Safepal Confirm Hackers Gained Access to Customer Order Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

SafePal has confirmed a security incident in which unauthorized parties accessed customer order information through a flaw in an order-tracking plug-in.

The company said the incident affected approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. The exposed information may include customer names, email addresses, shipping addresses, phone numbers, and purchase details.

SafePal said the issue did not expose seed phrases, private keys, wallet passwords, bank account data, payment card numbers, or government-issued identification documents. According to SafePal, the incident resulted from an authorization flaw in a plug-in used for customer order tracking.

Under certain conditions, the flaw allowed one party to access another customer’s order details without authorization. The company said it fixed the vulnerability after discovering it and added additional security controls.

Safepal Confirm Hackers Access

SafePal emphasized that it does not collect or store seed phrases, private keys, wallet passwords, banking details, payment card data, or identity-document information. The company also stated that it found no evidence that the incident enabled attackers to access SafePal wallets or steal cryptocurrency assets.

However, the data exposure creates a significant phishing risk. Threat actors could use real purchase and shipping details to make fraudulent messages appear convincing.

Affected customers may receive fake support emails, phone calls, text messages, refund offers, firmware-update requests, delivery notifications, or malicious links designed to steal wallet credentials.

The company said it notified affected customers by email on August 16 from [email protected]. The notification used the subject line: “[Important] Your SafePal Order Information Has Been Affected.”

SafePal advised customers to independently verify any communication through its official website rather than trusting links included in messages. SafePal has also opened a dedicated support channel for customers affected by the incident.

The company said it contacted relevant logistics and fulfillment partners to determine whether the exposure extended into other systems. It also reported taking down more than 30 fraudulent websites and phishing links connected to scam activity.

As part of its response, SafePal said it reduced the retention period for personal data in the affected order-processing environment to 90 days, subject to legal requirements.

The company is also engaging an independent third-party security firm to validate the remediation and review its wider order-processing systems.

Customers are advised never to share a seed phrase, private key, or wallet password with anyone claiming to represent SafePal. SafePal said it will not request those credentials through email, phone calls, text messages, social media, or any other communication channel.

Users should avoid clicking links or scanning QR codes in unexpected messages. They should manually type the SafePal web address into a browser when checking account or support information. SafePal warned that attackers have used lookalike domains, including domains that replace the lowercase letter “l” with an uppercase “I”.

Customers who have already entered a seed phrase or private key into a suspicious website should treat the wallet as compromised. They should create a new wallet through an official SafePal device or application and transfer remaining assets immediately.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.