Trezor's supplier breach keeps growing, and it was never Trezor's system
September 15, 2026. From issue 6 of The Compliance Brief, 3 stories for founders and executives who own security.
Issue 6 of The Compliance Brief went to subscribers on September 15, 2026. 3 of its 5 stories bear on breaches, incidents and security leadership, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for founders and executives who own security.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: Infosecurity
Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers. Separately, Trezor warned that attackers who breached its third-party email provider are using the data for phishing.
Our take, in short
This is the fourth-party problem that vendor questionnaires handle badly. You list your subprocessors, your customer's reviewer ticks the box, and nobody asks what the fulfilment house or the email delivery vendor is doing with customer contact data.
Read the full take on traztech.ca
Revolut gave customer data to someone posing as a government agency
Source: BleepingComputer
Revolut disclosed a breach after sharing customer data with a threat actor impersonating a government agency. The exposed information included financial details and passports.
Our take, in short
No exploit, no malware, a request that looked official enough to get answered. Every fintech I work with has an inbox that receives subpoenas, police requests and regulator letters, and almost none of them have a written procedure for verifying who sent one before data goes out the door.
Read the full take on traztech.ca
Delaware amends its privacy and breach notification laws
Source: DataBreaches.net
On September 2, 2026, Delaware's governor signed HB 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act, which took effect at the start of 2025, and HB 381 amends the state's computer security breach notification law.
Our take, in short
Delaware alone is not going to change anyone's quarter. The pattern is what I would pay attention to: the state obligations you mapped once during SOC 2 prep keep shifting under you, and your US customer contracts usually promise compliance with applicable law rather than with a fixed list.
Read the full take on traztech.ca
Related on HireACISO
- How to vet a security or compliance firm
- Our biggest deal is blocked on security
- Vendor risk management, done proportionately
- A security questionnaire and nobody owns it
Also in issue 6
Outside breaches, incidents and security leadership, but in the same email:
- Passkey enrolment is the new phishing target
- Artifactory auth bypasses are now on the exploited list
Older: issue 5 All issues on HireACISO Newer: issue 7
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.