Ledger Hit by Another Customer Data Leak as Global-e Flaw Raises Phishing Risk

Ledger Hit by Another Customer Data Leak as Global-e Flaw Raises Phishing Risk

N
News Editor 01
2026-07-24 00:15:16
ZachXBT said Ledger users were affected by a new personal data leak tied to payment partner Global-e. Exposed data reportedly included names, addresses, and phone numbers, but not seed phrases or private keys.
Ledgerdata breachGlobal-ehardware walletphishing

Ledger is facing another customer data leak after on-chain investigator ZachXBT disclosed on January 5, 2026 that users of the hardware wallet maker were affected by a fresh exposure of personal information. The report spread quickly across the crypto community, with several users reposting the warning and sharing screenshots of notification emails received by affected customers.

Global-e identified as the source of the exposure

The incident was not described as a direct compromise of Ledger’s own systems. Based on the information disclosed so far, the leak stemmed from a security flaw at Global-e, a payment service provider that works with Ledger. The exposed data reportedly included customer names, physical addresses, and phone numbers. Seed phrases, passwords, and private keys were not part of the leak.

That distinction matters, but it does not remove the danger. Once contact details are exposed, attackers can build targeted phishing campaigns, pose as official support staff, or send fraudulent emails and text messages designed to push users into revealing recovery phrases or installing fake update software.

The 2020 breach still shapes user concerns

This is not the first time Ledger has dealt with a customer data incident. In 2020, the company’s ecommerce database was breached, exposing more than 1 million customer email addresses along with some personal information. That breach was followed by years of phishing attempts, as scammers used the leaked data to send fake messages aimed at collecting wallet recovery phrases. Some users later reported asset losses.

The new case, tied to a third-party provider rather than Ledger itself, puts supply-chain security back in focus. User funds are not said to be directly at risk from this specific incident. Even so, leaked identity and contact data can create long-term exposure by making social engineering attacks more convincing.

Users urged to treat recovery phrase requests as red flags

Security guidance shared around the incident centers on skepticism. Users are advised to treat any unexpected Ledger-related email, SMS, or phone call with caution, especially messages asking for a 24-word recovery phrase, requesting a device reset, or urging the download of update software.

Other recommended steps include using a dedicated email account for crypto activity, enabling two-factor authentication, and reviewing wallet authorization records on a regular basis. Users who received a breach notification email are also advised to check Ledger’s official website directly for the latest statement rather than following links embedded in the message.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.