Ledger Breach Vastly Underestimated, 270,000 Clients Data Leaked

2020-12-21 15:44

Based in France, Ledger is the largest cryptocurrency hardware wallet company. Despite the firm’s reputation, it failed to secure its database containing the personal data of those customers, according to reports.

Ledger Leak Vastly Underestimated

The company revealed a security error that gave hackers unauthorized access to a database containing the personal contact details of Ledger’s e-commerce clients. The details included email addresses, first and last names, home addresses, and phone numbers.

While Ledger first reported the breach in July 2020, the event’s actual details were only understood yesterday when hackers published the hacked data belonging to hundreds of thousands of people.

Overall, Ledger accidentally exposed phone numbers and home addresses belonging to more than 270,0000 customers.  More than a million customers’ email addresses were also leaked from the marketing database.

Today we were alerted to the dump of the contents of a Ledger customer database on Raidforum. We are still confirming, but early signs tell us that this indeed could be the contents of our e-commerce database from June, 2020.

— Ledger (@Ledger) December 20, 2020

Ledger had earlier reported that hackers had stolen the personal data of only 9,500 customers. The data was initially published on Raidforums and then spread to other websites like Intelx and many others.

Source: Alon Gal, CEO of security firm Hudson RockThird-Party API Malfunctions

Ledger found out about the data breach on Jul. 14 during a bug bounty program. Even though the company fixed the issue immediately, it was too late. 

Before the data breach, Ledger had allowed a marketing company (an unknown partner) access to its e-commerce and marketing database through an API. 

But the API was misconfigured on Ledger’s website. 

“The API key misconfiguration at issue has been running since Aug 9, 2018. Based on the information we have, we believe it was discovered and exploited from April 2020 to June 28, 2020,” Ledger reported.

The API key has now been deactivated and is no longer accessible.

Phishing Attacks, Personal Threats

Ledger said the data breach did not cause any direct threat to funds security of users. But experts worry that many customers’ safety is at risk forever.

Alon Gal, Co-Founder & CTO at security firm Hudson Rock said, “This leak holds major risk to the people affected by it. Individuals who purchased a Ledger tend to have high net worth in cryptocurrencies and will now be subject to both cyber harassments as well as physical harassments on a larger scale than experienced before.”

Since July, the breach caused a wave of phishing attempts from hackers. Ledger has also warned customers of many more phishing attempts to come.

As the leak’s breadth is becoming better known, affected clients are now reporting ransom threats via email. As Decrypt reported, an attacker has identified one client by their crypto holdings and home address.

The threat demands the victim pay them $500 or face physical violence.

Wouldn't want to be a Ledger customer right now 👇 pic.twitter.com/wZoH3OwTLL

— Riku Raisanen (@rikuraisanen) December 21, 2020

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Streamr DATAcoin (DATA) на Currencies.ru

$ 0.0531465 (-0.87%)
Объем 24H $1.272m
Изменеия 24h: -2.25 %, 7d: 1.21 %
Cегодня L: $0.0519453 - H: $0.0536524
Капитализация $54.922m Rank 577
Цена в час новости $ 0.0360283 (47.51%)

clients data leaked 270 breach vastly underestimated

clients data → Результатов: 116


Coincheck Crypto Exchange Clients’ Data Compromised After Hacker Breached Its Domain

Japan-based cryptocurrency exchange, Coincheck, announced yet another hack – this time about 200 customers data was compromised after a domain account error. According to an official statement from the corporate desk of Coincheck, a third party was able to gain unauthorized access to one of the exchange’s domains from May 31st to June 1st. Coincheck’s […]

2020-6-3 18:35


Centotrenta launches credit securitization management platform based on IBM Blockchain technology

IBM and Centotrenta Servicing, today announced the HyperMast STS platform, an end to end credit securitization management platform based on IBM Blockchain technology designed to address financial sector requirements for their clients including data quality, process security, flow traceability, and the reduction of processing time and paper-based processes.

2020-2-20 18:45


Фото:

Anchorage Acquires Merkle Data, Launches Institutional-Grade Bitcoin Trading Platform 

Anchorage, a digital assets custodial service provider for institutional investors, has announced the acquisition of Merkle Data, and the launch of Anchorage Trading, a crypto brokerage platform that will allow its clients to buy and sell bitcoin (BTC) and altcoins straight from Anchorage’s vaults through expert traders, without needing to transfer the assets to anRead MoreRead More.

2020-1-17 02:00


Digital Asset Security Firm Fireblock Backed By Fidelity Gets EY’s SOC 2 Type II Accreditation

Fidelity Digital Assets (FDAS) thinks that in the future, custodians will work from behind the scenes to store cryptocurrencies for clients from different firms. At the same time, its enterprise-based platform for crypto transactions, Fireblocks, has just passed an EY audit that confirms it complies with data security standards, which has led to talks with […]

2019-12-20 21:21


Why Millennials Suck at Buying Stocks

Every month, TD Ameritrade puts out a proprietary behavior-based index based on the stock trading behavior of its clients, called the Investor Movement Index, or IMX. There are some critical pieces of data to come out of the IMX, the most important of which is that Millennials apparently have no idea how to buy stocks […] The post Why Millennials Suck at Buying Stocks appeared first on CCN.com

2019-9-15 19:30


Sidechains vs Plasma vs Sharding

Special thanks to Jinglan Wang for review and feedback One question that often comes up is: how exactly is sharding different from sidechains or Plasma? All three architectures seem to involve a hub-and-spoke architecture with a central “main chain” that serves as the consensus backbone of the system, and a set of “child” chains containing actual user-level transactions.

2019-6-14 04:03