Industry News

SafePal Data Breach Exposes Nearly 40,000 Customers to Phishing Risk

Bitcoin · 17 Aug 2026
Key Takeaway Regularly review and update any third-party plugins or apps connected to your business systems, as a single flaw can expose customer data and enable phishing attacks.

Hardware wallet maker SafePal has confirmed that a security flaw in a third-party plugin used to track customer orders allowed unauthorized parties to access personal data belonging to 39,798 customers. The company says the exposure occurred over an extended period, giving attackers a long window to collect information before the issue was identified.

SafePal has warned affected users that the exposed data could be used to craft convincing phishing emails or fraudulent phone calls, particularly dangerous given the company's role in cryptocurrency security. Attackers often use breached order or contact details to impersonate legitimate businesses and trick victims into revealing sensitive information such as passwords, recovery phrases, or payment details.

While this incident involves a large hardware wallet provider, it highlights a risk relevant to any small business using third-party plugins or apps to manage orders and customer data: a single flawed integration can expose customer information well beyond what the business intended to share. Regularly auditing third-party tools and promptly patching or disabling faulty plugins can reduce this risk.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Bitcoin. We link back to every original so you can read it yourself.