Ledger.com confirmed that a subset of its customers’ personal data was exposed following a breach at its third-party payment processor, Global-e. The incident was traced to a misconfigured API key on the Ledger website, which allowed unauthorized access to a cloud-based database managed by Global-e. Exposed information included customer names, email addresses, postal addresses, and phone numbers for those who made purchases using Global-e as the Merchant of Record. Both Ledger and Global-e stated that no payment information, account credentials, or crypto wallet recovery phrases were compromised, and their core systems remain secure. The primary risk to affected customers is the potential for targeted phishing attacks using the leaked contact details.
Ledger and Global-e responded by notifying affected individuals and regulators, engaging forensic experts, and implementing containment and remediation measures. Customers were advised to be vigilant against phishing attempts and reminded never to disclose their 24-word recovery phrases. The breach did not impact Ledger’s hardware wallets or payment processing infrastructure, and no financial data was involved. Other brands using Global-e may also have been affected, but Ledger emphasized that the breach was limited to contact and order information, not sensitive crypto or payment credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Soon after the breach became public, cybercriminals began sending phishing messages impersonating Ledger and Global-e to exploit the exposed customer information. Ledger warned users that it would never ask for 24-word recovery phrases, request code scans, or send unsolicited devices.
Following the disclosure, Ledger said affected users would receive direct communication from Global-e, and reports indicated both companies notified impacted customers and relevant regulators. The notifications warned that exposed data included contact and order information.
On January 5, 2026, Ledger disclosed that some customers' personal and order data was exposed through a breach at third-party payment processor Global-e. Ledger said its own systems were not compromised and that no payment data, passwords, or wallet recovery phrases were exposed.
Global-e detected unauthorized access to a cloud-based database tied to Ledger order processing, isolated the affected systems, and brought in independent forensic experts to investigate. Reports said no malware or lateral movement was observed and no threat actor had been identified.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcego.theregister.com
Open sourcerescana.com
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.