A seller on an English-language cybercrime forum in the is advertising what they describe as a stolen customer database from Ledger, the French manufacturer of cryptocurrency hardware wallets. The listing, titled “HACKED LEDGER 2026 DATABASE!”, offers roughly 471,000 records for $20,000 and gives the contents as email addresses, first and last names, physical addresses and phone numbers. The seller says the data has already been processed by their team and that sample lines are available through a Telegram account.
If the dataset is real and newly exfiltrated, it is the largest exposure of Ledger customer PII since the company’s 2020 e-commerce breach, whose fallout still feeds targeted phishing against wallet owners six years later. If it is recycled data with a fresh year stamped on it, it says more about how breach forums monetize fear than about Ledger’s current security. Both readings survive the available evidence. What follows covers the listing’s forensic details, the economics behind the price tag, and what Ledger customers should do either way.
Key takeaways
- A forum listing claims a 2026 Ledger database of about 471,000 records containing emails, names, physical addresses and phone numbers, priced at $20,000.
- The advertised field schema matches an e-commerce checkout export, the same class of source implicated in Ledger’s 2020 Shopify-related breach, which leaves both recycling and new exfiltration on the table.
- No passwords, payment card data, seed phrases or wallet addresses are claimed. Crypto funds cannot be stolen remotely with this data. The danger is social engineering with very good targeting.
- The seller’s account shows zero reputation and the entry-level “Member” rank, and sample distribution happens on Telegram, which bypasses the forum’s escrow and dispute mechanisms.
- Ledger customers should treat all unsolicited contact as hostile, harden their email and mobile carrier accounts, and remember that no legitimate support channel asks for a 24-word recovery phrase.
Inside the “HACKED LEDGER 2026 DATABASE!” listing
The post is short and written in the flat, transactional style of most data-sale threads. The seller offers a stolen Ledger database from 2026, lists the fields as email, name, last name, address and phone number, and puts the volume at 471k lines. Two claims carry most of the analytical weight. The first is that the data has already been “processed by our team”, with an aside that buyers who know what they are doing can work it in “their own areas”. Processed means normalized, deduplicated and formatted for immediate abuse. The aside is an open invitation to the downstream fraud verticals that value this data most: phishing, vishing, SIM swapping and identity fraud. The second is the price. The seller frames $20,000 as payment for that processing work, and says nothing about the data being rare. Samples go out by Telegram PM, which keeps verification off the forum and inside a private channel where nobody can audit the screenshots and no moderator can arbitrate a dispute.
The account metadata matters as much as the sales pitch. The seller’s profile shows a reputation score of zero, two likes and the entry-level “Member” rank. That is a new or throwaway identity rather than an established vendor with a record of delivered goods. On breach forums, reputation does the job a legal contract does elsewhere: buyers tolerate prepayment from vetted vendors because a bad exit destroys years of accumulated trust. A zero-rep account routing samples to Telegram removes that accountability layer, and the pattern historically goes with recycled resales, partial dumps sold as complete ones, and outright exit scams. None of that proves the data is fake. New accounts occasionally front for established groups, and operational security pressure pushes even reputable actors toward disposable identities. It does mean the burden of proof sits entirely on the sample lines, and nobody has published an independent analysis of those as of this writing.
The claimed schema deserves attention from anyone assessing provenance. Email, first name, last name, postal address and phone number is the field set of an e-commerce checkout and order-export pipeline, down to the ordering, and it matches the column structure of platform exports such as Shopify’s customer and order CSVs. What the listing leaves out is equally informative: no passwords or password hashes, no payment card numbers, no seed phrases, no wallet addresses, no transaction histories. That absence defines both the risk model and the investigative path. Data shaped like this almost certainly came out of a commerce, CRM or marketing system rather than anything touching key material, which means the damage it enables lands on people rather than on cryptography.

Why would contact data alone cost $20,000?
Run the arithmetic and the price looks anomalous. Twenty thousand dollars across 471,000 records works out to roughly 4.2 cents per record. Bulk commodity PII of this type, email plus name plus phone, typically trades underground for fractions of a cent to a few cents per record, while complete “fullz” identity packages with government ID scans and selfies command tens of dollars each. By commodity standards the seller is asking an order of magnitude too much, and the reason is the target. A Ledger customer list is a confirmed roster of people who have purchased self-custody cryptocurrency hardware, which in the attacker’s mental model doubles as a pre-filtered list of probable crypto holders with above-average purchasing power. Every record carries an implicit wealth signal that a breached retail database of the same size does not.
