Interestana
Home/News/SafePal Wallet Maker Reports Data Exposure for 39,798 Customers
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

SafePal Wallet Maker Reports Data Exposure for 39,798 Customers

SafePal Wallet Maker Reports Data Exposure for 39,798 Customers

SafePal, a company specializing in hardware wallets for cryptocurrency, has announced a significant data exposure incident affecting approximately 39,798 of its customers. The breach stemmed from an authorization flaw within a third-party order-tracking plug-in integrated into SafePal's e-commerce platform. This vulnerability allowed unauthorized access to sensitive customer information. The exposed data includes full names, email addresses, physical shipping addresses, and phone numbers. Additionally, details pertaining to customer purchases were also compromised. SafePal confirmed that all affected individuals were notified directly via email on August 16. These notifications were sent from the official security email address, [email protected], and carried the subject line "[Important] Your SafePal Order." The company stated that the plug-in in question was developed by a third-party vendor, indicating a potential supply chain vulnerability. SafePal has since taken steps to address the issue, including disabling the compromised plug-in and initiating an investigation with the third-party vendor. The company emphasized that its core hardware wallet products and the private keys of its users were not affected by this incident, as these are stored offline and are not accessible through the e-commerce platform. SafePal is advising all customers to remain vigilant against potential phishing attempts or other fraudulent activities that might arise from the exposed information. The company also recommends that users review their purchase history and be cautious of any unsolicited communications. This incident highlights the ongoing challenges faced by companies in securing their e-commerce operations and protecting customer data from third-party risks. Hardware wallet providers, in particular, must maintain robust security protocols across all customer touchpoints, including online sales and support channels, to uphold user trust. The exposure of personal and purchase data, while not directly impacting the security of cryptocurrency holdings, can lead to significant privacy concerns and potential social engineering attacks. SafePal's proactive notification to affected customers is a crucial step in mitigating further harm, allowing individuals to take necessary precautions. The company's commitment to transparency in disclosing the nature and scope of the breach is also a key factor in managing customer relations during such incidents. Further details regarding the specific third-party plug-in and the vendor involved are expected to be released as the investigation progresses.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next