A company whose entire product is “don’t trust anybody” had about 80,000 customers’ names, phone numbers and home addresses stolen last month — twice, through two different vendors, without ever being hacked themselves.
Their shipping provider got breached through a dashboard tool. Their email provider got breached and used to phish their customers. And the data that leaked was data a contract said had been deleted five years ago. This is what a blast radius actually looks like — and what a small business is supposed to do about it on Monday morning.
00:00 The company that sells “trust nobody”
00:40 The Blast — Trezor, ShipMonk, and a dashboard
05:59 The part that made me do this episode
08:32 Radius Check — where does your company actually end?
10:45 The control nobody audits
16:46 The Fix — three things you can do this week
FREE cybersecurity foundations course: Inside The Blast Radius — https://www.skool.com/blastradius (The Fix maps to Module 1 “The Map” and Module 3 “Identity”. Both free.)
Watch the video edition: https://youtu.be/nn8Nr9FGZbI
Trezor / ShipMonk disclosure: https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incidentExpanded disclosure (67,000 more): https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.htmlInitial 13,689 disclosure: https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/Weekly breach roundup (Brevo, Mathspace): https://www.privacyguides.org/news/2026/09/11/data-breach-roundup-sep-4-10-2026/THE BLAST RADIUS — Cyber • Tech • What’s Next. Hosted by Quinn “Q” Vidal.
https://theblastradius.io · https://aiqso.io
Free cybersecurity foundations course — Inside The Blast Radius: https://www.skool.com/blastradius | Show site: https://theblastradius.io