SafePal Data Breach Exposes 39,798 Customer Order Details, Data Put Up for Sale
What Happened — SafePal, a cryptocurrency hardware‑wallet provider, disclosed a breach that compromised order information for approximately 39,798 customers placed between March 2 2025 and April 11 2026. Names, email addresses, shipping addresses, phone numbers and purchase details were stolen and are being offered for sale on a cyber‑crime forum. Wallet seed phrases, private keys and payment credentials were not exposed.
Why It Matters for Compliance & Audit Readiness —
- The incident triggers SOC 2 CC5.5 (Privacy) obligations to protect personally identifiable information and to retain documented consent.
- Demonstrating a defensible breach‑response process and evidence of data‑handling controls is essential for GDPR/CCPA compliance and audit readiness.
- Verisq’s CookiePLUS capability can centralize consent records and automate DSAR workflows, delivering the audit evidence SOC 2 auditors expect.
Who Is Affected — Cryptocurrency hardware‑wallet users; broadly, the financial‑services and consumer‑technology sectors.
Recommended Actions — Map the exposed data fields to SOC 2 privacy controls, verify consent and data‑minimization practices, enable continuous monitoring of order‑processing systems, and update breach‑notification and DSAR response playbooks. Source: BleepingComputer
Technical Notes — The breach stemmed from an order‑tracking flaw (likely a misconfiguration) that allowed unauthorized retrieval of order records. No CVE was disclosed. Stolen data includes PII but not cryptographic credentials. Source: BleepingComputer