That signal converts into expected return on fraud. Personalization is the strongest lever in phishing conversion, and a dataset pairing names with home addresses and phone numbers allows mail-merge customization across email, SMS, voice and physical post, channels where generic lures fail outright. A “Ledger support” call that recites a victim’s real name, their city and the fact that they own a hardware wallet gets past the skepticism that stops cold outreach. The same records support SIM-swap workflows, because carrier social engineering succeeds far more often when the attacker can supply a target’s full legal name, address and date-of-birth-adjacent details, and they support helpdesk impersonation against email providers and exchanges whose account-recovery flows lean on phone verification. The seller’s line about working the data in “their own areas” reads as a menu of those verticals. Priced against a single successful six-figure wallet drain or extortion case, $20,000 for half a million pre-qualified targets is a wholesale entry fee to a retail fraud economy.
2020 all over again? The provenance question
Any serious assessment of this listing has to start with Ledger’s breach history, because the 2026 claim cannot be evaluated in isolation. In July 2020, Ledger disclosed that an unauthorized party had accessed customer data through its e-commerce infrastructure. In September 2020, Shopify confirmed that two rogue members of its support team had pulled data from roughly 200 merchant stores, Ledger among them. By December 2020 the consequences were public: a substantial dump circulated on open forums, reported at the time to contain on the order of 292,000 complete customer records with names, postal addresses, phone numbers and emails, alongside a marketing list of more than one million email addresses. Have I Been Pwned subsequently indexed the incident. That data never aged out of circulation. It propagated into scam-call-center databases, phishing-kit merge fields and identity-fraud tooling, and it anchored at least one U.S. class action along with sustained GDPR scrutiny, where France’s CNIL acts as Ledger’s lead supervisory authority.
| Attribute | December 2020 dump | Alleged 2026 listing |
|---|---|---|
| Confirmed source | Shopify rogue-support-insider access to Ledger’s store | Unverified; schema suggests e-commerce/CRM-class system |
| Record volume | ~292,000 full records + ~1M+ marketing emails (as reported) | 471,000 “lines” claimed |
| Fields | Email, name, postal address, phone | Email, name, postal address, phone (identical schema) |
| Distribution | Posted publicly, then commoditized | Private sale, $20,000, samples via Telegram |
| Verification status | Confirmed by researchers, victims, and HIBP indexing | Unconfirmed; seller rep 0, no public sample analysis |
The identical schema is where the provenance argument turns, and it supports both sides. Relabeling the 2020 corpus with a fresh year is a classic resale trick, and on that reading the fields match perfectly because the data is the 2020 extract in new packaging, sold to a market with a short memory and a long fear. The volume complicates that story. 471,000 exceeds the widely reported count of complete 2020 records, so bridging the gap would require merging in enriched subsets of the email-only marketing list, padding with duplicates and fabricated rows, or genuinely holding post-2020 customer records, which could only come from a new compromise of a commerce, CRM, marketing or support platform Ledger touched after 2020. The claim that the data was processed by the seller’s team fits either hypothesis, since deduplication and normalization are what a recycler does to inflate uniqueness counts and also what a fresh exfiltrator does to make raw exports saleable.
Resolving the question is a tractable forensic exercise, and it is the work researchers and journalists should be doing before amplifying the claim. Sample lines can be tested for recency indicators: customers whose first Ledger purchase postdates 2021, email addresses created after the 2020 dump, phone numbers in numbering plans Ledger entered later, or control columns such as order IDs and timestamps, which survive “processing” more often than sellers expect. Overlap analysis against the 2020 corpus quantifies recycling directly. A sample in which every record also appears in the old dump is recycled by definition, while a sample with substantial novel content implies new exfiltration. Duplicate-rate and entropy checks expose padding, and the geographic distribution of addresses and phone country codes can be compared against Ledger’s known market footprint. Until somebody publishes that analysis, agnosticism is the honest position: an unverified listing from an unvetted seller, notable for whom it targets rather than for anything it proves.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Two other events get folded into this one by readers and should not be. The December 2023 Ledger Connect Kit incident was a supply-chain attack in which a compromised npm package drained funds from users of third-party dApps, and no customer PII database was involved at all. The 2023 Ledger Recover controversy concerned an optional seed-backup feature and was a trust and design debate rather than a breach. The threat models and the defenses are different in each case, and treating them as one long story produces the confused risk perception that sellers of scare listings rely on.
