Security News

SafePal Data Breach Exposes Details of 40,000 Customers

Security Week · 17 Aug 2026
Key Takeaway Regularly audit and update any third-party plugins or integrations connected to customer data, as they can become an easy entry point for attackers.

Cryptocurrency wallet provider SafePal has confirmed a data breach affecting approximately 40,000 customers. According to reports, attackers exploited a vulnerability in the order-tracking function of a third-party plugin used by the company, allowing them to gain unauthorised access to customer information.

The breach highlights a growing risk for businesses that rely on plugins and third-party integrations to power everyday functions like order tracking, payments, or customer support. These add-ons often connect directly to sensitive customer databases, meaning a single flaw can expose large volumes of personal data even if a company's core systems remain secure.

While details on the exact nature of the exposed data have not been fully disclosed, incidents like this serve as a reminder that supply chain and plugin security are just as important as protecting internal systems. Businesses of all sizes, including small and medium enterprises using similar e-commerce or tracking tools, should review the security practices of any third-party software they rely on.

data breach SafePal third-party risk cryptocurrency plugin security
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.