SafePal Breach Spurs Phishing & Fake Support Scams

Infosecurity Magazine · Medium sophistication
Last updated August 17, 2026

SafePal disclosed a breach that exposed order and contact details for nearly 40,000 customers, and warned the stolen data may be used to run targeted phishing and impersonation scams. The company cautioned customers to expect fake support messages, refund offers, and firmware-update requests designed to trick people into revealing wallet credentials.

Key findings

  • SafePal reported order information tied to 39,798 customers was compromised.
  • Exposed data includes names, emails, shipping addresses, phone numbers, and purchase details (useful for highly believable, targeted scams).
  • SafePal says wallet credentials (seed phrases/private keys) were not part of the breach, but warns attackers may attempt to trick customers into handing them over.
  • SafePal warned of multiple scam channels: phone calls, emails, texts, letters, refund offers, firmware-update requests, and fake customer support.
  • SafePal says it has already taken down “over 30 fraudulent websites and phishing links” connected to the incident.
  • The issue reportedly originated from a vulnerability in an order-tracking function that could expose other customers’ order information under certain conditions.

Who’s being targeted

  • Commonly targeted roles: All Employees, Executives, Customer Support, IT/Security, Communications/PR.
  • Affected industries: Cryptocurrency, Consumer electronics, Financial services (crypto users).
  • Attack channels: email, website, vishing, smishing.
  • Impersonated: SafePal Customer Support / SafePal Security Team, SafePal employee / SafePal Support, SafePal Refunds / SafePal Billing.

Awareness takeaways

  • Treat breach-related outreach as suspicious, verify via official channels you navigate to yourself.
  • Never share seed phrases, private keys, or wallet passwords, legitimate support should not ask for them.
  • Do not click links or scan QR codes from unsolicited messages, even if they reference a real incident.
  • Report suspicious messages, calls, letters, and websites quickly to limit harm to others.

Red flags to watch for

  • Unsolicited message pressuring an urgent firmware update
  • Includes a link/redirect instead of telling users to type the SafePal address manually
  • Any request for seed phrase/private key/password (SafePal says it never requests this)
  • Caller claims to be SafePal and asks for seed phrase/private key/password
  • Creates urgency tied to the breach to push immediate compliance
  • Requests sensitive information that SafePal explicitly says it never collects
  • Unexpected refund message tied to a public incident
  • Includes a link or QR code in an unsolicited text
  • Pushes you to provide additional personal info beyond what a legitimate support process would require
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

If you use SafePal, scammers now know your name, email, and what you bought, because nearly 40,000 orders leaked. They’re using that info to send super convincing fakes, like an email from “SafePal Security” titled “Firmware Update Required,” with your real name and order details, pushing you to click a link and enter your seed phrase. Here’s the catch: SafePal says it will never ask for your seed phrase, private key, or wallet password, by email, text, phone call, refund offer, or firmware update request. If someone does, it’s a scam, no matter how real it sounds. Your move: if you get any SafePal message, don’t click or call back, open the official SafePal app or type the SafePal web address yourself and check there instead.

Similar attacks

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal disclosed that nearly 40,000 customers had personal and order information exposed due to an authorization flaw in an order-tracking plug-in. While wallet secrets were not exposed, SafePal warned that criminals can use the leaked order details to run highly convincing scams (fake support,…

August 17, 2026
Fake Google Play Pages Push Spyware at Logistics

Fake Google Play Pages Push Spyware at Logistics

A real campaign is targeting logistics firms with fake Google Play pages impersonating well-known logistics brands to trick employees into installing an Android spyware app. Once installed, the spyware can steal newly received SMS messages (including one-time passcodes) and enable call forwarding,…

September 24, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026
Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026