{"id":15193,"date":"2026-01-05T09:44:52","date_gmt":"2026-01-05T16:44:52","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=15193"},"modified":"2026-01-05T09:44:52","modified_gmt":"2026-01-05T16:44:52","slug":"ledger-customers-impacted-by-third-party-global-e-data-breach","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/01\/05\/ledger-customers-impacted-by-third-party-global-e-data-breach\/","title":{"rendered":"Ledger Customers Impacted by Third-Party Global-E Data Breach"},"content":{"rendered":"\n<p>If you bought from Ledger directly, yet another data breach. Consequently, I wouldn&#8217;t trust their hardware wallets because they&#8217;re not completely opensource, and they have a poor history of protecting data. And it was interesting that instead of tightening up their own products, they had funded a security team looking for vulnerabilities in other hardware wallets, to cast shade on competitors it would seem. Though, users benefited as a lot of hardware wallets improved their security as a result, with many better platforms than Ledger to choose from. <\/p>\n\n\n\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ledger-customers-impacted-by-third-party-global-e-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.bleepingcomputer.com\/news\/security\/ledger-customers-impacted-by-third-party-global-e-data-breach\/<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_332be914-4514-4450-9e9b-dfbe3b433aeb\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<p>By Bill Toulas<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2023\/12\/21\/Ledger.jpg\" alt=\"Ledger customers impacted by third-party Global-e data breach\"\/><\/figure>\n\n\n\n<p>Ledger is informing some customers that their personal data has been exposed after hackers breached the systems of third-party payment processor&nbsp;Global-e.<\/p>\n\n\n\n<p>In a statement for BleepingComputer, the&nbsp;blockchain company underlines that its network&nbsp;has&nbsp;not been impacted and that the platform&#8217;s hardware and software systems remain secure.<\/p>\n\n\n\n<p>&#8220;Some of the data accessed as part of this incident pertained to customers who purchased on Ledger.com using Global-e as a Merchant of Record,&#8221; the company told BleepingComputer.<\/p>\n\n\n\n<p>Out of an abundance of caution, Ledger, the maker of the namesake self-custodial hardware wallets, is warning its customers that the third-party data breach exposed their names and contact information.<\/p>\n\n\n\n<p>On-chain investigator ZachXBT published a community alert with the notification from Ledger:<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><a href=\"https:\/\/x.com\/zachxbt\/status\/2008139053544194545\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/December\/tweet(3).png\" alt=\"Tweet\"\/><\/a><\/figure>\n\n\n\n<p>The Global-e platform handles checkout, order processing, localization, taxes, duties, and compliance for multiple online retailers and brands. Among its customers are Bang&amp;Olufsen, adidas, Disney, Givenchy, Hugo Boss, Ralph Lauren, Michael Kors, Netflix, and M&amp;S.<\/p>\n\n\n\n<p>These services require storing customer order data, though Ledger specified that the exposed details do not include financial information.<\/p>\n\n\n\n<p>According to Ledger, the hackers had access to order data present on Global-e&#8217;s systems. However, neither Global-e nor Ledger had access to customers&#8217; 24-word seed phrases for accessing the crypto wallet, the&nbsp;blockchain balance, or any secrets related to digital assets.<\/p>\n\n\n\n<p>&#8220;Importantly, no payment information was involved,&#8221;&nbsp;the company said, noting that attackers may try to target customers in&nbsp;phishing campaigns designed to steal their passphrases.<\/p>\n\n\n\n<p>\u201cWe encourage everyone to be alert to any potential phishing campaigns, never disclose their 24 words, and always Clear Sign transactions where possible.\u201d &#8211; Ledger<\/p>\n\n\n\n<p>It was also specified that Ledger was not the only brand whose customer data was affected, and that the unauthorized party gained access to a Global-e cloud-based information system containing shopper order data from several brands.<\/p>\n\n\n\n<p>BleepingComputer&nbsp;reached out to Global-e to learn more about the incident and the affected brands, but we have not received a response by publication time.<\/p>\n\n\n\n<p>Ledger says that affected users will receive direct communication from Global-e about the incident and its impact. They are recommended to contact Global-e for more details.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you bought from Ledger directly, yet another data breach. Consequently, I wouldn&#8217;t trust their hardware wallets because they&#8217;re not completely opensource, and they have a poor history of protecting data. And it was interesting that instead of tightening up their own products, they had funded a security team looking for vulnerabilities in other hardware [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-15193","post","type-post","status-publish","format-standard","hentry","category-tech"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/15193","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=15193"}],"version-history":[{"count":1,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/15193\/revisions"}],"predecessor-version":[{"id":15194,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/15193\/revisions\/15194"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=15193"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=15193"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=15193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}