Ledger reassures users after third-party data breach

Ledger has confirmed its hardware wallets and user funds remain secure after a data breach at its third-party e-commerce partner, Global-e. The company revealed the incident on January 5, stating that unauthorized access occurred in Global-e’s cloud systems, which process orders for purchases through Ledger.com. The two companies began collaborating in October 2023.
The breach did not affect Ledger’s platforms, devices, or cryptocurrency holdings. According to the company, the exposed data included basic customer information, such as names and contact details, from those who bought Ledger products via Global-e. Other brands using Global-e’s services also had order data compromised.
Ledger stressed that Global-e did not store sensitive personal data, including birth dates, government identification, or financial information like credit card numbers. The company also confirmed that account passwords, wallet secrets, or 24-word recovery phrases were not exposed. Since Ledger wallets operate on a self-custody model, users maintain full control over their private keys and assets.
Global-e discovered the breach after detecting unusual activity in its cloud infrastructure. The company contained the incident, engaged forensic specialists, and confirmed only a limited dataset was leaked. Ledger reiterated that its hardware and software were not directly compromised, reaffirming that its security approach, where users hold their own keys, remains effective.
Read Also: Cyprus university tops regional research rankings
This incident comes after several major data breaches in the cryptocurrency sector, including attacks on Coinbase and Binance, where exposed consumer data has fueled phishing schemes. While Ledger’s wallets were not directly impacted, the breach highlights the risks third-party vulnerabilities create within the broader industry.
Ledger’s official statement reinforced that self-custody provides the strongest protection against direct fund theft. The company warned users to stay alert for scams exploiting exposed personal information.
Global-e has since restored its systems, and Ledger has reported no further service interruptions.