SafePal Order‑Tracking Plugin Authorization Flaw Exposes Personal Data of ≈ 39,800 Customers
What Happened — Hackers leveraged an authorization flaw in SafePal’s order‑tracking plug‑in, allowing them to retrieve order‑related personal data (names, addresses, emails, phone numbers, purchase details) for customers who placed orders between 2 Mar 2025 and 11 Apr 2026. The breach affected roughly 39,798 individuals; wallet credentials and payment information were not compromised.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a failure in SOC 2 Access Controls (CC6.1 – logical access restriction) that continuous‑compliance programs are built to detect, remediate, and evidence.
- Demonstrating timely identification, containment, and documented notification satisfies the Security and Privacy trust service criteria and provides audit‑ready proof of due diligence.
Who Is Affected — Cryptocurrency‑wallet providers, fintech SaaS platforms, and any organization that stores order‑related PII in web‑exposed components.
Recommended Actions
- Map the flaw to SOC 2 CC6.1 and CC6.2 controls; capture remediation tickets, code‑review evidence, and notification logs as audit artifacts.
- Conduct a focused access‑control review of all plug‑ins and third‑party components; implement least‑privilege checks and automated testing for authorization bypass.
- Update security‑awareness content to address phishing scenarios that leverage exposed order data.
Source: Security Affairs
Technical Notes
- Attack vector: Authorization flaw in order‑tracking plug‑in (mis‑implemented access control).
- Data exposed: Customer name, email, shipping address, phone number, order details. No wallet private keys, seed phrases, or payment card data.
- Timeline: Data from 02‑Mar‑2025 to 11‑Apr‑2026; breach disclosed 17‑Aug‑2026.