LIVE · cybersecurity feed
Live wire
breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]

zeroday.news ·

SafePal, a provider of cryptocurrency hardware wallets, has disclosed a data breach affecting approximately 39,798 customers. The incident, which exposed customer order information, stems from an exploited authorization flaw within an order-tracking plugin.

The breach impacts customers who placed orders between March 2, 2025, and April 11, 2026. The compromised data includes names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal has confirmed that sensitive information such as wallet seed phrases, private keys, passwords, bank account details, payment card numbers, or government-issued identification numbers were not exposed. The company stated that there is no evidence the incident compromised access to SafePal wallets or funds.

SafePal began notifying affected customers via email on August 16, using the subject line "[Important] Your SafePal Order Information Has Been Affected." The company has also launched an online verification tool, allowing customers to check if their order details were stolen by entering their order number and shipping country.

A threat actor is reportedly selling the stolen SafePal customer data on a cybercrime forum. The seller's claims align with SafePal's disclosed affected order period and customer count. As proof of legitimacy, the threat actor is offering to share order IDs and shipping country information for verification against SafePal's online tool.

The company first received a report consistent with the issue in early May 2026, which was initially treated as an isolated case. During that period, a customer reported receiving a phishing email and a phone call from someone impersonating a SafePal employee. The phishing email falsely claimed a security vulnerability in the SafePal X1 hardware wallet required a firmware update.

In July, SafePal initiated a comprehensive review and rebuild of its order-processing system. This investigation uncovered an authorization flaw in the order-tracking function of a plugin, which permitted unauthorized access to other customers' order information. SafePal has since patched the vulnerability and implemented additional security measures, and is working with a third-party security firm to validate the fix and conduct a broader review.

During the investigation, SafePal also identified a separate configuration error that caused a data-cleanup process to malfunction between September 2025 and April 2026. This error resulted in order data being retained from as far back as March 2025. For affected orders, SafePal has purged personal data from active e-commerce servers, while retaining an encrypted offline copy for potential law enforcement investigations.

SafePal is urging customers to be vigilant against targeted phishing emails and phone calls related to firmware upgrades, product returns, refunds, or legal investigations. The company has already taken down over 30 fraudulent websites and phishing links associated with the incident.

Customers whose order information was exposed are not advised to replace their hardware wallets or move cryptocurrency solely due to this breach. However, SafePal advises that if a customer has already shared their seed phrases or private key in response to a phishing attempt, they should consider their wallet compromised and transfer any assets to a new wallet using a trusted SafePal device or official application.

breachvulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.