Cryptopolitan
2026-01-05 13:20:47

Ledger customers personal data exposed in payment processor Global-e data leak

Ledger says there was a data breach at its payment processor Global-e, announced on January 5, 2026. Ledger emailed customers whose information was affected to say personal data, such as names and contact information, had been accessed improperly. Global-e took action upon noticing unusual activity on the part of its network and hired independent forensic experts to investigate. Ledger announces a third-party processor breach Ledger told customers that Global-e, which processes its payments, had noticed suspicious activity in part of its network. Global-e took immediate action to block the relevant systems when it became aware of suspicious activity in its cloud environment. Independent forensic experts have been hired to investigate. Community alert: Ledger had another data breach via payment processor Global-e leaking the personal data of customers (name & other contact information). Earlier today customers received the email below. pic.twitter.com/RKVbv6BTGO — ZachXBT (@zachxbt) January 5, 2026 The investigations concluded that some personal data, involving names and contact information, were breached. Ledger has refused to divulge the total number of users affected or the exact reason behind the breach. It is the second time that customers have been affected by unauthorized access at Ledger, after the first in April 2025. Ledger relies on Global-e to process payments and maintain contact information. Relying on third-party vendors creates more avenues for data to be accessed. Global-e breach leaks customer contact information The exposed data includes customer names and contact information. Ledger did not specify whether the breach included email addresses, phone numbers, physical addresses, or other types of contact information. Previous breaches have exposed various combinations of these. It does not involve wallet recovery seed phrases, private keys, or any cryptocurrency holdings. No user funds were directly taken during the Global-e breach. Past Ledger data breaches have aided phishing efforts. For instance, a breach in an e-commerce database in 2020 exposed approximately one million email addresses and detailed contact information of about 9,500 customers. Ledger’s security history since 2020 Its first major incident was in June 2020, when an unauthorized person accessed the e-commerce and marketing database via a third-party API that had been misconfigured. Approximately one million email addresses were leaked with detailed contact information for 9,500 customers, including postal addresses, phone numbers, and names. It drained between $484,000 and $600,000 in cryptocurrency from the users who were affected during a period of five hours. SushiSwap, Zapper, MetalSwap, and Harvest Finance were among the dApps affected by the compromised library being loaded. Within 40 minutes from the time it noticed the bug, Ledger’s team was able to pinpoint and fix the issue. ZachXBT warns against trusting hardware wallet companies Following Ledger’s latest disclosure, blockchain researcher ZachXBT posted a community alert. In response to a user asking where to safely store one’s funds, ZachXBT concluded that none of these hardware wallet companies can be trusted. He suggested using fake information when purchasing hardware wallets in order to protect privacy. The idea is that giving false information can make it harder for the attackers to link the real identities to cryptocurrency holdings. If hackers breach a customer database, fake contact details dilute targeted phishing. Want your project in front of crypto’s top minds? Feature it in our next industry report, where data meets impact.

获取加密通讯
阅读免责声明 : 此处提供的所有内容我们的网站,超链接网站,相关应用程序,论坛,博客,社交媒体帐户和其他平台(“网站”)仅供您提供一般信息,从第三方采购。 我们不对与我们的内容有任何形式的保证,包括但不限于准确性和更新性。 我们提供的内容中没有任何内容构成财务建议,法律建议或任何其他形式的建议,以满足您对任何目的的特定依赖。 任何使用或依赖我们的内容完全由您自行承担风险和自由裁量权。 在依赖它们之前,您应该进行自己的研究,审查,分析和验证我们的内容。 交易是一项高风险的活动,可能导致重大损失,因此请在做出任何决定之前咨询您的财务顾问。 我们网站上的任何内容均不构成招揽或要约