SafePal customer order data breach and sale claim
Data Leak
Summary
Hide ▲
Show ▼
SafePal disclosed a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and the stolen dataset is now being offered for sale. Exposed records included names, email addresses, shipping addresses, phone numbers, and purchase information from orders placed between March 2, 2025, and April 11, 2026. The exposure increases targeted phishing and social-engineering risk, while SafePal says wallet seed phrases, private keys, passwords, and funds were not compromised.
Related Happenings
SafePal hit by cyberattack
Incident
H score44
First: 17.08.2026 02:47
Last: 17.08.2026 02:47
Sources 1
How related:
However, as part of this investigation, SafePal determined that a threat actor exploited the flaw to steal order information belonging to approximately 39,798 customers.
About this happening:
SafePal disclosed a data breach that exposed customer order information for 39,798 customers after an authorization flaw in a plug-in order-tracking function....
SafePal hit by cyberattack
IncidentHow related: However, as part of this investigation, SafePal determined that a threat actor exploited the flaw to steal order information belonging to approximately 39,798 customers.
About this happening: SafePal disclosed a data breach that exposed customer order information for 39,798 customers after an authorization flaw in a plug-in order-tracking function....
SafePal order-tracking plug-in authorization actively exploited security flaw
Vulnerability
H score37
First: 17.08.2026 02:47
Last: 17.08.2026 02:47
Sources 1
How related:
In July, SafePal began what it described as a "full review and rebuild" of its order-processing system and discovered an authorization flaw in the order-tracking function of a plug-in that allowed unauthorized access to another customer's order information.
About this happening:
SafePal's order-tracking plug-in had an authorization flaw that was actively exploited to expose customer order information for about 39,798 customers. The wea...
SafePal order-tracking plug-in authorization actively exploited security flaw
VulnerabilityHow related: In July, SafePal began what it described as a "full review and rebuild" of its order-processing system and discovered an authorization flaw in the order-tracking function of a plug-in that allowed unauthorized access to another customer's order information.
About this happening: SafePal's order-tracking plug-in had an authorization flaw that was actively exploited to expose customer order information for about 39,798 customers. The wea...
ShipMonk hit by network compromise
Incident
H score43
First: 13.08.2026 18:13
Last: 13.08.2026 18:13
Sources 1
About this happening:
ShipMonk suffered unauthorized access to systems containing customer data, creating a compromise event that exposed information tied to Trezor orders. The provider bre...
ShipMonk hit by network compromise
IncidentAbout this happening: ShipMonk suffered unauthorized access to systems containing customer data, creating a compromise event that exposed information tied to Trezor orders. The provider bre...
Trezor customers customer data exposed after ShipMonk breach
Data Leak
H score44
First: 13.08.2026 18:13
Last: 13.08.2026 18:13
Sources 1
About this happening:
A ShipMonk breach exposed Trezor customer order data for 11,742 fully exposed records and 1,947 partially exposed records, increasing the risk of phishing and impe...
Trezor customers customer data exposed after ShipMonk breach
Data LeakAbout this happening: A ShipMonk breach exposed Trezor customer order data for 11,742 fully exposed records and 1,947 partially exposed records, increasing the risk of phishing and impe...
Timeline
-
18.08.2026 12:10 1 articles · 12d ago
Threat actor advertises SafePal order dataset on cybercrime forum
Victim Impact UpdateA threat actor advertised a SafePal order dataset on a cybercrime forum on August 16 and offered to share order IDs and shipping countries so prospective buyers could check them against SafePal's own verification tool.
Show sources
- SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers — thehackernews.com — 18.08.2026 12:10
-
17.08.2026 02:47 2 articles · 14d ago
SafePal customer order data breach and sale claim
Initial DisclosureSafePal first received a report consistent with the exposure in early May 2026 and initially treated it as isolated. The issue was later escalated into a formal investigation that identified the order-tracking flaw and the customer-data theft.
Show sources
- SafePal data breach impacts 39,798 customers, stolen info for sale — www.bleepingcomputer.com — 17.08.2026 02:47
- SafePal data breach impacts 39,798 customers, stolen info for sale — www.bleepingcomputer.com — 17.08.2026 02:47