What is not at risk: seeds, keys and on-chain funds
The reassurance here is architectural. A Ledger device generates and stores private keys inside a secure element, and the 24-word recovery phrase is derived offline at setup. Neither the keys nor the seed ever traverse Ledger’s servers, its e-commerce stack, or any system this listing could plausibly represent. A database of emails, names, addresses and phone numbers cannot sign transactions, cannot derive keys and cannot drain a wallet remotely. There is no cryptographic path from this dump to anyone’s bitcoin, and any headline implying otherwise misreads how hardware wallet security works.
Social engineering is the way around that architecture. The seed stays safe only as long as the human guarding it refuses to type it into a fake Ledger Live update, read it to a “support agent”, or scan it into a counterfeit verification tool. Info-stealer campaigns distributed as Ledger Live installers have been a persistent threat for years, and their effectiveness scales with the quality of the contact data used to deliver them. A PII breach does not compromise keys; it manufactures the credibility that makes key-compromise lures land. That distinction is worth holding onto when the headlines get loud.
What attackers actually do with this data
The 2020 breach provides a documented rehearsal of what follows a Ledger PII exposure, and the playbooks observed then map one to one onto what a 2026 dataset would enable. Within months of the December 2020 dump, customers reported sharply personalized phishing emails referencing real names and purchase details, messages impersonating Ledger support with warnings about account suspension or wallet migration, and lures pointing to clone domains hosting credential harvesters or malicious “Ledger Live” installers bundled with info-stealing malware. Some victims described physical mail arriving at the breached home addresses, with printed letters and QR codes routing targets to fraudulent verification pages. That escalation was only possible because postal data was in the dump, and printed post carries an institutional trust that no email filter can intercept and no spam heuristic can downgrade. Voice phishing followed the same script, with callers reciting real addresses to establish legitimacy before requesting seed phrases or two-factor codes.
Beyond remote fraud, the address and phone fields elevate two lower-probability, higher-severity risks. SIM swapping uses the identity tuple to convince carrier support to port a victim’s number, converting control of SMS-based one-time codes into control of email password resets and exchange account recovery. And for holders whose wealth becomes inferable, doxxing-style extortion and, in extreme cases, physical coercion or “wrench attacks” become conceivable, which is why security guidance for high-value self-custody holders has long included operational security around home addresses and mail. None of these chains require breaking cryptography. They require only that a victim trust a message that knows too much about them, which is the asset this listing prices at 4.2 cents a row.
What Ledger users should do now
Prioritize by leverage rather than by effort. The non-negotiable rule comes first: never enter, speak, photograph or share your 24-word recovery phrase anywhere except on the device itself during a legitimate restore. No firmware update, support ticket, warranty claim or security verification will ever legitimately request it, and any contact that does is hostile by definition regardless of how much personal detail it recites. Second, assume from today that any email or phone number associated with a Ledger purchase is in scammer hands permanently. Treat unsolicited contact claiming to be from Ledger, your exchange, your email provider or your carrier as adversarial, and initiate any follow-up yourself through officially published channels only. Third, harden the accounts that password resets flow through. Give your primary email a unique passphrase-strength password and a hardware-key or authenticator-app second factor, and place a port freeze or SIM-swap PIN with your mobile carrier. That last control takes five minutes and neutralizes an entire attack class this dataset enables.
Holders of meaningful value have two further measures that pay for themselves many times over. Adding a BIP-39 passphrase, the optional 25th word, means the phrase alone restores only a decoy or empty wallet, so even a successful seed-phishing attempt yields nothing of value, and separate wallet accounts can be structured so that visible balances under duress remain plausible yet small. Operationally, scrutinize physical mail referencing your crypto holdings, verify sender domains character by character before clicking anything, and report phishing attempts to Ledger’s official support channels and to national reporting bodies so takedown and warning ecosystems keep pace. Finally, beware the secondary scam layer that blooms around every breach headline: services offering to check whether you are in the dump in exchange for your email or seed, and firms promising to remove your data for a fee. Only established, reputable breach-notification services such as Have I Been Pwned should receive your email address for checking, and no legitimate service can delete data from criminal infrastructure at any price.
Regulatory exposure and disclosure obligations
The legal characterization of this listing depends entirely on the provenance question. Ledger is a Paris-headquartered controller under the GDPR, so a confirmed new personal data breach triggers notification to the CNIL within 72 hours of awareness under Article 33, and communication to affected data subjects under Article 34 when the breach is likely to result in high risk. PII that enables identity fraud and targeted attacks can plausibly meet that threshold. If forensic analysis instead shows the advertised dataset to be the 2020 extract relabeled, then no new breach has occurred, no fresh notification duty arises, and the event is a market phenomenon rather than a compliance incident, however alarming the headline. That bifurcation is why responsible coverage emphasizes verification. “Ledger breached again” and “old Ledger breach resurfacing for resale” carry different obligations, and conflating them damages both public understanding and the company’s ability to respond credibly.
