SafePal Data Leak: Order-Tracking Plugin Hits 39,798 Customers

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/5 · Reconnaissance

The attacker identified the plugin's order-tracking function as a potential target.

T1595 – Active Scanning
  • Only the order-tracking function of an unnamed plugin was affected
  • Exact attack vector (enumeration, manipulated API, IDOR) not confirmed by SafePal
  • No CVE number, plugin name or version disclosed
PHASE 2/5 · Initial Access

An authorization flaw (Broken Access Control) allowed the permission check to be bypassed.

T1190 – Exploit Public-Facing Application
  • Authorization flaw in the plugin's order-tracking function
  • Vulnerability class: OWASP Top 10:2021 A01 – Broken Access Control
  • Under certain conditions, unauthorized access to other customers' order data was possible
PHASE 3/5 · Collection

By bypassing access control, other customers' order data could be viewed.

T1213 – Data from Information Repositories
  • Exposed: names, email addresses, shipping addresses, phone numbers, order details
  • Not affected: seed phrases, private keys, wallet passwords, bank/payment data
  • Misconfiguration in data purge process extended the affected period (Sep 2025–Apr 2026)
PHASE 4/5 · Exfiltration

An attacker exfiltrated the order data of approximately 39,798 customers.

T1041 – Exfiltration Over C2 Channel
  • Approximately 39,798 affected customers according to SafePal
  • Affected order period: 2 March 2025 to 11 April 2026
  • An actor offered matching data for sale in a cybercrime forum (not independently verified)
PHASE 5/5 · Impact

The stolen contact and order data was used for targeted follow-up phishing campaigns.

T1566 – Phishing
  • SafePal removed more than 30 fraudulent websites and phishing links
  • Combination of contact, address and order data makes scams convincing
  • Tactics: fake support, alleged refunds, bogus firmware update prompts
Short & clear answers
Frequently asked questions about this incident
Am I affected by the SafePal data breach?
Affected are SafePal customers who placed an order between March 2, 2025 and April 11, 2026 — around 39,798 customers according to the company. These were notified individually by email on August 16, 2026 from security@safepal.com with the subject "[Important] Your SafePal Order Information Has Been Affected." You can also check your status on the official SafePal scam-protection page using your order number and delivery country.
What data was stolen in the incident?
According to SafePal, names, email addresses, shipping addresses, phone numbers, and order/purchase details were exposed. Explicitly not affected were seed phrases, private keys, wallet passwords, bank account information, payment card numbers, and government-issued ID numbers. SafePal states there is no indication of compromised access to wallets or funds.
What should I do now as an affected customer?
Expect targeted phishing attempts, since contact, address, and order details combined make scams very convincing — such as fake support, bogus refunds, or fake firmware update prompts. Do not click links in unsolicited messages, and only visit SafePal pages by typing the address manually. Germany's BSI generally recommends using strong passwords and enabling two-factor authentication.
Are my crypto wallet and funds at risk?
According to SafePal, no seed phrases, private keys, wallet passwords, or other wallet credentials were affected. The order-tracking function is described as independent from SafePal's other systems. There is also no indication of any unauthorized access to wallets or balances.
I run my own online shop — am I at risk from the same plugin?
SafePal has not published the plugin's name or version, so no direct risk to other shops can be inferred. Still, review your own order, tracking, and support integrations: test in an authorized test environment whether customer A can ever view customer B's order data, and ensure this access check runs server-side. Also review your server and API logs for suspicious request patterns or attempts to enumerate sequential order numbers.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.