Ledger Data Leak Exposes Customer Details as Experts Warn of Phishing and Real-World Threats

Ledger Data Leak Exposes Customer Details as Experts Warn of Phishing and Real-World Threats

N
News Editor 01
2026-07-23 19:45:15
Ledger confirmed a customer data breach linked to Global-e. Experts say names and contact details can fuel phishing, social engineering and even physical risk, while urging users never to share recovery phrases.
Ledgerdata breachhardware walletphishingwallet security

Ledger has confirmed that a breach tied to its third-party e-commerce partner Global-e exposed customer data, reviving security concerns around one of crypto’s best-known hardware wallet brands. According to Ledger, private keys, wallet funds and payment information were not accessed. The exposed data involved the names and contact details of users who bought devices through Ledger’s online store.

Reports of phishing started appearing within hours of the disclosure. Users said they were receiving emails and other scam attempts from actors posing as Ledger or Global-e support, using the leaked information to pressure recipients into revealing sensitive details. Security researchers said the danger is not limited to inbox spam. Past campaigns linked to Ledger-related leaks have been associated with wallet takeovers, financial losses and concern over physical targeting in so-called wrench attacks.

Risk extends beyond the leaked customer list

Security experts said the threat is wider than the group whose data was directly exposed. Anyone publicly known to own a hardware wallet can become a target for phishing or social engineering. Zengo Wallet CEO Ouriel Ohayon told CoinDesk that users included in the leak face even greater risk because they become what he described as an official and time-stamped target.

Alexander Urbelis, chief information security officer at ENS, said some categories of leaked information raise the threat level more than others. A physical home address is especially sensitive. If that address can be tied to a hardware wallet purchase, the risk profile increases sharply.

Phishing campaigns are leaning on trust, urgency and off-channel contact

Users have reported unsolicited messages claiming to come from Ledger support, including cases where the recipient did not even own a Ledger device. Experts said the attackers are relying less on technical exploits and more on psychological pressure. Urbelis said the strongest phishing operations build credibility first with real names and order details, then switch quickly to fear and urgency through a security alert or replacement-device story that demands immediate action.

The contact methods are broadening as well. Email remains part of the playbook, but SMS messages and convincing unsolicited support calls are now common elements of the same scam pattern.

Never share a recovery phrase, and avoid panic-driven transfers

Experts were direct on the main rule: no legitimate company will ever ask for a recovery phrase. Ohayon said users should never share a seed phrase with anyone under any circumstance. He also advised checking the real sender of every email and treating unsolicited direct messages or support outreach arriving outside official channels as a warning sign.

Both experts also cautioned against rushing to move assets onchain. Ohayon said that once a person is identified as a wallet owner, the target is the individual rather than the device itself, and moving funds may simply create a public trail that attackers can follow. Urbelis gave similar advice, saying a hurried transfer can leave users exposed to a well-timed phishing attempt. For the near future, he said, people affected by this kind of offchain leak should use extra caution with emails, text messages, voicemail responses and phone calls.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.