email, as well as tickets, including following up on inquiries based on committed dates.
  • Partner with warehouse management and developers to ensure requests are completed on time and professionally.
  • Build sustainable, long-term relationships with merchants.
  • Educate merchants on service offerings and help them proactively plan to minimize issues.
  • Support merchant projects and assist throughout their lifecycle.
  • Identify opportunities to improve the merchant experience and propose upgrades and new products as appropriate.

About the company

ShipMonk provides e-commerce order fulfillment as a 3PL, using a global warehouse network (US, Canada, Mexico, UK, and Europe) to store inventory closer to customers for faster shipping. It automates order processing through a platform that integrates with over 100 marketplaces and offers real-time tracking, plus inventory management tools to edit orders before shipment and view detailed logs. It differentiates itself with an agile, personalized fulfillment approach and broad platform integrations rather than traditional 3PL/4PL models, supported by its warehouse network and fast shipping options. The goal is to help e-commerce brands scale by delivering fast, reliable fulfillment and near-market inventory.

Company Size

1,001-5,000

Company Stage

Growth Equity (Venture Capital)

Total Funding

$365.1M

Headquarters

Fort Lauderdale, Florida

Founded

2014

Get referred to ShipMonk

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Trezor’s breach response validates ShipMonk’s scale with complex, high-volume merchants.
  • Ruby Has integration can deepen density, improve delivery speed, and lower per-order costs.
  • Global warehouse coverage supports brands demanding two-day shipping across North America and Europe.

What critics are saying

  • The 2026 Trezor breach exposed 80,000-plus customers, damaging trust and triggering contract reviews.
  • ShipMonk’s San Bernardino closure and 360 WARN layoffs signal operating pressure in 2024-2026.
  • Periphas and Flexport deal chatter signals strategic stress; a failed sale risks employee churn.

What makes ShipMonk unique

  • ShipMonk spans U.S., Canada, Mexico, U.K., and Europe for faster cross-border fulfillment.
  • Its software integrates with 100-plus commerce platforms, automating order processing and tracking.
  • The Ruby Has acquisition expanded ShipMonk’s warehouse footprint and enterprise-class DTC capabilities.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↑ 0%

2 year growth

↑ 0%
Payney
Sep 9th, 2026
Trezor Email Provider breached; 81,000 hit by prior leak.

