The security vulnerability allowed unauthorized third parties to view sensitive customer records due to a software defect that persisted for over a year. SafePal revealed that a secondary configuration error in their data-cleanup process further exacerbated the exposure by retaining historical records longer than the firm’s standard policy allowed. Following the discovery of the flaw during a July investigation, the provider has restricted personal data retention to a 90-day window.
SafePal emphasized that private keys, seed phrases, and payment credentials were not stored within the compromised order-processing environment. Despite this, the company has taken down more than 30 phishing websites that leveraged the stolen data to target customers with fraudulent communications. Users are advised to remain vigilant against phishing attempts that utilize their specific purchase history to gain trust. The firm is currently working with an independent security consultant to audit its systems and has established a dedicated support channel for those affected by the incident.

Comments (0)
No comments yet. Be the first!