Data Leak at a Ledger Partner

A data breach at Ledger’s payment partner may have exposed customers’ contact details, but it did not compromise wallets.

Data Leak at a Ledger Partner

Ledger announced that a data incident occurred at an external payment service provider. The company involved is Global-e, whose cloud systems were accessed without authorization. As a result, some information related to customer orders may have been exposed.

According to the statement, the incident affected a system used to process orders placed on Ledger’s website as well as on other online stores. The exposed data may have included customers’ names, physical addresses, email addresses, phone numbers, and order details. The company emphasized that payment information was not compromised.

Ledger stressed that the breach did not impact its own infrastructure. Devices, hardware wallets, and recovery phrases remain secure. The payment partner does not have access to wallet balances or any data that could be used to take control of users’ funds.

Customers were also informed through a message sent by Global-e, which reported unusual activity detected in its cloud systems.

Security experts urge users to exercise extra caution. They recommend ignoring suspicious messages, unsolicited contact requests, or links impersonating Ledger support. Under no circumstances should recovery phrases or other sensitive information be shared.

Share