Trezor Email Provider breached; 81,000 hit by prior leak. Trezor says hackers breached its email provider and sent fake STM32 security alerts, weeks after a ShipMonk leak exposed data on 81,000 customers total. The Payney Desk The 30-second version Payney AI * 01Trezor says attackers breached a third-party email provider and sent phishing emails from its domain. * 02The fake alert claims a 'STM32 Entropy Vulnerability' and pushes users toward handing over recovery phrases. * 03A separate August breach at shipper ShipMonk now covers 81,000 customers, up from about 13,689. * 04It matters because leaked names, addresses and phones make future crypto phishing far more convincing. 81,000 Trezor customers have now had order data exposed in the August breach at logistics provider ShipMonk, after the company revised its first estimate of roughly 13,689 upward in early September. On 9 September 2026, Trezor said attackers had separately breached a third-party email provider and used it to push out a fake warning titled 'Critical Security Alert: STM32 Entropy Vulnerability' - a message engineered to get recipients to type in the recovery phrase that controls their coins. What Trezor said about the email breach. According to BeInCrypto, Trezor said attackers breached its third-party email provider and sent customers a phishing message disguised as a critical chip security alert, that the company has taken down the domain used in the campaign, and that it is investigating how the attackers were able to send from its legitimate domain. Trezor said wallets, private keys and recovery backups stored on devices were not exposed. Trezor has not publicly named the email provider. Two terms in the lure are worth decoding, because the fake alert borrows real vocabulary. STM32 is the family of microcontroller chips used inside Trezor devices. Entropy is the randomness a wallet uses when it generates a recovery phrase; weak entropy would, in theory, make a backup guessable. Pairing a genuine chip name with a genuine cryptographic concept is what makes the email read as technical rather than fraudulent. One correction to how this story is being framed elsewhere: a Trezor is a self-custody device, not a custodial service. The company never holds customer coins, which is precisely why attackers go after the recovery phrase instead - it is the only thing that can move the funds. The same day, Swiss hardware wallet maker BitBox posted on X that a phishing mail had gone to its newsletter subscribers and that its preliminary review found it very likely that its newsletter provider was compromised. BitBox added that multiple other Bitcoin companies were targeted and appeared to share the same newsletter provider, that it warned subscribers and reported the phishing domains, and that most links had already been taken down. That is a preliminary assessment from one company, not a confirmed shared root cause across vendors. How the ShipMonk count went from 14,000 to 81,000. The email incident lands on top of an unresolved data leak. Trezor's own blog post says ShipMonk, one of its shipping providers, suffered a breach exposing customer order data including full names, physical addresses, phone numbers and email addresses. Security firm Halborn's write-up dates the notification to 10 August 2026 and splits the initial scope into 11,742 customers with names, phone numbers, emails and shipping addresses exposed, plus 1,947 with partial exposure. Halborn attributes the intrusion to exploitation of a public-facing Metabase application via SQL injection, escalated to administrator access, followed by extortion emails to ShipMonk from the group ShinyHunters. Trezor's blog then records an update dated 4 September 2026: on 2 September it was told the breach was larger than stated and also contained order data from a prior cooperation with ShipMonk between November 2019 and August 2021, despite Trezor having repeatedly requested and received written assurance that the data was deleted. BleepingComputer reports that this added roughly 67,000 U.S. customers, bringing the total to 81,000. The two headline numbers are the same incident measured at different dates, not two separate breaches: 11,742 plus 1,947 is 13,689 ("nearly 14,000"), and adding the 67,000 older U.S. records gives 80,689, which BleepingComputer rounds to 81,000. | Metric | Value | Source | | Total customers affected by ShipMonk breach (revised) | 81,000 | BleepingComputer | | Initial disclosure: full exposure / partial exposure | 11,742 / 1,947 | Halborn | | Additional U.S. customers added 4 Sept 2026 (orders Nov 2019-Aug 2021) | ~67,000 | Trezor blog; BleepingComputer | | Order window in first disclosure | 10 May - 8 Aug 2026 | BleepingComputer | | Trezor eShop stated data-retention period | 90 days | The Hacker News, quoting Trezor | | Users warned after 2024 Trezor support-portal breach | 66,000 | BeInCrypto | What the figures actually establish for a Trezor owner. Nothing in these disclosures indicates that the hardware was broken. Every verified loss vector here runs through data held by suppliers, not through the device. That distinction matters for what you should do: firmware and PINs are not the exposure; your contact details are. The 81,000 figure is a count of exposed customer records, not a count of phishing emails sent, victims, or coins stolen. Trezor has not disclosed how many recipients got the 9 September email, and no confirmed thefts from that campaign had been reported at the time of writing. It is also an assumption, not a fact, that the ShipMonk list and the email list are the same people - they were held by different vendors. The valid comparison is with Trezor's earlier contact-data incidents. BeInCrypto notes Trezor warned 66,000 users after a 2024 support-portal breach, and describes the September email incident as the company's third vendor failure in four weeks; it also reports that rival SafePal leaked nearly 40,000 records in the prior month. BeInCrypto further reports that customers have since received scam calls and printed letters, which is the practical consequence of a leak that included phone numbers and home addresses rather than just email. The Hacker News quotes Trezor saying it deletes or anonymises eShop purchase data after 90 days, chosen as the shortest window covering delivery, returns and refunds. Read against the 2019-2021 records that surfaced in the leaked dataset, that policy shows the limit of a retention rule: it governs what the merchant keeps, not what a third-party processor actually deleted. What is still unknown. * The provider. Neither Trezor nor BitBox named the compromised email vendor in the statements found. * The scale of the phishing wave. No recipient count, click-through count or loss figure has been published. * Whether the incidents are linked. BitBox's shared-provider theory is explicitly preliminary; Trezor says it is still investigating how attackers reached its legitimate domain. * Any deadline. No dated regulatory filing, notification schedule or investigation report was published alongside these statements, so there is no verified upcoming catalyst to watch. The single rule that survives all of this: a recovery phrase entered into any website, app or form other than the device itself is a transfer of ownership, and it cannot be reversed. Sources used during research. Check their dates and original context before relying on a figure. How Payney report. Crypto Trezor Email Provider Breach Phishing Trezor Stm32 Entropy Vulnerability Email Trezor Shipmonk Data Breach 81,000 Customers Bitbox Newsletter Provider Phishing September 2026 Frequently asked Is there a real STM32 entropy vulnerability in Trezor wallets? No. Trezor said the email titled 'Critical Security Alert: STM32 Entropy Vulnerability' is a phishing attempt sent via a breached third-party email provider, and that wallets, private keys and recovery backups on devices were not exposed. Was my data in the Trezor ShipMonk breach? The first disclosure covered about 13,689 customers with orders received between 10 May and 8 August 2026 in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal; the 4 September update added roughly 67,000 US customers with orders from November 2019 to August 2021. Do I need to move my crypto if I received the phishing email? Only if you entered your recovery phrase or passcode somewhere after clicking. Trezor says the devices themselves were not compromised, so simply receiving or opening the email does not put funds at risk.

