Find notable cyber news and cases, enriched with sources, timelines, and signals.

SafePal customer order data breach and sale claim

Data Leak
First reported
Last updated
Happening score
H score 39
2 unique sources, 2 articles

Summary

Hide ▲

SafePal disclosed a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and the stolen dataset is now being offered for sale. Exposed records included names, email addresses, shipping addresses, phone numbers, and purchase information from orders placed between March 2, 2025, and April 11, 2026. The exposure increases targeted phishing and social-engineering risk, while SafePal says wallet seed phrases, private keys, passwords, and funds were not compromised.

Related Happenings

SafePal hit by cyberattack

Incident
H score44 First: 17.08.2026 02:47 Last: 17.08.2026 02:47 Sources 1

How related: However, as part of this investigation, SafePal determined that a threat actor exploited the flaw to steal order information belonging to approximately 39,798 customers.

About this happening: SafePal disclosed a data breach that exposed customer order information for 39,798 customers after an authorization flaw in a plug-in order-tracking function....

SafePal order-tracking plug-in authorization actively exploited security flaw

Vulnerability
H score37 First: 17.08.2026 02:47 Last: 17.08.2026 02:47 Sources 1

How related: In July, SafePal began what it described as a "full review and rebuild" of its order-processing system and discovered an authorization flaw in the order-tracking function of a plug-in that allowed unauthorized access to another customer's order information.

About this happening: SafePal's order-tracking plug-in had an authorization flaw that was actively exploited to expose customer order information for about 39,798 customers. The wea...

ShipMonk hit by network compromise

Incident
H score43 First: 13.08.2026 18:13 Last: 13.08.2026 18:13 Sources 1

About this happening: ShipMonk suffered unauthorized access to systems containing customer data, creating a compromise event that exposed information tied to Trezor orders. The provider bre...

Trezor customers customer data exposed after ShipMonk breach

Data Leak
H score44 First: 13.08.2026 18:13 Last: 13.08.2026 18:13 Sources 1

About this happening: A ShipMonk breach exposed Trezor customer order data for 11,742 fully exposed records and 1,947 partially exposed records, increasing the risk of phishing and impe...

Timeline

  1. 18.08.2026 12:10 1 articles · 12d ago

    Threat actor advertises SafePal order dataset on cybercrime forum

    Victim Impact Update

    A threat actor advertised a SafePal order dataset on a cybercrime forum on August 16 and offered to share order IDs and shipping countries so prospective buyers could check them against SafePal's own verification tool.

    Show sources
  2. 17.08.2026 02:47 2 articles · 14d ago

    SafePal customer order data breach and sale claim

    Initial Disclosure

    SafePal first received a report consistent with the exposure in early May 2026 and initially treated it as isolated. The issue was later escalated into a formal investigation that identified the order-tracking flaw and the customer-data theft.

    Show sources