Find notable cyber news and cases, enriched with sources, timelines, and signals.

SafePal hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 44
1 unique sources, 1 articles

Summary

Hide ▲

The SafePal breach exposed customer order information after an authorization flaw in the order-processing system was exploited, putting about 39,798 customers at risk of phishing and account fraud. The compromised records covered orders placed between March 2, 2025 and April 11, 2026 and included names, email addresses, shipping addresses, phone numbers, and purchase information. SafePal said the incident did not expose seed phrases, private keys, or wallet funds, and it has since fixed the flaw and notified affected customers.

Related Happenings

SafePal order-tracking plug-in authorization actively exploited security flaw

Vulnerability
H score38 First: 17.08.2026 02:47 Last: 17.08.2026 02:47 Sources 1

How related: In July, SafePal began what it described as a "full review and rebuild" of its order-processing system and discovered an authorization flaw in the order-tracking function of a plug-in that allowed unauthorized access to another customer's order information.

About this happening: SafePal's order-tracking plug-in had an authorization flaw that was actively exploited to expose customer order information for about 39,798 customers. The wea...

SafePal customer order data breach and sale claim

Data Leak
H score39 First: 17.08.2026 02:47 Last: 17.08.2026 02:47 Sources 1

How related: SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.

About this happening: SafePal disclosed a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and the stolen dataset is now being of...

Timeline

  1. 17.08.2026 02:47 2 articles · 1h ago

    SafePal warns of order-data breach affecting 39,798 customers

    Initial Disclosure

    SafePal said an authorization flaw in the order-tracking function of a plug-in let a threat actor steal customer order information, affecting approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. Exposed records included names, email addresses, shipping addresses, phone numbers, and purchase information, and SafePal said the incident did not expose wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials. SafePal notified impacted customers by email on August 16, launched an online verification tool for order checks, and said it had fixed the vulnerability and implemented additional security measures.

    Show sources