Ledger Breach Vastly Underestimated, 270,000 Clients Data Leaked

2020-12-21 15:44

Based in France, Ledger is the largest cryptocurrency hardware wallet company. Despite the firm’s reputation, it failed to secure its database containing the personal data of those customers, according to reports.

Ledger Leak Vastly Underestimated

The company revealed a security error that gave hackers unauthorized access to a database containing the personal contact details of Ledger’s e-commerce clients. The details included email addresses, first and last names, home addresses, and phone numbers.

While Ledger first reported the breach in July 2020, the event’s actual details were only understood yesterday when hackers published the hacked data belonging to hundreds of thousands of people.

Overall, Ledger accidentally exposed phone numbers and home addresses belonging to more than 270,0000 customers.  More than a million customers’ email addresses were also leaked from the marketing database.

Today we were alerted to the dump of the contents of a Ledger customer database on Raidforum. We are still confirming, but early signs tell us that this indeed could be the contents of our e-commerce database from June, 2020.

— Ledger (@Ledger) December 20, 2020

Ledger had earlier reported that hackers had stolen the personal data of only 9,500 customers. The data was initially published on Raidforums and then spread to other websites like Intelx and many others.

Source: Alon Gal, CEO of security firm Hudson RockThird-Party API Malfunctions

Ledger found out about the data breach on Jul. 14 during a bug bounty program. Even though the company fixed the issue immediately, it was too late. 

Before the data breach, Ledger had allowed a marketing company (an unknown partner) access to its e-commerce and marketing database through an API. 

But the API was misconfigured on Ledger’s website. 

“The API key misconfiguration at issue has been running since Aug 9, 2018. Based on the information we have, we believe it was discovered and exploited from April 2020 to June 28, 2020,” Ledger reported.

The API key has now been deactivated and is no longer accessible.

Phishing Attacks, Personal Threats

Ledger said the data breach did not cause any direct threat to funds security of users. But experts worry that many customers’ safety is at risk forever.

Alon Gal, Co-Founder & CTO at security firm Hudson Rock said, “This leak holds major risk to the people affected by it. Individuals who purchased a Ledger tend to have high net worth in cryptocurrencies and will now be subject to both cyber harassments as well as physical harassments on a larger scale than experienced before.”

Since July, the breach caused a wave of phishing attempts from hackers. Ledger has also warned customers of many more phishing attempts to come.

As the leak’s breadth is becoming better known, affected clients are now reporting ransom threats via email. As Decrypt reported, an attacker has identified one client by their crypto holdings and home address.

The threat demands the victim pay them $500 or face physical violence.

Wouldn't want to be a Ledger customer right now 👇 pic.twitter.com/wZoH3OwTLL

— Riku Raisanen (@rikuraisanen) December 21, 2020

origin »

Bitcoin price in Telegram @btc_price_every_hour

Streamr DATAcoin (DATA) на Currencies.ru

$ 0.0009632 (-0.24%)
Объем 24H $108.948k
Изменеия 24h: 2.57 %, 7d: -2.44 %
Cегодня L: $0.0009288 - H: $0.0009905
Капитализация $1.217m Rank 1853
Цена в час новости $ 0.0360283 (-97.33%)

clients data leaked 270 breach vastly underestimated

clients data → Результатов: 116


Coincheck Crypto Exchange Clients’ Data Compromised After Hacker Breached Its Domain

Japan-based cryptocurrency exchange, Coincheck, announced yet another hack – this time about 200 customers data was compromised after a domain account error. According to an official statement from the corporate desk of Coincheck, a third party was able to gain unauthorized access to one of the exchange’s domains from May 31st to June 1st. Coincheck’s […]

2020-6-3 18:35


Centotrenta launches credit securitization management platform based on IBM Blockchain technology

IBM and Centotrenta Servicing, today announced the HyperMast STS platform, an end to end credit securitization management platform based on IBM Blockchain technology designed to address financial sector requirements for their clients including data quality, process security, flow traceability, and the reduction of processing time and paper-based processes.

2020-2-20 18:45


Фото:

Anchorage Acquires Merkle Data, Launches Institutional-Grade Bitcoin Trading Platform 

Anchorage, a digital assets custodial service provider for institutional investors, has announced the acquisition of Merkle Data, and the launch of Anchorage Trading, a crypto brokerage platform that will allow its clients to buy and sell bitcoin (BTC) and altcoins straight from Anchorage’s vaults through expert traders, without needing to transfer the assets to anRead MoreRead More.

2020-1-17 02:00


Digital Asset Security Firm Fireblock Backed By Fidelity Gets EY’s SOC 2 Type II Accreditation

Fidelity Digital Assets (FDAS) thinks that in the future, custodians will work from behind the scenes to store cryptocurrencies for clients from different firms. At the same time, its enterprise-based platform for crypto transactions, Fireblocks, has just passed an EY audit that confirms it complies with data security standards, which has led to talks with […]

2019-12-20 21:21


Sidechains vs Plasma vs Sharding

Special thanks to Jinglan Wang for review and feedback One question that often comes up is: how exactly is sharding different from sidechains or Plasma? All three architectures seem to involve a hub-and-spoke architecture with a central “main chain” that serves as the consensus backbone of the system, and a set of “child” chains containing actual user-level transactions.

2019-6-14 04:03


Фото:

Out of Testnet and Into Alpha: Lightning Labs’ Desktop Application Is Live

Lightning Labs just released an alpha version of its Lightning Network wallet. The desktop application is now compatible with Bitcoin’s mainnet and it leverages Neutrino (the protocol, not the analytics company acquired by Coinbase) to give users a lightweight option to “control their own funds,” as opposed to running a full node or trusting a third party to play custodian.

2019-4-24 01:38


Coinbase Executive Leaves the Firm and Goes to Fidelity Amid Customer Data Drama

Coinbase, one of the most important crypto-related platforms in the market, lost another executive. This time, Christine Sandler, the Director of Institutional Sales, will be leaving the firm. Coinbase has been criticized by enthusiasts in the crypto market after reports emerged about the firm selling clients’ data to other companies. Christine Sandler Leaves Coinbase Sandler […]

2019-4-1 13:55


Фото:

Intercontinental Exchange Adding Long List of Cryptocurrencies to Dedicated Data Feed

Intercontinental Exchange Data Services (ICE Data Services) recently tweeted out a lengthy list of cryptocurrencies to be included in its Cryptocurrency Data Feed. ICE Data Services provides pricing, analytics, indices, and exchange data in a custom-tailored fashion for clients seeking more insight and information on financial markets.

2019-3-19 06:00


Фото:

As Court Reconvenes for QuadrigaCX, Questions Surround Empty Cold Wallets

As QuadrigaCX’s legal counsel descends on the courtroom in Halifax, Nova Scotia, for another round of legal proceedings, the court monitor’s third report on QuadrigaCX’s finances — specifically its revelation that the exchange’s cold wallets are empty — lays out some hopeful avenues for fund recovery — and some frustrating dead ends.

2019-3-5 20:20