Crypto wallet data breach compromises hundreds of thousands of users

Bitcoin
(Image credit: Shutterstock / REDPIXEL.PL)

Email addresses belonging to hundreds of thousands of users of a cryptocurrency wallet have been leaked online. It is an embarrassing development for Ledger, a hardware wallet manufacturer, who suffered a data breach back in June.

It appears that an unknown threat actor has managed to acquire email addresses of 1,075,382 individuals that subscribe to the Ledger newsletter, in addition to the names and addresses of 272,853 people that have purchased a Ledger device. Both sets of information were subsequently posted online, being shared freely on Raidforums.

At the time of the June data breach, Ledger posted that it worked quickly to patch the relevant security flaw and had notified all affected customers.

From breach to leak

We are actively monitoring for evidence of the database being sold on the internet, and have found none thus far,” Ledger explained in June. “We also performed an internal penetration testing and we are pushing forward the external penetration testing that was originally planned for September.”

Now it appears that the cyberattacker in possession of the hacked information was simply biding his or her time and has now shared the ill-gotten information online. Already, Ledger customers have begun notifying the company that they have been receiving a number of phishing emails.

In addition to digital harassment in the form of unwanted emails, Ledger customers may now find themselves at a greater physical security risk due to the nature of the Ledger wallet. As these are physical wallets, and generally owned by high-net-worth individuals, the appearance of names and addresses online represents a huge privacy invasion. The 24-word recovery phrase and optional secret passphrase used to access the Ledger wallet is now of even greater importance for individuals affected by the latest leak.

Via Bleeping Computer

Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
Dark Web monitoring
A worrying critical security flaw in Apache Tomcat could let hackers take over servers with ease
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
Latest in News
A woman sitting in a chair looking at a Windows 11 laptop
Microsoft is supercharging Windows 11’s voice commands on Copilot+ PCs with Snapdragon CPUs, and fine-tuning a few Recall features
MacBook Air M4
Apple's rumored foldable iPad tipped to launch sooner than expected with an exciting software twist
A phone displaying the Google Messages logo
Google Messages could finally be getting this WhatsApp-style group chat feature
The Future Games Show Spring Showcase
The Future Games Show returns this week for its Spring Showcase, here's how to watch and what games to expect
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content