HireACISO

Trezor's supplier breach keeps growing, and it was never Trezor's system

September 15, 2026. From issue 6 of The Compliance Brief, 3 stories for founders and executives who own security.

Last reviewed 2026-09-15Written by Jacob Masse, TrazTech Inc.

Issue 6 of The Compliance Brief went to subscribers on September 15, 2026. 3 of its 5 stories bear on breaches, incidents and security leadership, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Infosecurity

Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers. Separately, Trezor warned that attackers who breached its third-party email provider are using the data for phishing.

Our take, in short

This is the fourth-party problem that vendor questionnaires handle badly. You list your subprocessors, your customer's reviewer ticks the box, and nobody asks what the fulfilment house or the email delivery vendor is doing with customer contact data.

Read the full take on traztech.ca

Revolut gave customer data to someone posing as a government agency

Source: BleepingComputer

Revolut disclosed a breach after sharing customer data with a threat actor impersonating a government agency. The exposed information included financial details and passports.

Our take, in short

No exploit, no malware, a request that looked official enough to get answered. Every fintech I work with has an inbox that receives subpoenas, police requests and regulator letters, and almost none of them have a written procedure for verifying who sent one before data goes out the door.

Read the full take on traztech.ca

Delaware amends its privacy and breach notification laws

Source: DataBreaches.net

On September 2, 2026, Delaware's governor signed HB 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act, which took effect at the start of 2025, and HB 381 amends the state's computer security breach notification law.

Our take, in short

Delaware alone is not going to change anyone's quarter. The pattern is what I would pay attention to: the state obligations you mapped once during SOC 2 prep keep shifting under you, and your US customer contracts usually promise compliance with applicable law rather than with a fixed list.

Read the full take on traztech.ca

Also in issue 6

Outside breaches, incidents and security leadership, but in the same email:

Older: issue 5 All issues on HireACISO Newer: issue 7