cryptonews
2026-01-05 14:55:11

Ledger Hit by Another Data Breach — Customer Names and Contact Details Exposed

Ledger, a hardware wallet manufacturer, which has historically been known by the reputation of keeping crypto assets offline, has suffered another data exposure incident and has brought back old worries regarding the privacy of customers and third-party risk in the industry. On January 5, 2026, blockchain researcher ZachXBT revealed that the personal information of Ledger customers was accessed in a hack on Global-e, a payment processor that the company uses. Community alert: Ledger had another data breach via payment processor Global-e leaking the personal data of customers (name & other contact information). Earlier today customers received the email below. pic.twitter.com/RKVbv6BTGO — ZachXBT (@zachxbt) January 5, 2026 Ledger Breach Raises Phishing Concerns Despite No Wallet Impact ZachXBT reported that victimized customers were sent an email informing them that Global-e had noticed suspicious activity in some part of its cloud environment. The payment company claimed that it was fast enough to lock down and take control of its systems after it detected the problem and contracted external forensic investigators. No indication was given that there was an exposure of payment card details, passwords, recovery phrases, and wallet private keys. so Ledger's payment processor Global-e got breached and name & contact information were leaked (none of the payment information fortunately but it doesn't make it better). This is all fucking insane – everything you do online will be fucking leaked one day, so don't use your real… pic.twitter.com/95QVR7zlO5 — sudo rm -rf –no-preserve-root / (@pcaversaccio) January 5, 2026 Ledger stated in the email that the intrusion was at the level of a third-party partner and not in the fundamental security of its hardware wallets. While funds remain safe, security researchers and community members warned that the exposure significantly increases the risk of targeted phishing and social engineering attacks, particularly given Ledger’s history. This latest incident comes at a sensitive time for crypto security. It follows days after Trust Wallet users suffered unauthorized fund outflows linked to a compromised browser extension and days after attackers targeted MetaMask users in coordinated wallet-draining attempts . Multiple Trust Wallet users experienced unauthorized fund outflows on Thursday due to a new browser extension theft. Losses are estimated to surpass $6 million. #TrustWallet #CryptoTheft #TrustWalletTheft https://t.co/mchzwWAHK3 — Cryptonews.com (@cryptonews) December 26, 2025 Although unrelated technically, the clustering of incidents has heightened user anxiety across the ecosystem. Ledger’s name carries particular weight in data breach discussions due to the severe fallout from its 2020 e-commerce and marketing database leak. That breach exposed roughly 1.1 million email addresses and detailed personal information, including home addresses and phone numbers, for about 292,000 customers. The data was later dumped publicly, leading to years of persistent phishing campaigns, extortion attempts, and even reports of physical threats against known crypto holders. Repeated Data Leaks Expose Long-Term Risks for Ledger Users The company has also faced other security challenges, as in December 2023, attackers compromised Ledger’s Connect Kit JavaScript library through a supply-chain exploit, draining nearly $500,000 from users who interacted with affected decentralized applications during a short window. Security experts note that while the hardware wallets themselves remain uncompromised, repeated leaks of customer data create long-term risks that extend beyond immediate financial loss. Exposed personal information is often reused in highly convincing phishing campaigns, including fake emails, messages, and even physical letters. In April 2025, Ledger users received professionally designed mail telling them to scan QR codes and input their 24-word recovery phrases, which was a scam that the company confirmed to be fake. Owners of @Ledger hardware wallets have reported receiving fake letters designed to trick them into revealing their wallet seed phrases. #Ledger #Scam https://t.co/s0jxsJxckm — Cryptonews.com (@cryptonews) April 30, 2025 Some community members traced those efforts back to data obtained during earlier breaches, showing how long such incidents can echo. The Ledger hack also confirms a larger pattern in the industry, as in December 2025, crypto tax software maker Koinly alerted users that their email addresses and basic profile information might have been leaked in a hack on analytics firm Mixpanel. @KoinlyOfficial warns a third-party breach may have exposed user emails but stresses that no wallet, transaction, tax, or portfolio data was shared with Mixpanel. #CryptoSecurity #CryptoTax #Koinly https://t.co/ASDxMchfyg — Cryptonews.com (@cryptonews) December 23, 2025 Supply chain vulnerabilities are mentioned by investigators and regulators as one of the least secure links in crypto security, as attackers focus on vendors who have access to user data, not core systems. The attackers are dynamic and evolving in spite of the reported reduction of phishing-related losses by 83% in 2025 . Security companies have noted that the number of losses peaks during times of high activity in the market, and low-activity markets have lower incidences. The post Ledger Hit by Another Data Breach — Customer Names and Contact Details Exposed appeared first on Cryptonews .

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.