CryptoReal
CASE FILE — Dec 21, 2020

Ledger Data Breach: Full Customer Database Leaked for Free

Ledger's standing with its own customer base took a fresh hit this week. Records stolen from the company months earlier, previously accessible only to buyers who could pay for them, are now available to anyone at no cost, and that shift has already started producing real-world consequences for the people named in the files.

The barrier came down on the night of December 20, 2020, when a database file covering 272,853 customer accounts and 1,075,382 email subscribers turned up on raidforums. Rather than welcoming wider access, a number of forum members objected, annoyed that a free release had wiped out whatever resale value the dataset still carried.

The underlying breach traces back to July 2020. Someone testing Ledger's bug bounty program flagged a security gap in the platform, only to find that the same gap had already been used by an outside party. Ledger later confirmed the intrusion, stating that an "unauthorized third party had gained access to a portion of our e-commerce and marketing database through an API Key."

Prior to this week, copies of the stolen records reportedly sold for figures approaching six digits — a price that says a great deal about how much this kind of personal data is worth to someone hoping to profit from it. Now that no payment is required, affected users have begun flagging a noticeable uptick in phishing contact attempts. That trend is expected to keep building over the coming months, and given how much personal detail has been exposed, a physical incident linked to the leak would not be surprising.

Framed generously, Ledger has handed SIM-swap operators and phishing crews a ready-made contact list. Framed less generously, the leaked home addresses and phone numbers create a real risk of burglary or direct physical harm to the individuals involved.

Ledger's original disclosure, published as a support FAQ, described roughly 9,500 customers as affected, with exposed data limited to full names, mailing addresses, and phone numbers. That estimate has since been dwarfed by reality: the true number sits closer to 227,000. The size of that gap invites an obvious question — did Ledger understate how serious the incident really was?

Asked for comment, a representative from Ledger provided the following statement:

We're still investigating this ongoing issue, but the dumped content may be Ledger's e-commerce database that was exposed during the data breach in June 2020. This database may be used by scammers for phishing attacks through emailing and text message campaigns.

Our Customer Support team has been working to notify our users via Twitter and responding to questions while also reporting all tweets and Reddit posts that contain a link to the database. We urge all of our users to never share their 24-word phrase, and remember that no one from our team will ever request that private information.

Since we discovered the data breach in June 2020, we worked with an external security organization to conduct a forensic review. The review confirmed that only 9,500 individuals were impacted, all of whom were personally contacted by Ledger Support. Since the phishing attacks started to occur, we anticipated more information could have leaked and continued to notify all users via Twitter and email.

We are doing everything in our power to cease these attacks and avoid situations like this in the future. Ledger has a set of measures in place to protect our users from falling victims to phishing attacks. We have set up a webpage sharing the anatomy of phishing attacks so users can avoid falling for them and report any new attacks: https://www.ledger.com/phishing-campaigns-status

We sincerely regret this situation, and our team is working diligently to stop the scammers and restore faith within the community. We have been open and transparent about this issue from the onset and will continue to respond to any new developments as the information becomes available. We are continuing analysis of this data and will continue to provide updates.


The regulatory dimension of this case is arguably the most damning part. Several affected customers say they had already asked Ledger, in writing, to delete their personal information under GDPR — requests that were either ignored or answered with assurances that were never acted on.

One customer described their experience to us this way:

I sent them an email in May 2020 and asked them to delete any data they have about me from multiple orders. I referenced GDPR in the message. They replied: "Thank you for contacting us. It will be done as soon as possible."

With the leaks I cross checked and realized that I am in the big data dump (email, address, phone...)

Under a proper GDPR-compliant process, this sort of personal information should have been purged automatically once a defined retention period expired. Whether Ledger's failure to act on these deletion requests reflects incompetence or something more deliberate is now beside the point — nothing about that changes what has already happened.

More broadly, the incident is a reminder of what it costs to depend on centralized third parties for data custody. As decentralized alternatives mature, the weaknesses of the older, custodial model become harder to excuse, and compliance obligations carried over from traditional business do little to protect the underlying database. Users are effectively required to hand their information to companies like this despite knowing the risks of centralized storage, and firms such as Ledger remain caught between the old model and the new — reluctant, or unable, to adopt privacy tools like zk-proofs that could otherwise secure their systems.

Criminal actors will not be the only ones drawn to this kind of leak, either. There is precedent for governments doing the same: European tax authorities previously paid for stolen Swiss banking records specifically to pursue tax-evasion cases.

There is no undoing a data breach once it happens. Prevention, not remediation, is the only real defense.

gdprledger
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.