SafePal Breach Spurs Phishing & Fake Support Scams

Infosecurity Magazine · Medium sophistication
Last updated August 17, 2026

SafePal disclosed a breach that exposed order and contact details for nearly 40,000 customers, and warned the stolen data may be used to run targeted phishing and impersonation scams. The company cautioned customers to expect fake support messages, refund offers, and firmware-update requests designed to trick people into revealing wallet credentials.

Key findings

  • SafePal reported order information tied to 39,798 customers was compromised.
  • Exposed data includes names, emails, shipping addresses, phone numbers, and purchase details (useful for highly believable, targeted scams).
  • SafePal says wallet credentials (seed phrases/private keys) were not part of the breach, but warns attackers may attempt to trick customers into handing them over.
  • SafePal warned of multiple scam channels: phone calls, emails, texts, letters, refund offers, firmware-update requests, and fake customer support.
  • SafePal says it has already taken down “over 30 fraudulent websites and phishing links” connected to the incident.
  • The issue reportedly originated from a vulnerability in an order-tracking function that could expose other customers’ order information under certain conditions.

Who’s being targeted

  • Commonly targeted roles: All Employees, Executives, Customer Support, IT/Security, Communications/PR.
  • Affected industries: Cryptocurrency, Consumer electronics, Financial services (crypto users).
  • Attack channels: email, website, vishing, smishing.
  • Impersonated: SafePal Customer Support / SafePal Security Team, SafePal employee / SafePal Support, SafePal Refunds / SafePal Billing.

Awareness takeaways

  • Treat breach-related outreach as suspicious, verify via official channels you navigate to yourself.
  • Never share seed phrases, private keys, or wallet passwords, legitimate support should not ask for them.
  • Do not click links or scan QR codes from unsolicited messages, even if they reference a real incident.
  • Report suspicious messages, calls, letters, and websites quickly to limit harm to others.

Red flags to watch for

  • Unsolicited message pressuring an urgent firmware update
  • Includes a link/redirect instead of telling users to type the SafePal address manually
  • Any request for seed phrase/private key/password (SafePal says it never requests this)
  • Caller claims to be SafePal and asks for seed phrase/private key/password
  • Creates urgency tied to the breach to push immediate compliance
  • Requests sensitive information that SafePal explicitly says it never collects
  • Unexpected refund message tied to a public incident
  • Includes a link or QR code in an unsolicited text
  • Pushes you to provide additional personal info beyond what a legitimate support process would require
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

If you use SafePal, scammers now know your name, email, and what you bought, because nearly 40,000 orders leaked. They’re using that info to send super convincing fakes, like an email from “SafePal Security” titled “Firmware Update Required,” with your real name and order details, pushing you to click a link and enter your seed phrase. Here’s the catch: SafePal says it will never ask for your seed phrase, private key, or wallet password, by email, text, phone call, refund offer, or firmware update request. If someone does, it’s a scam, no matter how real it sounds. Your move: if you get any SafePal message, don’t click or call back, open the official SafePal app or type the SafePal web address yourself and check there instead.

Similar attacks

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal disclosed that nearly 40,000 customers had personal and order information exposed due to an authorization flaw in an order-tracking plug-in. While wallet secrets were not exposed, SafePal warned that criminals can use the leaked order details to run highly convincing scams (fake support,…

August 17, 2026
Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake “Apple Found Your iPhone” Phish Steals Codes

Fake “Apple Found Your iPhone” Phish Steals Codes

A criminal service called AnonymousKit helps iPhone thieves turn stolen devices into cash by impersonating Apple and tricking victims into handing over their passcode, Apple ID, and two-factor codes. The workflow starts with a realistic “found your device” message (email or text) that includes a…

September 3, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026