The broader lesson for the industry is supply-chain concentration risk. The 2020 incident originated in a commerce platform’s support workflow, an insider threat at a vendor with legitimate API access to merchant data, rather than inside Ledger’s own perimeter. Six years later, the same architecture persists across the sector. Customer PII lives in e-commerce stacks, CRMs, helpdesks and marketing automation tools, each with its own insider and API risk surface, while key custody, the security property customers actually care about, sits safely offline on the device. Controllers remain accountable for processor security under Article 28 obligations, and incidents like this alleged one are the recurring invoice for that dependency. Until commerce platforms treat merchant customer exports as crown-jewel data with per-access justification and anomaly detection, hardware wallet makers will keep discovering that the weakest component in their security model is the checkout page.
Verification status: what we know and what we do not
Transparency about evidentiary status is part of responsible reporting on breach-market claims, so we state ours plainly. Confirmed: a listing matching the description and screenshot exists on a cybercrime forum, advertising 471,000 records of Ledger customer PII at $20,000 with Telegram-based samples, posted by a zero-reputation “Member”-rank account. Unconfirmed: the authenticity, completeness, recency and novelty of the data; whether any sample lines have survived independent scrutiny; and whether Ledger has suffered any new compromise, about which the company has made no public statement tied to this listing as of publication. Our assessment methodology combined the listing’s own metadata and schema against the documented structure and history of the 2020 incident, standard breach-market trust heuristics, and known post-breach attack campaigns. We deliberately do not link to the seller, reproduce sample lines, or provide contact handles, both to avoid amplifying the sale and because republishing samples launders unverified data into apparent credibility. We will update this article if independent researchers publish overlap analysis, if samples surface publicly, or if Ledger issues a statement.
Frequently asked questions
Was Ledger hacked in 2026?
As of now, that is an unverified claim made by a low-reputation seller on a cybercrime forum. No independent analysis of sample data and no official Ledger confirmation exists yet, and the dataset may prove to be recycled material from the confirmed 2020 breach relabeled with a new year.
Are my cryptocurrency funds safe if my data is in this dump?
Yes, from remote theft. The claimed fields contain no seeds, private keys, passwords or wallet addresses, so nothing in the dataset can sign transactions or drain a wallet. The realistic risk is intensified social engineering: phishing calls, emails, letters and SIM-swap attempts designed to trick you into surrendering credentials or your recovery phrase.
Is this the same data as the 2020 Ledger breach?
Possibly, in whole or in part. The advertised schema matches the 2020 e-commerce extract exactly, but the claimed volume of 471,000 records exceeds the roughly 292,000 complete records reported in 2020, which leaves open the possibilities of merging, padding, or genuinely new post-2020 records. Overlap testing of sample lines against the 2020 corpus is the decisive check.
How can I find out whether my information is in the dump?
You cannot query an unverified criminal sale directly, and any site offering to check it in exchange for your email or seed should be treated as a scam. Use Have I Been Pwned to confirm exposure in previously verified breaches, including the 2020 Ledger incident, and watch for researcher publications analyzing sample lines if any become available.
Should I move my funds to a new wallet because of this listing?
A PII exposure alone does not require wallet migration, because contact data cannot compromise keys. If you are experiencing targeted phishing or suspect your seed was ever typed into a website or shared with anyone, then migrating to a freshly generated seed on a verified device, ideally protected by a BIP-39 passphrase, is the correct response.
Why would simple contact information be priced at $20,000?
Because the list doubles as a confirmed roster of crypto hardware owners, which makes each record a pre-qualified target for high-yield fraud such as seed phishing, SIM swapping and extortion. The price reflects the downstream value of successful attacks on wealthy crypto holders, not the commodity value of names and addresses.
Where this leaves Ledger customers
Whether this listing proves to be a genuine 2026 exfiltration or a vintage breach in fresh wrapping, the exposure it describes sits outside the device. Ledger’s secure element has not been the weak link in either the 2020 incident or this one. The contact record has, because a name, an address and a phone number are what make a fraudulent message believable. For users, the defense is behavioral and cheap: verify independently, trust no inbound contact, and let the recovery phrase live nowhere but memory and steel. For the industry, the defense is architectural and overdue: treat customer PII with the same rigor as key material. We will update this analysis as verification evidence emerges.









