Threat Intelligence Brief
Curated summary with source attribution
Source: securityaffairs.com
Threat Risk: Medium
Victim: Cryptocurrency wallet users
Incident: Unauthorized access to customer PII via an authorization flaw in an order-tracking plugin.
Impact: Exposure of names, emails, phone numbers, and shipping addresses for approximately 39,798 customers.
Attacker: Unidentified threat actors
Analysis: Attackers exploited an authorization flaw in an order-tracking plugin to scrape customer PII. While wallet credentials and private keys remained secure, the leaked shipping and contact details provide a foundation for highly targeted social engineering. The breach was confirmed after the stolen data was advertised on a cybercrime forum.
Recommendations: Be extremely wary of unsolicited emails or calls claiming to be SafePal support.; Avoid entering seed phrases or private keys on any website, regardless of the urgency.; Enable multi-factor authentication on all related financial and email accounts.
Source: Security Affairs
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source