logo
    TicketsSpeakers
    News
    logo

    #Phishing

    SafePal Security Incident Exposes Personal Data of Nearly 40,000 Customers

    SafePal Security Incident Exposes Personal Data of Nearly 40,000 Customers

    Charles Obison
    August 17, 2026
    1,957 views
    Make Us Preferred on Google

     

    Crypto wallet SafePal has suffered a security breach that exposed the personal information of approximately 39,798 customers.

     

    In a post on X, the crypto wallet said the affected customers were users who placed orders between March 2, 2025, and April 11, 2026. According to SafePal, the exposed information included names, email addresses, shipping addresses, phone numbers, and purchase details.

     

    However, sensitive information such as seed phrases, private keys, wallet passwords, other wallet credentials, bank account information, payment card numbers, and government issued identification numbers were not exposed.

     

     

    Detailing the incident in a blog post, SafePal said the breach was caused by an authorization flaw in the order tracking function of one of its plug-ins associated with customer order information. The flaw made it possible for unauthorized parties to access customers' information. After detecting the flaw, SafePal said it promptly fixed the issue and introduced additional security measures.

     

    SafePal has warned affected customers to remain vigilant, as their exposed personal information could potentially be used in sophisticated phishing campaigns. According to the company, these campaigns may take several forms, including fraudulent phone calls, emails, text messages, letters, refund offers, firmware update requests, and fake customer support communications, all intended to obtain customers' wallet credentials or additional personal information.

     

    Response Efforts So Far

     

    As part of its remediation efforts, SafePal said it had fixed the flaw and implemented additional security measures. It also engaged an independent third party security firm to verify that the flaw had been fixed and conduct a broader security assessment of its systems.

     

    It said it had also opened a dedicated support channel to respond to affected customers. The crypto wallet company also claimed it had taken down more than 30 websites and phishing links reportedly linked to the scam.

    Tags:
    #crypto security#Crypto Wallets#Phishing#Cybersecurity#SafePal#Data Breach#Data Privacy
    IRS Issues Warning Over Fraud Campaign Targeting Crypto Holders

    IRS Issues Warning Over Fraud Campaign Targeting Crypto Holders

    Charles Obison
    July 31, 2026
    3,589 views
    Make Us Preferred on Google

     

    The U.S. Internal Revenue Service (IRS) has warned of a fraud campaign in which scammers are impersonating the agency and sending fake IRS letters to cryptocurrency holders in an attempt to steal personal credentials and digital assets.

     

    According to the IRS, the fake letters direct unsuspecting recipients to a fraudulent website that closely mimics the official IRS.gov website. Once there, victims are instructed to enrol in a "Digital Asset Compliance Portal" before an urgent deadline.

     

    Image credit: x.com 

     

    As part of the enrollment process, the website may ask users for personal information, including cryptocurrency wallet details, exchange account credentials, and other sensitive data that could be used to steal their digital assets.

     

    "Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence," said IRS Criminal Investigation (IRS-CI) Chief Jarod Koopman. "Before responding to unexpected requests for personal information, stop, verify the source, and report potential fraud schemes to law enforcement."

     

    Regarding the identities of those behind the campaign, the IRS said in a press release that Coinbase and its cyber intelligence partner, Dark Tower, traced the campaign's infrastructure to a domain registered through a Hong Kong registrar, while the fraudulent website was hosted in Romania.

     

    The IRS also outlined several measures to help cryptocurrency holders stay safe, including exercising caution when responding to unsolicited letters, emails, text messages, and phone calls from individuals whose identities cannot be verified.

     

    The IRS remains one of the most frequently impersonated U.S. government agencies by scammers. According to the Treasury Inspector General for Tax Administration, victims reported losses exceeding $114 million from IRS impersonation scams between 2013 and mid-2020.

     

    Tags:
    #digital assets#Cryptocurrency#Crypto Scams#Phishing#Cybersecurity#Fraud#IRS
    FBI Warns of Fake Tron Token Crypto Scam

    FBI Warns of Fake Tron Token Crypto Scam

    Charles Obison
    March 21, 2026
    2,752 views
    Make Us Preferred on Google

     

    The U.S. Federal Bureau of Investigation (FBI) has warned crypto users about a fake token on the Tron blockchain impersonating the agency.

     

    In a post on its New York X account, the FBI said some Tron users have received messages from scammers posing as the agency, asking them to complete an anti-money laundering verification to avoid having their assets frozen and falsely claiming their wallets are under investigation.

     

    The FBI cautioned against falling for such scams. “If you receive a token from an account with the details below, do not provide any identifying information to any website associated with the token,” the agency said.

     

    Users who have already sent their personal information to the scammers were urged to file a complaint with the Internet Crime Complaint Center.

     

     

    Inside Crypto Phishing Scams

    The launch of the fake FBI token is one of several crypto phishing scams that have emerged in recent months. These scams often involve impersonating recognized government agencies, companies, or public figures, tricking users into giving up their personal credentials.

     

    According to Scam Sniffer, about 106,106 victims were affected by crypto phishing scams in 2025, resulting in losses of approximately $83.85 million. 

     

    Although this represents a significant drop compared to the $494 million in losses and 332,000 victims recorded the previous year, phishing remains widely used by attackers, especially with the growing use of AI-generated phishing campaigns.

     

     

    FBI Created Fake Cryptocurrency Token

    In 2024, the FBI created a fake artificial intelligence–related token, called NexFundAI, an Ethereum-based cryptocurrency designed to catch scammers.

     

    The NexFundAI token was part of Operation “Token Mirrors,” launched to identify and expose fraudulent market makers and manipulators, including those involved in wash trading and pump-and-dump schemes.

     

    The operation was successful, as it led to the arrest of more than 18 individuals and the seizure of several million dollars from the suspects. 

     

    Tags:
    #Blockchain#Cryptocurrency#crypto news#TRON#crypto security#Crypto Scams#FBI#Phishing#Cybersecurity#Scam Alerts