Interestana
Home/News/SafePal Data Breach Exposes 39,798 Customer Records
BleepingComputer2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

SafePal Data Breach Exposes 39,798 Customer Records

Cryptocurrency hardware wallet provider SafePal disclosed a data breach on June 11, 2024, that compromised the personal information of 39,798 customers. The breach occurred due to an exploited vulnerability in a third-party partner's system, which allowed unauthorized access to customer order data. This stolen information, including email addresses, usernames, and transaction details, is reportedly being offered for sale by a threat actor on the dark web. SafePal stated that the compromised data does not include private keys or any sensitive financial assets stored within the wallets themselves, emphasizing that users' cryptocurrency holdings remain secure.

SafePal initiated an investigation immediately upon discovering the incident and has been working with cybersecurity experts to assess the extent of the breach and bolster its security measures. The company has begun notifying affected customers, advising them to remain vigilant against phishing attempts and other potential scams that may leverage the stolen information. The vulnerability was identified and addressed by SafePal's security team, and the third-party partner involved has also implemented corrective actions to prevent future occurrences. The company has not disclosed the name of the third-party partner involved in the incident.

This incident highlights ongoing security challenges within the cryptocurrency ecosystem, where the protection of user data is paramount. Hardware wallets like SafePal are designed to provide a high level of security for digital assets by storing private keys offline, making them less susceptible to online threats. However, breaches involving associated customer data underscore the importance of comprehensive security practices across all points of interaction, including third-party service providers. The threat actor claiming to sell the data is a common tactic following such breaches, aiming to monetize the stolen information through illicit channels.

SafePal has committed to enhancing its security protocols and working closely with its partners to ensure robust data protection. The company is also exploring additional measures to safeguard customer information and rebuild trust within its user base. The incident serves as a reminder for all cryptocurrency users to practice good digital hygiene, including using strong, unique passwords, enabling two-factor authentication where available, and being wary of unsolicited communications that request personal information.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next