NetmanageIT
Sep 5th, 2026
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted TheHackerNews 05 Sep 2026

CISTCK
Sep 5th, 2026
Trezor says ShipMonk breach exposed 67,000 U.S. Customers' data it said was deleted.

Trezor says ShipMonk breach exposed 67,000 U.S. Customers' data it said was deleted. by admin | Sep 5, 2026 Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

The Digital Track
Sep 4th, 2026
Trezor breach worse than reported: another 67,000 US customers exposed.

Trezor breach worse than reported: another 67,000 US customers exposed. September 4, 2026 Bitcoin Magazine general Negative Hardware wallet manufacturer Trezor has confirmed that a data breach affecting its customers is significantly worse than initially disclosed, with an additional 67,000 US customers now identified as exposed after third-party logistics partner ShipMonk failed to delete customer data as required. The revelation expands the scope of one of the most serious crypto hardware wallet security incidents in recent memory, raising urgent concerns about supply chain data security for Bitcoin (BTC) and cryptocurrency hardware storage users. ShipMonk's failure to purge sensitive customer records means tens of thousands of Trezor users - individuals who specifically chose hardware wallets for enhanced crypto security - now face elevated risks including phishing attacks, SIM-swapping attempts, and physical theft targeting, as bad actors may access names, addresses, and order details. This incident highlights a critical and often overlooked vulnerability: even the most secure cold storage devices depend on third-party fulfillment and logistics partners whose data practices may not meet the security standards crypto users expect. The Trezor breach arrives as hardware wallet adoption is growing alongside rising Bitcoin prices and increased mainstream crypto ownership, making vendor due diligence and data minimization practices more urgent than ever. Affected Trezor customers should immediately review account security and enable all available two-factor authentication options, while the industry watches to see whether regulators will use this breach to push for mandatory data retention standards across crypto hardware supply chains. Trezor said that its third party shipping partner, ShipMonk, had not erased customer data.

Rescana
Sep 4th, 2026
Trezor ShipMonk breach exposes 67,000 U.S. Customer records via Metabase zero-day vulnerability (CVE-2026-72898).

