Loading market data...

Safepal Data Breach Exposes 39,798 Customers to Phishing Risk

Safepal Data Breach Exposes 39,798 Customers to Phishing Risk

A faulty plugin

The breach stemmed from a plugin used to track orders. It malfunctioned, leaving a gap that unauthorized threat actors exploited. The company did not specify what kind of data was taken, but the disclosure ties the exposure directly to customer records linked to those orders.

Safepal said the incident is a new customer data breach, though it offered no timeline for when it discovered the problem. The disclosure does not say how the attackers gained entry beyond the plugin failure, or whether any of the stolen data has been used.

" Translation: "

Un plugin difettoso

La violazione è originata da un plugin utilizzato per tracciare gli ordini. Ha funzionato male, lasciando un varco che gli attori non autorizzati hanno sfruttato. L'azienda non ha specificato quali dati siano stati presi, ma la divulgazione lega direttamente l'esposizione ai dati dei clienti associati a quegli ordini.

Safepal ha dichiarato che si tratta di una nuova violazione dei dati dei clienti, ma non ha fornito una tempistica per quando ha scoperto il problema. La divulgazione non dice come gli attaccanti hanno ottenuto l'accesso oltre al malfunzionamento del plugin, né se alcuni dei dati rubati siano stati utilizzati.

" I need to be careful with "it malfunctioned" - "Ha funzionato male" or "Ha avuto un malfunzionamento". Also "leaving a gap" - "lasciando un varco" or "lasciando una falla". I used "varco" but "falla" is more common for security. Let's use "falla". Also "attacco" - I used "attacco" but it should be "attori" (actors). Actually "unauthorized actors" = "attori non autorizzati" or "soggetti non autorizzati". I'll use "soggetti non autorizzati" to be clear. Let me rephrase: "Il plugin ha funzionato male, lasciando una falla che i soggetti non autorizzati hanno sfruttato." That's better. Also "The company did not specify what kind of data was taken" -> "L'azienda non ha specificato che tipo di dati siano stati prelevati" or "quali dati siano stati prelevati". I'll use "quali dati siano stati prelevati". Third: "

Phishing and fraud risk

With customer information in hand, the affected users are vulnerable to targeted phishing emails and fake phone calls. Hardware wallet owners are a common target for social engineering because a successful scam can drain crypto holdings. The company's warning suggests that the exposed data could include contact details and order history, enough for scammers to sound convincing.

Safepal has not announced any specific protective measures beyond the disclosure. Customers who believe they were affected should be cautious with unsolicited messages asking for passwords, seed phrases, or payment details. Legitimate support teams do not ask for that information.

" Translation: "

Rischio di phishing e frode

Con le informazioni dei clienti in mano, gli utenti colpiti sono vulnerabili a email di phishing mirate e chiamate telefoniche finte. I proprietari di hardware wallet sono un obiettivo comune per l'ingegneria sociale perché una truffa riuscita può prosciugare i fondi in criptovalute. L'avvertimento dell'azienda suggerisce che i dati esposti potrebbero includere dettagli di contatto e indirizzi degli ordini, sufficienti per rendere i truffatori convincenti.

Safepal non ha annunciato misure protettive specifiche oltre alla divulgazione. I clienti che credono di essere stati colpiti dovrebbero essere cauti con messaggi non richiesti che chiedono password, frasi di recupero (seed) o dettagli di pagamento. I team di supporto legittimi non chiedono queste informazioni.

" Note: "seed phrases" - in Italian, "frase di recupero" or "seed phrase" often used. I'll keep "frase di recupero" but also mention "seed phrase" in parentheses? Actually, we can say "frase di recupero" as it's standard. Also "crypto holdings" - "fondi in criptovaluta" or "possessioni in criptovaluta". I'll use "fondi in criptovaluta". Third: "

Disclosure and next steps

The company has not said whether it notified law enforcement or offered credit monitoring. It also hasn't clarified if the breach is fully contained or if more customers could be affected. The disclosure focuses on the 39,798 customers whose data was accessed during the 13-month window.

For now, the safest move for anyone who bought from Safepal during that period is to assume their data is out there. Change passwords, enable two-factor authentication, and treat any unexpected call or email with suspicion. Safepal has yet to announce further steps, leaving affected users waiting on more details about what exactly was taken and what they should do next.

" Translation: "

Divulgazione e prossimi passi

L'azienda non ha detto se ha informato le autorità o se ha offerto monitoraggio del credito. Non ha inoltre chiarito se la violazione è completamente contenuta o se altri clienti potrebbero essere coinvolti. La divulgazione si concentra sui 39.798 clienti i cui dati sono stati accessi durante la finestra di 13 mesi.

Per ora, la mossa più sicura per chiunque abbia acquistato da Safepal in quel periodo è presumere che i