Cyber Security News

SafePal Confirms Hackers Gained Access to Customer Order Information

SafePal has confirmed a security incident in which unauthorized parties accessed customer order information through a flaw in an order-tracking plug-in.

The company said the incident affected approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. The exposed information may include customer names, email addresses, shipping addresses, phone numbers, and purchase details.

SafePal said the issue did not expose seed phrases, private keys, wallet passwords, bank account data, payment card numbers, or government-issued identification documents. According to SafePal, the incident resulted from an authorization flaw in a plug-in used for customer order tracking.

Under certain conditions, the flaw allowed one party to access another customer’s order details without authorization. The company said it fixed the vulnerability after discovering it and added additional security controls.

Safepal Confirm Hackers Access

SafePal emphasized that it does not collect or store seed phrases, private keys, wallet passwords, banking details, payment card data, or identity-document information. The company also stated that it found no evidence that the incident enabled attackers to access SafePal wallets or steal cryptocurrency assets.

However, the data exposure creates a significant phishing risk. Threat actors could use real purchase and shipping details to make fraudulent messages appear convincing.

Affected customers may receive fake support emails, phone calls, text messages, refund offers, firmware-update requests, delivery notifications, or malicious links designed to steal wallet credentials.

The company said it notified affected customers by email on August 16 from security@safepal.com. The notification used the subject line: “[Important] Your SafePal Order Information Has Been Affected.”

SafePal advised customers to independently verify any communication through its official website rather than trusting links included in messages. SafePal has also opened a dedicated support channel for customers affected by the incident.

The company said it contacted relevant logistics and fulfillment partners to determine whether the exposure extended into other systems. It also reported taking down more than 30 fraudulent websites and phishing links connected to scam activity.

As part of its response, SafePal said it reduced the retention period for personal data in the affected order-processing environment to 90 days, subject to legal requirements.

The company is also engaging an independent third-party security firm to validate the remediation and review its wider order-processing systems.

Customers are advised never to share a seed phrase, private key, or wallet password with anyone claiming to represent SafePal. SafePal said it will not request those credentials through email, phone calls, text messages, social media, or any other communication channel.

Users should avoid clicking links or scanning QR codes in unexpected messages. They should manually type the SafePal web address into a browser when checking account or support information. SafePal warned that attackers have used lookalike domains, including domains that replace the lowercase letter “l” with an uppercase “I”.

Customers who have already entered a seed phrase or private key into a suspicious website should treat the wallet as compromised. They should create a new wallet through an official SafePal device or application and transfer remaining assets immediately.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago