ICO fines & breach roundup — 26 August 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
1. Nearly 14,000 Trezor customers exposed after hackers breached its shipping partner ShipMonk
Hardware crypto-wallet maker Trezor disclosed that a cyberattack on ShipMonk, the third-party fulfilment company that ships its orders, exposed the personal details of 13,689 customers, including some in the UK. Attackers exploited a vulnerability in Metabase, a data-analytics tool ShipMonk uses internally, to gain unauthorised access on 6 August 2026; ShipMonk notified Trezor on 10 August, and Trezor disclosed publicly soon after. For 11,742 of those customers, names, shipping addresses, email addresses and phone numbers were exposed; a further 1,947 had names, cities and email addresses exposed. The window covers orders placed between 10 May and 8 August 2026, and customers across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal were affected. Trezor's own systems and devices were not compromised — the breach happened one supplier removed, in a tool most customers had never heard of. No ICO enforcement outcome has been published for this incident; it's included here as a live example of the supply-chain breach category the regulator penalises once fully investigated, and as a sharper-than-usual illustration of the fraud risk that follows: because Trezor customers hold cryptocurrency, they are now a target list for scammers impersonating Trezor support and asking for wallet recovery details or PINs.
What your business should learn: Your supplier's security is only as good as the tools their supplier plugs in behind the scenes — Trezor didn't choose Metabase, ShipMonk did, and Trezor's customers paid the price anyway. When you're assessing a supplier that will hold your customers' data, ask directly what other software and analytics tools touch that data, and whether those tools are kept patched. And if you ever do have to notify customers of a breach, spell out the specific scam that's likely to follow — "we will never call or email you asking for a password, PIN or account code" — because that one line is free and blunts the most damaging part of the aftermath.
2. A ransomware gang claims to have stolen 15GB of data from Davroc, a family-run UK bathroom and furniture business
A criminal extortion group calling itself Booba Project posted Davroc Limited — a 40-plus-year-old, family-run distributor and manufacturer of bathrooms and furniture with sites in Hoddesdon, Bristol, Leeds, the Midlands and Chichester — to its dark-web leak site on 24 August 2026, claiming to have stolen around 15GB of the company's data and threatening to publish it unless paid. Booba Project is a newly emerged operation, first tracked in mid-2026, that follows the now-standard double-extortion playbook: get in (commonly via phishing, exposed remote-desktop access, or a stolen vendor login), copy the data out quietly, then encrypt systems and threaten public release to force payment. Important caveat: as of this roundup, this is an unverified claim made on the criminal group's own leak site — Davroc has not issued a public statement, and neither the company nor the ICO has confirmed a breach occurred or what data was actually taken. It is included because it illustrates, in real time, exactly the kind of business these gangs are choosing to target.
What your business should learn: Ransomware groups increasingly target smaller, well-established firms specifically because they assume weaker defences and a strong incentive to pay quietly to protect a reputation built over decades — being a 50-person family business is not protection, it's part of the pitch the criminals are making to themselves. The single cheapest defence against the "pay or we publish/lock everything" threat is a backup regime the attackers can't reach: keep at least one copy of your critical data offline or in storage your everyday admin credentials can't touch, and actually test restoring from it. That test is what turns "we have backups" from a comforting assumption into something you can rely on under pressure.
Sources
- Trezor — Recent customer data exposed in shipping provider incident
- BleepingComputer — Trezor discloses data breach affecting nearly 14,000 customers
- SecurityWeek — 14,000 Trezor Customers Impacted by Data Breach at ShipMonk
- teiss — Trezor discloses data breach affecting nearly 14,000 customers after shipping partner hack
- Protos — Trezor says 13,689 customers hit by data breach at shipping partner
- DeXpose — Booba Project Targets UK Furniture Manufacturer Davroc
- Ransomware.live — Victim: Davroc, Booba Project
- Davroc Limited — About Us