SafePal Breach Spurs Phishing & Fake Support Scams

Infosecurity Magazine · Medium sophistication
Last updated August 17, 2026

SafePal disclosed a breach that exposed order and contact details for nearly 40,000 customers, and warned the stolen data may be used to run targeted phishing and impersonation scams. The company cautioned customers to expect fake support messages, refund offers, and firmware-update requests designed to trick people into revealing wallet credentials.

Key findings

  • SafePal reported order information tied to 39,798 customers was compromised.
  • Exposed data includes names, emails, shipping addresses, phone numbers, and purchase details (useful for highly believable, targeted scams).
  • SafePal says wallet credentials (seed phrases/private keys) were not part of the breach, but warns attackers may attempt to trick customers into handing them over.
  • SafePal warned of multiple scam channels: phone calls, emails, texts, letters, refund offers, firmware-update requests, and fake customer support.
  • SafePal says it has already taken down “over 30 fraudulent websites and phishing links” connected to the incident.
  • The issue reportedly originated from a vulnerability in an order-tracking function that could expose other customers’ order information under certain conditions.

Who’s being targeted

  • Commonly targeted roles: All Employees, Executives, Customer Support, IT/Security, Communications/PR.
  • Affected industries: Cryptocurrency, Consumer electronics, Financial services (crypto users).
  • Attack channels: email, website, vishing, smishing.
  • Impersonated: SafePal Customer Support / SafePal Security Team, SafePal employee / SafePal Support, SafePal Refunds / SafePal Billing.

Awareness takeaways

  • Treat breach-related outreach as suspicious, verify via official channels you navigate to yourself.
  • Never share seed phrases, private keys, or wallet passwords, legitimate support should not ask for them.
  • Do not click links or scan QR codes from unsolicited messages, even if they reference a real incident.
  • Report suspicious messages, calls, letters, and websites quickly to limit harm to others.

Red flags to watch for

  • Unsolicited message pressuring an urgent firmware update
  • Includes a link/redirect instead of telling users to type the SafePal address manually
  • Any request for seed phrase/private key/password (SafePal says it never requests this)
  • Caller claims to be SafePal and asks for seed phrase/private key/password
  • Creates urgency tied to the breach to push immediate compliance
  • Requests sensitive information that SafePal explicitly says it never collects
  • Unexpected refund message tied to a public incident
  • Includes a link or QR code in an unsolicited text
  • Pushes you to provide additional personal info beyond what a legitimate support process would require
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

If you use SafePal, scammers now know your name, email, and what you bought, because nearly 40,000 orders leaked. They’re using that info to send super convincing fakes, like an email from “SafePal Security” titled “Firmware Update Required,” with your real name and order details, pushing you to click a link and enter your seed phrase. Here’s the catch: SafePal says it will never ask for your seed phrase, private key, or wallet password, by email, text, phone call, refund offer, or firmware update request. If someone does, it’s a scam, no matter how real it sounds. Your move: if you get any SafePal message, don’t click or call back, open the official SafePal app or type the SafePal web address yourself and check there instead.

Similar attacks

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal disclosed that nearly 40,000 customers had personal and order information exposed due to an authorization flaw in an order-tracking plug-in. While wallet secrets were not exposed, SafePal warned that criminals can use the leaked order details to run highly convincing scams (fake support,…

August 17, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA…

July 29, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Levi’s Breach Tied to Phone-to-Phish Workflow

Levi’s Breach Tied to Phone-to-Phish Workflow

Levi Strauss disclosed a breach after attackers used social engineering to access three employees’ work computers and steal some corporate data. Separately, reporting and Google’s tracking describe a broader campaign where criminals call employees while posing as coworkers or IT, then send them to…

August 10, 2026
Quishing Emails Use QR Codes to Bypass Filters

Quishing Emails Use QR Codes to Bypass Filters

The article describes how attackers use QR codes in emails (“quishing”) to hide malicious links, push victims onto less-protected mobile phones, and steal credentials or MFA tokens. It also cites an FBI notice describing North Korea’s Kimsuky using QR codes in spearphishing emails targeting think…

August 18, 2026