SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
Overview
SafePal, a manufacturer of hardware wallets, has revealed that an authorization flaw in one of its order-tracking plugins exposed sensitive information belonging to nearly 40,000 customers. This breach compromised names, email addresses, shipping addresses, phone numbers, and details of their purchases. The company took immediate action, notifying the affected customers via email on August 16, 2023. This incident raises significant concerns about the security of customer data in online transactions, as it highlights vulnerabilities that can lead to identity theft or phishing attacks. Users of SafePal products need to be cautious and monitor their accounts for any unusual activity following this breach.
Key Takeaways
- Affected Systems: SafePal hardware wallets and order-tracking plugin
- Timeline: Disclosed on August 16, 2023
Original Article Summary
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line "[Important] Your SafePal Order
Impact
SafePal hardware wallets and order-tracking plugin
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed on August 16, 2023
Remediation
Not specified
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Phishing, Data Breach.