SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

Summary

Hardware wallet maker SafePal has announced a data exposure incident affecting nearly 40,000 customers. An authorization flaw in an order-tracking plug-in inadvertently exposed customer names, email addresses, shipping addresses, phone numbers, and purchase details. The company has begun notifying affected individuals.

IFF Assessment

FOE

This incident involves the exposure of sensitive customer data, which is negative for defenders and users.

Defender Context

This incident highlights the ongoing risks associated with third-party integrations and plugins, even for security-focused hardware. Defenders should maintain vigilance over supply chain risks and ensure proper access controls are implemented for all integrated services, especially those handling sensitive customer data. Organizations should also be prepared to respond to data exposure events and communicate transparently with affected users.

Read Full Story →