Trezor ShipMonk breach exposes 67,000 U.S. Customer records via Metabase zero-day vulnerability (CVE-2026-72898). Executive summary. On September 4, 2026, Trezor disclosed that a breach at its third-party logistics provider, ShipMonk, exposed sensitive order data for approximately 67,000 U.S. customers from November 2019 through August 2021. This incident follows an earlier disclosure in August 2026, which affected 13,689 customers. The compromised data includes names, email addresses, phone numbers, shipping addresses, and order numbers. No wallet seeds, private keys, or funds were exposed, and Trezor's own systems remain uncompromised. The breach was enabled by exploitation of a critical zero-day SQL injection vulnerability (CVE-2026-72898, CVSS 10.0) in the Metabase analytics platform used by ShipMonk. The attack is attributed to the ShinyHunters extortion group. The exposed data increases the risk of phishing, social engineering, and potential physical targeting of affected customers. Trezor has directly notified all impacted individuals and continues to advise vigilance against scams. This incident highlights the importance of third-party risk management and the limitations of data deletion policies without verification. Technical information. The breach at ShipMonk was the result of a sophisticated supply chain attack exploiting a zero-day SQL injection vulnerability (CVE-2026-72898, CVSS 10.0) in the Metabase analytics platform. Attackers leveraged this flaw to create administrator-level sessions, enabling bulk downloads of sensitive customer data stored within Metabase. The attack is mapped to MITRE ATT&CK techniques T1190 (Exploit Public-Facing Application) and T1005 (Data from Local System), with possible use of T1078 (Valid Accounts) if admin session creation was abused for further access. The compromised data set includes full names, email addresses, phone numbers, shipping addresses, and order numbers for approximately 67,000 U.S. customers, in addition to the 13,689 customers previously disclosed. The breach did not impact Trezor's wallet systems, and no cryptographic secrets or funds were exposed. However, the exposure of physical addresses and purchase history creates significant risks for targeted phishing, social engineering, and potential physical threats. Attribution for the attack has been assigned to the ShinyHunters extortion gang, based on reporting from enterprise blockchain security firm Holborn. While this attribution is consistent with ShinyHunters' historical targeting of SaaS, e-commerce, and supply chain providers, it is based on pattern analysis and third-party reporting rather than direct technical evidence. The incident underscores the criticality of robust third-party risk management, particularly for organizations handling sensitive customer data. Trezor's reliance on written assurances of data deletion from ShipMonk proved insufficient, as years-old records remained accessible and were ultimately exfiltrated. This highlights the limitations of contractual data deletion policies without technical verification or audit. ShipMonk has reportedly secured the affected systems and implemented additional security measures following the breach. As of the latest reporting, ShipMonk has not issued a public statement regarding the incident. Affected versions & timeline. The breach affected Trezor customers whose orders were fulfilled by ShipMonk between November 2019 and August 2021. The initial notification to Trezor occurred on August 10, 2026, with public disclosure on August 13, 2026, covering 13,689 customers. On September 2, 2026, Trezor was informed that the breach was significantly larger, involving an additional 67,000 U.S. customers. Public updates and media coverage followed on September 4-5, 2026. The vulnerability exploited was CVE-2026-72898, a critical SQL injection flaw in Metabase. The attack window is not precisely defined in public sources, but the data exposed spans orders from November 2019 through August 2021. Threat activity. The threat actor, identified as the ShinyHunters extortion gang, exploited a zero-day vulnerability in Metabase to gain unauthorized access to ShipMonk's systems. By creating administrator-level sessions, the attackers were able to perform bulk downloads of customer data tables. The attack did not involve deployment of malware or commodity tools; instead, it relied on direct exploitation of a software vulnerability. The primary risk to affected customers is increased exposure to phishing, social engineering, and potential physical targeting. The attackers now possess data that links individuals to cryptocurrency hardware wallet purchases, including physical addresses. While no downstream attacks have been publicly confirmed as of the latest updates, the risk profile for affected individuals is significantly elevated. The breach demonstrates a common pattern in recent supply chain attacks, where third-party service providers become the weak link in otherwise secure environments. The incident also illustrates the challenges of enforcing data deletion policies and the need for technical validation of compliance. Mitigation & workarounds. The following mitigation and response actions are prioritized by severity: Critical: Organizations using Metabase or similar analytics platforms should immediately review their exposure to CVE-2026-72898 and apply all available patches or mitigations. Technical validation of data deletion and retention policies with third-party vendors is essential to prevent similar incidents. High: All organizations handling sensitive customer data through third-party providers should conduct comprehensive third-party risk assessments, including technical audits of data retention and deletion practices. Customers affected by this breach should be vigilant for phishing emails, fraudulent calls, and social engineering attempts leveraging the exposed data. Medium: Security awareness training for staff and customers should be updated to reflect the increased risk of targeted phishing and impersonation attacks. Organizations should review and update incident response plans to address supply chain and third-party breaches. Low: Regularly monitor public disclosures and threat intelligence sources for updates on the ShinyHunters group and related supply chain attack patterns. Indicators of compromise. The following indicators are provided as a point-in-time reference and should be validated before enforcement in production environments. | Type | Indicator | Reported (date) | Source | | Domain | cryptoslate[.]com | 2026-09-05 | https://cryptoslate.com/users-exposed-by-trezor-breach-grows-sixfold-after-supposedly-deleted-shipping-logs-are-found/ | | Domain | trezor[.]io | 2026-09-04 | https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident?srsltid=AfmBOopoBysb50Bf0n7OLbW8vZu1IYePxm5tMjIb7Jciz4Q2p52wkFhq | | URL | hxxps://cryptoslate[.]com/users-exposed-by-trezor-breach-grows-sixfold-after-supposedly-deleted-shipping-logs-are-found/ | 2026-09-05 | https://cryptoslate.com/users-exposed-by-trezor-breach-grows-sixfold-after-supposedly-deleted-shipping-logs-are-found/ | | URL | hxxps://trezor[.]io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident?srsltid=AfmBOopoBysb50Bf0n7OLbW8vZu1IYePxm5tMjIb7Jciz4Q2p52wkFhq | 2026-09-04 | https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident?srsltid=AfmBOopoBysb50Bf0n7OLbW8vZu1IYePxm5tMjIb7Jciz4Q2p52wkFhq | About Rescana. Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organizations identify, assess, and monitor risks associated with their vendors and supply chain partners. Its platform enables continuous visibility into third-party exposures, supports technical validation of vendor data handling practices, and facilitates rapid response to supply chain incidents. For more information or to discuss your organization's third-party risk posture, contact Rescana at [email protected].