Find notable cyber news and cases, enriched with sources, timelines, and signals.

SafePal hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 44
2 unique sources, 2 articles

Summary

Hide ▲

SafePal disclosed a data breach that exposed customer order information for 39,798 customers after an authorization flaw in a plug-in order-tracking function. The affected orders were placed between March 2, 2025 and April 11, 2026, and the stolen records included names, email and shipping addresses, phone numbers, and purchase details. SafePal said the incident did not expose seed phrases, private keys, wallet credentials, or funds, but it warned customers about phishing attempts and said it had removed over 30 fraudulent websites and phishing links tied to the breach.

Related Happenings

SafePal order-tracking plug-in authorization actively exploited security flaw

Vulnerability
H score37 First: 17.08.2026 02:47 Last: 17.08.2026 02:47 Sources 1

How related: In July, SafePal began what it described as a "full review and rebuild" of its order-processing system and discovered an authorization flaw in the order-tracking function of a plug-in that allowed unauthorized access to another customer's order information.

About this happening: SafePal's order-tracking plug-in had an authorization flaw that was actively exploited to expose customer order information for about 39,798 customers. The wea...

SafePal customer order data breach and sale claim

Data Leak
H score39 First: 17.08.2026 02:47 Last: 17.08.2026 02:47 Sources 1

How related: SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.

About this happening: SafePal disclosed a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and the stolen dataset is now being of...

Latest development: 18.08.2026 12:10

A threat actor advertised a SafePal order dataset on a cybercrime forum on August 16 and offered to share order IDs and shipping countries so prospective buyers could check them against SafePal's own verification tool.

Timeline

  1. 17.08.2026 02:47 3 articles · 14d ago

    SafePal warns of order-data breach affecting 39,798 customers

    Initial Disclosure

    SafePal said an authorization flaw in the order-tracking function of a plug-in let a threat actor steal customer order information, affecting approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. Exposed records included names, email addresses, shipping addresses, phone numbers, and purchase information, and SafePal said the incident did not expose wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials. SafePal notified impacted customers by email on August 16, launched an online verification tool for order checks, and said it had fixed the vulnerability and implemented additional security measures.

    Show sources