SafePal Order‑Tracking Plug‑in Flaw Exposes 39,798 Customer Records
What Happened — A flaw in a third‑party order‑tracking plug‑in allowed one SafePal customer to view another’s order details. The defect exposed names, emails, shipping addresses, phone numbers and purchase data for 39,798 customers between 2 Mar 2025 and 11 Apr 2026.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a control gap that SOC 2 – Security and Confidentiality criteria require you to identify, remediate, and continuously monitor.
- Demonstrating that the mis‑configuration was detected, fixed, and that evidence of the change is retained satisfies the “Control Activities” and “Monitoring” principles of a SOC 2 audit.
- Mapping this breach to your control framework provides defensible audit evidence and shows due‑diligence to regulators and partners.
Who Is Affected – Cryptocurrency‑wallet providers, fintech platforms, and any SaaS that handles order or shipping data.
Recommended Actions –
- Map the plug‑in authorization flaw to the relevant SOC 2 control (CC6.1 – Logical Access Controls).
- Capture remediation tickets, code‑review logs, and post‑mortem reports as continuous audit evidence.
- Reduce data‑retention periods for personally identifiable order information and verify that the change is reflected in your data‑retention policy.
Source: Help Net Security
Technical Notes – The vulnerability was an authorization bypass in a third‑party order‑tracking plug‑in, allowing unauthorized read access to order records. No wallet‑private keys or financial credentials were compromised. The breach was later linked to phishing attempts that leveraged the exposed data. Source: same as above