Ledger disclosed that customer information was exposed after an incident involving Global-e, a third-party e-commerce partner used for order processing. Reporting from The Register and CoinDesk said the breach affected Ledger customer order data rather than wallet seed phrases or private keys, but still exposed personally identifiable information tied to purchases, raising renewed phishing, social-engineering, and physical-security concerns for hardware wallet owners.
Ledger later published support advisories and an FAQ describing the Global-e incident and the resulting e-commerce and marketing data breach, including guidance on recognizing legitimate Ledger email addresses and avoiding scams. The company linked the event to order-data exposure and framed it separately from the firm’s widely known 2020 e-commerce data breach, while warning customers to remain alert for fraudulent messages that misuse leaked contact or purchase details.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Ledger published an FAQ covering the e-commerce and marketing data breach, providing customers with additional guidance and answers about the incident. The FAQ appears to consolidate response information and support resources.
Ledger released a dedicated support article about the January 2026 Global-e incident affecting order data, documenting the incident for customers. The notice served as an official reference page for the breach and its scope.
Ledger published a support article listing legitimate Ledger email addresses to help customers distinguish authentic communications from phishing attempts following the breach-related concerns. This was part of its customer guidance and response materials.
Ledger confirmed that customer data had been accessed or lifted as part of the Global-e-related incident, providing public acknowledgment of the breach. Media coverage on January 6 reported Ledger's confirmation and the involvement of the third-party e-commerce provider.
In early January 2026, Ledger disclosed that a security incident involving its e-commerce partner Global-e led to unauthorized access to some Ledger customer order data. Reporting described the exposure as a new customer data breach affecting Ledger through the third-party partner.
Ledger said it suffered an e-commerce and marketing database breach in July 2020 that exposed customer contact and order-related information. The company published a leadership statement addressing the incident and its impact on affected users.
6 references tracked. Mallory keeps watching after this page renders.
support.ledger.com
Open sourcesupport.ledger.com
Open sourcesupport.ledger.com
Open sourcetheregister.com
Open sourcecoindesk.com
Open sourceledger.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.