Find notable cyber news and cases, enriched with sources, timelines, and signals.

SafePal customer order data breach and sale claim

Data Leak
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

SafePal disclosed a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and the stolen dataset is now being offered for sale. Exposed records included names, email addresses, shipping addresses, phone numbers, and purchase information from orders placed between March 2, 2025, and April 11, 2026. The exposure increases targeted phishing and social-engineering risk, while SafePal says wallet seed phrases, private keys, passwords, and funds were not compromised.

Related Happenings

SafePal hit by cyberattack

Incident
H score44 First: 17.08.2026 02:47 Last: 17.08.2026 02:47 Sources 1

How related: However, as part of this investigation, SafePal determined that a threat actor exploited the flaw to steal order information belonging to approximately 39,798 customers.

About this happening: The SafePal breach exposed customer order information after an authorization flaw in the order-processing system was exploited, putting about 39,798 customers at r...

SafePal order-tracking plug-in authorization actively exploited security flaw

Vulnerability
H score38 First: 17.08.2026 02:47 Last: 17.08.2026 02:47 Sources 1

How related: In July, SafePal began what it described as a "full review and rebuild" of its order-processing system and discovered an authorization flaw in the order-tracking function of a plug-in that allowed unauthorized access to another customer's order information.

About this happening: SafePal's order-tracking plug-in had an authorization flaw that was actively exploited to expose customer order information for about 39,798 customers. The wea...

Timeline

  1. 17.08.2026 02:47 2 articles · 1h ago

    SafePal customer order data breach and sale claim

    Initial Disclosure

    SafePal first received a report consistent with the exposure in early May 2026 and initially treated it as isolated. The issue was later escalated into a formal investigation that identified the order-tracking flaw and the customer-data theft.

    Show sources