Ledger (@Ledger) on X

2 min read Original article ↗
  • user avatar

    Today we were alerted to the dump of the contents of a Ledger customer database on Raidforum. We are still confirming, but early signs tell us that this indeed could be the contents of our e-commerce database from June, 2020.

  • user avatar

    We were aware of this data breach, alerted the authorities, our users, and have been fighting downstream attacks ever since. For more information on this breach, please see the original entry in our FAQ: support.ledger.com/hc/en-us/artic…

  • user avatar

    It is a massive understatement to say we sincerely regret this situation. We take privacy extremely seriously. Avoiding situations like this are a top priority for our entire company, and we have learned valuable lessons from this situation which will make Ledger even more secure

  • user avatar

    Since July, we have done everything possible to make Ledger stronger for the future. We have hired a new Chief Information Security Officer (CISO). We are further hardening our already strong systems and have thoroughly reviewed our data policy.

    user avatar

    We executed penetration tests and forensic analysis with external security firms to test these and find any additional vulnerabilities on our e-commerce systems.

    user avatar

    We are continuously working with law enforcement to prosecute hackers and stop these scammers. We have taken down more than 170 phishing websites since the original breach.

    user avatar

    We have notified the French data protection authority regarding the data breach and are working with other data protection authorities across the world. Our Customer Support team is working 24/7 to answer your questions.

    user avatar

    We have set up a webpage sharing the anatomy of these phishing attacks so you can avoid falling for them and report any new attacks you receive:

    user avatar

    MOST IMPORTANTLY: Never share the 24 words of your recovery phrase with anyone, even if they are pretending to be a representative of Ledger. Ledger will never ask you for them. Ledger will never contact you via text messages or phone call.

  • user avatar

    You really think this kind of apology cuts it? Your bad practices will very likely lead to the physical harm of a large number of your users. This is quite possibly the worst data leak in recent times. At least every other hack was “only” user data. This is their lives at risk