HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

SafePal Data Breach Exposes 39,798 Customer Order Details, Data Put Up for Sale

SafePal, a cryptocurrency hardware wallet provider, disclosed a breach affecting nearly 40 k customers where order information—including names, emails, shipping addresses and phone numbers—was stolen and is being sold on a cyber‑crime forum. While wallet credentials remained secure, the exposure raises privacy compliance concerns and underscores the need for robust data‑handling controls.

LiveThreat™ Intelligence · 📅 August 17, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

SafePal Data Breach Exposes 39,798 Customer Order Details, Data Put Up for Sale

What Happened — SafePal, a cryptocurrency hardware‑wallet provider, disclosed a breach that compromised order information for approximately 39,798 customers placed between March 2 2025 and April 11 2026. Names, email addresses, shipping addresses, phone numbers and purchase details were stolen and are being offered for sale on a cyber‑crime forum. Wallet seed phrases, private keys and payment credentials were not exposed.

Why It Matters for Compliance & Audit Readiness

  • The incident triggers SOC 2 CC5.5 (Privacy) obligations to protect personally identifiable information and to retain documented consent.
  • Demonstrating a defensible breach‑response process and evidence of data‑handling controls is essential for GDPR/CCPA compliance and audit readiness.
  • Verisq’s CookiePLUS capability can centralize consent records and automate DSAR workflows, delivering the audit evidence SOC 2 auditors expect.

Who Is Affected — Cryptocurrency hardware‑wallet users; broadly, the financial‑services and consumer‑technology sectors.

Recommended Actions — Map the exposed data fields to SOC 2 privacy controls, verify consent and data‑minimization practices, enable continuous monitoring of order‑processing systems, and update breach‑notification and DSAR response playbooks. Source: BleepingComputer

Technical Notes — The breach stemmed from an order‑tracking flaw (likely a misconfiguration) that allowed unauthorized retrieval of order records. No CVE was disclosed. Stolen data includes PII but not cryptographic credentials. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →