Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Ledger

Ledger Vendor Cyber Rating & Cyber Score

ledger.com

At Ledger, we’re proud to be the global platform for digital assets and Web3, with over 20% of the world’s crypto assets secured through our Ledger devices. With our headquarters in Paris, and offices in Vierzon, Grenoble, Montpellier, London, Portland, Geneva, Zurich and Central Singapore, we have a team of around 600 professionals developing a variety of products and services to enable individuals and companies to securely buy, store, swap, grow and manage crypto assets – including the Ledger hardware wallets line with more than 7.5 millions units already sold in 200 countries. We’re a team of experts pushing the limits of what’s possible, united by our common goal to unlock true freedom through digital ownership, making technology


Ledger A.I CyberSecurity Scoring

Ledger
Company Information
Website:https://www.ledger.com
Employees number:824
Number of followers:91,625
NAICS:541514
Industry Type:Computer and Network Security
Homepage:ledger.com
Ledger Risk Score (AI oriented)
Between 0 and 549
logo
LedgerComputer and Network Security
Updated:
03/09/2026
101/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Ledger Global Score (TPRM)
xxxx
logo
LedgerComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

LedgerCritical
Current Score
101C (CRITICAL)
01000
14 incidents
-44.75 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
113Before Incident
SEPTEMBER 2026
100Before Incident
AUGUST 2026
288Before Incident
Breach
27 Aug 2026 • Ledger
Ledger: Ledger sued for $500M over its many data breaches

Ledger Faces $500M Lawsuit Over Repeated Data Breaches and Crypto Theft

100After Incident
CRITICAL-188
LED1788458082
Ledger Faces $500M Lawsuit Over Repeated Data Breaches and Crypto Theft Crypto wallet manufacturer Ledger is at the center of a $500 million class action lawsuit filed on August 27, alleging systemic negligence in protecting customer data. The plaintiff, Douglas Kim, claims to have lost nearly $2 million after attackers exploited stolen personal information from Ledger’s 2020 and 2023 breaches to target his crypto assets. The lawsuit outlines a pattern of security failures, including a 2020 breach that exposed the personal data of nearly 300,000 users, later sold on dark web marketplaces. In 2023, a phishing attack on a Ledger employee led to malware distribution, enabling attackers to redirect funds from users’ wallets. A separate 2026 breach unrelated to the lawsuit involved a hack of payments processor Global-e, further compromising Ledger users’ data. The complaint accuses Ledger of downplaying the breaches, delaying customer notifications, and failing to strengthen security measures. It alleges that these lapses allowed criminals to exploit leaked data, resulting in preventable financial losses. The lawsuit also cites violations of New York’s Stop Hacks and Improve Electronic Data Security Act and seeks damages ranging from $500 million to potentially billions, along with a jury trial. Ledger has declined to comment on the ongoing legal matter.
INCIDENT DETAILS -
TYPE
Data BreachPhishing AttackMalware Distribution
MOTIVATION
Financial GainData Exfiltration
IMPACT
Financial Loss: $500M (lawsuit claim)Data Compromised: Personal data of nearly 300,000 users (2020), crypto wallet funds (2023)Ledger’s customer databaseUser crypto walletsOperational Impact: Delayed customer notifications, failure to strengthen security measuresBrand Reputation Impact: Accusations of negligence and downplaying breachesLegal Liabilities: Violations of New York’s *Stop Hacks and Improve Electronic Data Security Act*Identity Theft Risk: High (personal data sold on dark web)Payment Information Risk: High (crypto wallet funds redirected)
DATA BREACH
Personal DataCrypto Wallet InformationNumber Of Records Exposed: Nearly 300,000 (2020 breach)Sensitivity Of Data: High (personally identifiable information, crypto assets)Data Exfiltration: Yes (sold on dark web)Personally Identifiable Information: Yes
AUGUST 2026
299Before Incident
Cyber Attack
01 Aug 2026 • Ledger
Ledger: MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets

MacSync Malware Campaign Targets macOS Users via Fake Claude AI Guides

279After Incident
CRITICAL-20
LED1785572706
MacSync Malware Campaign Targets macOS Users via Fake Claude AI Guides A newly uncovered macOS malware campaign, dubbed MacSync, exploits fake Claude AI installation guides to deploy a sophisticated six-stage stealer and remote access trojan (RAT). Discovered by Huntress, the attack targets browser credentials, keychain secrets, cryptocurrency wallets, and other sensitive data. The campaign begins when victims search for "how to install Claude on a Mac" and click a malicious Google-sponsored ad, redirecting them to a weaponized claude.ai/share page disguised with a fake "Shared by Apple Support" badge. The page instructs users to execute a Base64-obfuscated curl command in Terminal, which fetches a loader from domains like agenticsora[.]com or malwareaudit[.]com while bypassing certificate validation. The malware unfolds in six stages, starting with a polymorphic zsh loader that establishes persistence via a background daemon. Subsequent stages include an AppleScript that tricks users into granting Full Disk Access, harvests credentials, and installs a Mach-O RAT written in C++ with OpenSSL. The RAT persists through a LaunchAgent mimicking legitimate updaters (e.g., Google Keystone, Adobe ARM) and deploys a helper app named "Screen Recording" to gain screen-capture permissions. The final stage trojanizes hardware-wallet companion apps including Ledger Live, Ledger Wallet, and Trezor Suite to phish seed phrases. Huntress reports the stealer targets 60+ wallet browser extensions, 21 desktop wallet apps, and three trojanized hardware wallet tools, indicating cryptocurrency theft as the primary objective. Infrastructure spans Cloudflare-fronted delivery domains, an operator panel at 103.216.221[.]95, and a raw-IP TLS channel (85.206.161[.]241:8443) for RAT control. Stolen data is exfiltrated to domains like sdhomeinspectors[.]com and southcarolinacounselor[.]com. Russian-language comments in the source code and collection techniques suggest ties to the AMOS/Atomic Stealer lineage, though researchers note this as a family resemblance rather than confirmed shared authorship. Detection relies on behavioral indicators, including curl commands piped into zsh, osascript bridges executing stealer logic, and unexpected Full Disk Access or Screen Recording grants tied to newly signed apps. Persistence artifacts include paths like ~/.local/com.apple.<8hex>.hcpi and mutex files at /tmp/macsync_<token>.lock.
INCIDENT DETAILS -
TYPE
Malware Campaign
MOTIVATION
Cryptocurrency theft, data exfiltration
IMPACT
Data Compromised: Browser credentials, keychain secrets, cryptocurrency wallets, seed phrases, sensitive dataSystems Affected: macOS systemsIdentity Theft Risk: HighPayment Information Risk: High (cryptocurrency wallets)
DATA BREACH
Browser credentialsKeychain secretsCryptocurrency walletsSeed phrasesPersonally identifiable informationSensitivity Of Data: High
JULY 2026
290Before Incident
JUNE 2026
299Before Incident
Cyber Attack
01 Jun 2026 • Ledger
Electrum, Exodus, Ledger and Trezor: Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft

New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain

279After Incident
CRITICAL-20
ELEEXOLEDTRE1784199019
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain Security researchers at SlowMist have uncovered a sophisticated macOS-focused infostealer designed to harvest credentials, wallet databases, and session data for offline cryptocurrency theft. Detected by the MistEye monitoring system, the malware casts a wide net, extracting sensitive information from Apple Keychain, Safari and Chromium browsers, Telegram Desktop, Apple Notes, and multiple wallet applications including Electrum, Exodus, Atomic, Wasabi, Monero, Bitcoin Core, Ledger Live, and Trezor Suite. The malware’s primary threat lies in its ability to pair stolen wallet databases with potential unlocking material, such as passwords from Keychain or browser stores. While most wallet apps encrypt data locally, attackers can test harvested credentials against exfiltrated wallet files in an isolated environment, bypassing the limitations of online password-guessing attacks. SlowMist demonstrated this by successfully decrypting Atomic Wallet data using a password obtained from the victim’s Keychain. Once a wallet’s recovery phrase or private key is extracted, simply reinstalling the app or changing its password offers no protection. The malware also employs social engineering tactics, including a fake "Google API Connector" update prompt to capture the victim’s macOS password. It validates credentials using the `dscl` authentication utility, ensuring attackers obtain the correct login details. Additionally, it targets Chrome Safe Storage secrets from Keychain, which can decrypt stored browser logins and cookies. Telegram users face a separate risk: the stealer copies the `tdata` directory, containing encryption keys and session state. In lab tests, restoring these files on a compatible Mac immediately granted access to the victim’s account without requiring SMS codes or two-factor authentication effectively hijacking an active session. Stolen `tdata` artifacts could also be converted into programmable Telegram API sessions, enabling full chat access. For Ledger Live and Trezor Suite users, the malware deploys phishing pages disguised as legitimate wallet applications. After removing the real software, it installs lookalike WebView loaders that connect to attacker-controlled sites, tricking victims into entering recovery phrases or PINs under the guise of trusted desktop apps. The campaign highlights how infostealers exploit the interplay between credentials, encrypted local stores, and user trust. While a stolen wallet database alone may be secure, pairing it with Keychain secrets and reused passwords creates a portable target for offline decryption. Indicators of compromise (IOCs) include malicious domains and IP addresses linked to the phishing infrastructure.
INCIDENT DETAILS -
TYPE
Infostealer Malware
MOTIVATION
Financial Gain
IMPACT
CredentialsWallet DatabasesSession DataEncryption KeysRecovery PhrasesPrivate KeysBrowser LoginsCookiesmacOSIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
CredentialsWallet DatabasesSession DataEncryption KeysRecovery PhrasesPrivate KeysBrowser LoginsCookiesSensitivity Of Data: HighLocal Wallet EncryptionChrome Safe StorageWallet DatabasesKeychain DataBrowser DataTelegram `tdata` DirectoryApple NotesRecovery PhrasesPrivate KeysBrowser LoginsCookies
MAY 2026
292Before Incident
APRIL 2026
294Before Incident
Vulnerability
17 Apr 2026 • Ledger
Espressif Systems and Ledger: Fake Ledger Hardware Wallets on Chinese Marketplaces Steal Crypto Seeds and PINs

Sophisticated Supply Chain Attack Targets Crypto Users with Counterfeit Ledger Wallets

285After Incident
LOW-9
ESPLED1776435883
Sophisticated Supply Chain Attack Targets Crypto Users with Counterfeit Ledger Wallets A Brazilian cybersecurity researcher uncovered a large-scale supply chain scam involving counterfeit Ledger Nano S Plus hardware wallets sold on a Chinese marketplace. The fake devices, designed to drain cryptocurrency across 20 blockchains, were engineered with tampered hardware, trojanized software, and cross-platform malware creating a seamless phishing pipeline. The researcher, u/Past_Computer2901, purchased the device at the same price as the official Ledger store, with packaging that appeared authentic. Suspicion arose only after the device failed Ledger’s Genuine Check when connected to a legitimate Ledger Live installation. A physical teardown revealed the original secure element chip had been replaced with an ESP32-S3 microcontroller, a generic IoT component from Espressif Systems, with its markings scraped off to avoid detection. The counterfeit device also included a WiFi/Bluetooth antenna, absent in genuine Ledger wallets. Firmware analysis exposed the full extent of the compromise: every PIN entry and seed phrase was stored in plaintext and transmitted to attacker-controlled command-and-control (C2) servers, including the domain kkkhhhnnn[.]com. The fake firmware, labeled "Nano S+ V2.1" a version that doesn’t exist in Ledger’s official releases was designed to impersonate a legitimate update. The scam extended beyond the hardware. The counterfeit device shipped with a QR code directing users to a cloned phishing site, where they downloaded a trojanized Ledger Live app. The fake app bypassed security warnings with a hardcoded "Genuine Check" that always returned a success screen, ensuring victims remained unaware of the breach. The malware also exfiltrated wallet data upon use and was distributed across Android, Windows, macOS, and iOS, with the iOS variant spread via Apple’s TestFlight to evade App Store reviews. Infrastructure analysis linked the operation to a Shanghai-based shell company, with three C2 servers, a cloned website, and a QR code redirect chain. While Ledger’s official Genuine Check can detect the counterfeit device, the scam’s success relied on victims never using the legitimate Ledger Live app. The researcher submitted a full technical report to Ledger’s security team, with further analysis pending. The attack has already resulted in confirmed financial losses exceeding $9.5 million across more than 50 victims, marking one of the most advanced hardware wallet supply chain attacks documented to date.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Financial Gain
IMPACT
Financial Loss: $9.5 millionPIN entriesSeed phrasesWallet dataLedger Nano S Plus (counterfeit)Ledger Live (trojanized)Cross-platform malware (Android, Windows, macOS, iOS)Operational Impact: Cryptocurrency theft across 20 blockchainsBrand Reputation Impact: Severe (counterfeit devices, phishing pipeline)Identity Theft Risk: High (PII and wallet data exfiltration)Payment Information Risk: High (cryptocurrency theft)
DATA BREACH
PIN entriesSeed phrasesWallet dataPersonally Identifiable Information (PII)Sensitivity Of Data: High (cryptocurrency wallet credentials)Data Exfiltration: Yes (to attacker-controlled C2 servers)Data Encryption: No (stored in plaintext)Personally Identifiable Information: Yes (wallet data, seed phrases)
MARCH 2026
286Before Incident
FEBRUARY 2026
289Before Incident
Cyber Attack
01 Feb 2026 • Ledger
OpenClaw, Coinbase, MetaMask, 1Password and Ledger Live: Hackers Use Fake OpenClaw Installer to Steal Crypto Wallet and Password Manager Credentials

Hologram Infostealer Campaign Targets Crypto Wallets and Password Managers via Fake OpenClaw Installer

270After Incident
CRITICAL-19
METLED1PACOIOPE1778262200
New "Hologram" Infostealer Campaign Targets Crypto Wallets and Password Managers via Fake OpenClaw Installer A sophisticated infostealer campaign, dubbed "Hologram," has been active since at least February 2026, targeting sensitive data stored in 250+ browser extensions tied to crypto wallets and password managers. The malware spreads via a fake installer for OpenClaw, a legitimate open-source AI assistant, hosted on a convincing typosquat domain (openclaw-installer[.]com), registered on March 9, 2026. ### How the Attack Works 1. Initial Infection - Victims download OpenClaw_x64[.]7z, a 130MB Rust-based executable padded with fake documentation to evade antivirus scans and bypass sandbox upload limits. - The dropper, named "Hologram" in its manifest, performs anti-analysis checks, including: - Scanning for virtual machine BIOS strings and suspicious software libraries. - Waiting for real mouse movement (automated sandboxes don’t trigger this). - If checks pass, it disables Windows Defender, opens firewall ports, and downloads six modular components from an attacker-controlled Azure DevOps repository. 2. Credential Theft & Persistence - The malware fetches a dynamic targeting list (hosted on Azure DevOps) covering: - 201 crypto wallets (MetaMask, Phantom, Coinbase, Ledger Live, etc.). - 49 password managers/authenticators (Bitwarden, LastPass, 1Password, Google Authenticator, etc.). - The list is remotely updatable, allowing attackers to expand targets without recompiling the malware. - Persistence mechanisms include: - Registry autoruns. - Windows logon hijacking. - Scheduled tasks. - Telegram-based droppers that survive even if the main implant is removed. 3. Evasive Infrastructure - Command-and-control (C2) servers are never hardcoded instead, the malware retrieves them from Telegram channel descriptions, allowing rapid rotation if domains are blocked. - Victim data (usernames, IPs, timestamps) is routed through Hookdeck, a legitimate webhook relay service, obscuring the attacker’s backend. - Researchers observed infrastructure rotation during analysis, with domains and IPs changing before findings were published. ### Key Indicators of Compromise (IoCs) - File Hashes: Multiple Rust-based droppers (e.g., `OpenClaw_x64[.]exe`, `svc_service[.]exe`) and secondary payloads (e.g., `onedrive_sync[.]exe`, `WinHealhCare[.]exe`). - Domains: - `openclaw-installer[.]com` (delivery). - `hkdk.events` (C2 relay via Hookdeck). - `dev.azure.com/sagonbretzpr` (payload staging). - Hijacked Brazilian law firm domain (`frr.rubensbruno.adv.br`) and others. - IPs: `193.202.84.14`, `45.55.35.48`, `188.114.97.3` (C2 beacons). - Registry Keys & Paths: - `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit` (logon hijack). - `C:\Users\Public\` (stage-2 binary drop location). - `%APPDATA%\Ledger Live` (targeted for wallet theft). ### Why This Campaign Stands Out - Advanced Evasion: Uses Rust-based malware, in-memory .NET assembly loading (via `clroxide`), and Telegram for C2 rotation. - Dynamic Targeting: The remote Git repository allows attackers to silently expand their target list without detection. - Persistence: Multiple layers of registry, scheduled tasks, and Telegram-based backdoors ensure long-term access. Researchers at Netskope Threat Labs identified this as a second, more advanced iteration of the campaign, following an earlier variant. The attack highlights the growing sophistication of infostealers, particularly in crypto and credential theft.
INCIDENT DETAILS -
TYPE
Infostealer
MOTIVATION
Financial gain (crypto theft, credential harvesting)
IMPACT
Data Compromised: Crypto wallet credentials, password manager data, personally identifiable informationSystems Affected: Windows systems with targeted browser extensionsOperational Impact: Potential unauthorized access to financial and personal accountsIdentity Theft Risk: HighPayment Information Risk: High (crypto wallets)
DATA BREACH
Crypto wallet credentialsPassword manager dataPersonally identifiable informationSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
JANUARY 2026
344Before Incident
Breach
05 Jan 2026 • Ledger
Ledger and Global-e: Crypto wallet firm Ledger faces new data breach through Global-e partner

Ledger Data Exposure via Third-Party Payment Processor Global-e

281After Incident
CRITICAL-63
LEDGLO1767622098
Ledger Customers Exposed in Third-Party Payment Processor Breach Hardware wallet provider Ledger is addressing a data exposure incident tied to its third-party payment processor, Global-e. The breach, first reported by blockchain investigator ZachXBT on X, involved unauthorized access to Ledger users' personal details—including names and contact information—stored in Global-e’s cloud system. Global-e detected the suspicious activity and launched an investigation, confirming that an unauthorized party accessed customer order data. While the exact number of affected users and the timeline of the breach remain undisclosed, forensic experts verified the improper access. The company stated that payment information was not compromised. Ledger clarified that the incident occurred at Global-e, not within its own systems, and emphasized that no hardware, software, or cryptocurrency-related data—such as seed phrases or wallet balances—was exposed. As the data controller, Global-e issued notifications to impacted customers. The breach also affected other brands using Global-e’s services, as the compromised cloud system contained order data from multiple retailers. This is not Ledger’s first security incident. In 2020, a breach via e-commerce partner Shopify exposed data from 270,000 customers, and in 2023, a hack resulted in nearly $500,000 in losses for decentralized finance applications. Ledger has stated it is collaborating with Global-e to provide updates to affected users.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Data Compromised: Personal details (names, contact information)Systems Affected: Global-e's cloud systemIdentity Theft Risk: PotentialPayment Information Risk: None (payment information not involved)
DATA BREACH
Type Of Data Compromised: Personal details (names, contact information)Sensitivity Of Data: Low to moderate (no payment information or secrets)Personally Identifiable Information: Names, contact information
JANUARY 2026
363Before Incident
Cyber Attack
01 Jan 2026 • Ledger
Microsoft, Trezor, Audacity, GitHub and Ledger: OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases

New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics

344After Incident
CRITICAL-19
LEDGITMICAUDTRE1784125944
New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics A sophisticated malware framework, OkoBot, has emerged as a major threat to cryptocurrency users, employing a multi-stage attack chain to steal recovery phrases, credentials, and wallet data. First observed in January 2026, the campaign builds on the TookPS downloader, which has been active since March 2025. OkoBot operates as a modular platform with over 202,020 payloads, allowing attackers to deploy capabilities remotely via SSH infrastructure. Initial infections occur through ClickFix social-engineering attacks and trojanized applications hosted on GitHub, including a fake Microsoft SQL Server Management Studio (SSMS) repository that delivered a malicious Audacity installer. Once executed, TookPS installs an SSH service, establishes a tunnel to attacker-controlled servers, and conducts system reconnaissance identifying security software, harvesting browser data, and preparing for deeper compromise. The malware also enables remote desktop (RDP) access by modifying firewall rules, creating backdoor user accounts, and patching termsrv.dll to allow concurrent sessions. A key component, HDUtil, bypasses User Account Control (UAC) using Windows RPC and msconfig.exe, while SeedHunter targets Ledger Live, Ledger Wallet, and Trezor Suite by injecting fake recovery prompts. When a victim enters their seed phrase, it is exfiltrated to moonsand[.]store and stored locally in an RC4-encrypted file. Additional plugins include: - MC Keylogger – Logs clipboard data, USB devices, and screenshots. - OkoSpyware – Records keystrokes and video streams from wallet apps and password managers. Kaspersky researchers detected hundreds of victims across 25+ countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye. While attribution remains unclear, Russian-language artifacts, Rilide stealer usage, and CIS geoblocking suggest ties to Russian-speaking cybercrime groups. The malware’s ability to bypass security controls, maintain persistence, and exfiltrate sensitive data makes it a significant risk for cryptocurrency holders and organizations.
INCIDENT DETAILS -
TYPE
Malware
MOTIVATION
Financial gain
IMPACT
Recovery phrasesCredentialsWallet dataBrowser dataKeystrokesVideo streamsClipboard dataUSB device dataScreenshotsCryptocurrency wallet applications (Ledger Live, Ledger Wallet, Trezor Suite)Password managersIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Recovery phrasesCredentialsWallet dataBrowser dataPersonally identifiable informationSensitivity Of Data: HighData Exfiltration: Yes (to moonsand[.]store)Data Encryption: RC4-encrypted files (local storage)Personally Identifiable Information: Yes
DECEMBER 2025
357Before Incident
NOVEMBER 2025
372Before Incident
Cyber Attack
19 Nov 2025 • Ledger
Ledger / Trezor (Cryptocurrency Wallet Providers)

Nova Stealer macOS Malware Campaign Targeting Cryptocurrency Users

352After Incident
CRITICAL-20
LED5093550111925
The Nova Stealer malware campaign targets macOS users by replacing legitimate Ledger Live and Trezor Suite cryptocurrency wallet applications with malicious counterparts. The attack begins with a dropper downloading a shell script (`mdriversinstall.sh`) from a C2 server, establishing persistence via a hidden directory (`~/.mdrivers`) and a LaunchAgent (`application.com.artificialintelligence`). The malware operates stealthily using detached `screen` sessions, ensuring survival across reboots.Key modules include:- `mdriversfiles.sh`: Exfiltrates wallet data (e.g., Trezor’s `IndexedDB`, Exodus’ `passphrase.json`, Ledger’s `app.json`).- `mdriversswaps.sh`: Replaces genuine wallet apps with unsigned FAT Mach-O executables (Swift-based) that render phishing pages (`wheelchairmoments[.]com`, `sunrisefootball[.]com`). These pages use BIP-39/SLIP-39 validation to harvest recovery phrases (12–33 words) via keystroke logging (200–400ms debounce) and real-time tracking (`/track` endpoints).- `mdriversmetrics.sh`: Conducts system reconnaissance (installed apps, processes).Victims unknowingly interact with counterfeit apps (registered in Dock via `PlistBuddy`), leading to full compromise of cryptocurrency assets. The modular design allows remote updates, extending the campaign’s lifespan while evading static detection. The attack focuses on high-value targets (crypto users), with potential for mass financial loss and irreversible asset theft due to exposed recovery phrases.
INCIDENT DETAILS -
TYPE
malwarephishingdata theftcryptocurrency fraud
MOTIVATION
financial gain (theft of cryptocurrency via harvested recovery phrases)
IMPACT
cryptocurrency wallet recovery phrases (BIP-39/SLIP-39)Trezor Suite IndexedDB filesExodus wallet configuration (passphrase.json, seed.seco)Ledger Live app.jsoninstalled applications listrunning processeswallet presence indicatorsmacOS systems with Ledger Live, Trezor Suite, or Exodus wallets installedunauthorized replacement of legitimate applications with malicious counterpartspersistent background monitoring via detached screen sessionsreal-time exfiltration of keystrokes and recovery phrasespotential loss of trust in cryptocurrency wallet providers (Ledger, Trezor, Exodus) due to impersonationhigh (if recovery phrases are used to drain wallets)high (direct theft of cryptocurrency assets)
DATA BREACH
cryptocurrency wallet recovery phraseswallet configuration files (passphrase.json, seed.seco, app.json)system reconnaissance data (installed apps, processes)Sensitivity Of Data: extremely high (direct access to cryptocurrency assets)recovery phrases sent to /seed and /seed2 endpointspartial keystrokes logged with 200-400ms debounceuser activity beacons sent to /track every 10 secondsnone (data exfiltrated in plaintext via HTTP POST)JSON (passphrase.json, app.json, seed.seco), IndexedDB, SQLite (Launchpad databases)potentially linked to wallet ownership if recovery phrases are tied to identities
AUGUST 2025
437Before Incident
Breach
18 Aug 2025 • Ledger
Canadian Investment Regulatory Organization: 750,000 Impacted by Data Breach at Canadian Investment Watchdog

CIRO Data Breach Exposes Personal Information of 750,000 Individuals

349After Incident
CRITICAL-88
CIR1768585990
CIRO Data Breach Exposes Personal Information of 750,000 Individuals The Canadian Investment Regulatory Organization (CIRO) disclosed a data breach on August 18, 2025, revealing that hackers accessed the personal information of approximately 750,000 individuals in an August cyberattack. The breach stemmed from a sophisticated phishing incident, which led to temporary system shutdowns, though CIRO confirmed its critical regulatory functions remained unaffected. According to CIRO, the compromised data includes sensitive details such as annual income, dates of birth, government-issued ID numbers, phone numbers, investment account numbers, social insurance numbers, and account statements information collected during routine regulatory and compliance activities. The organization clarified that passwords, PINs, and security questions were not exposed, as CIRO does not store such data. While CIRO reported no evidence of data misuse or dark web exposure, it continues to monitor for malicious activity. Impacted individuals clients and former clients of CIRO dealer members are being notified and offered two years of free credit monitoring and identity theft protection services. An FAQ page has also been published to provide further details. CIRO, a pan-Canadian self-regulatory body overseeing investment and mutual fund dealers, stated that the incident is contained with no active threat remaining in its environment. The breach follows a series of recent cybersecurity incidents affecting financial and healthcare sectors globally.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal information of 750,000 individualsSystems Affected: Temporary system shutdownsOperational Impact: Critical regulatory functions remained unaffectedIdentity Theft Risk: High
DATA BREACH
Annual incomeDates of birthGovernment-issued ID numbersPhone numbersInvestment account numbersSocial insurance numbersAccount statementsNumber Of Records Exposed: 750,000Sensitivity Of Data: HighData Exfiltration: No evidence of data misuse or dark web exposurePersonally Identifiable Information: Yes
MARCH 2025
483Before Incident
Breach
02 Mar 2025 • Ledger
SafePal: SafePal data breach impacts 39,798 customers, stolen info for sale

SafePal Data Breach Exposes Nearly 40,000 Customers’ Order Information

400After Incident
CRITICAL-83
SAF1786926220
SafePal Data Breach Exposes Nearly 40,000 Customers’ Order Information SafePal, a cryptocurrency hardware wallet provider, has disclosed a data breach affecting 39,798 customers after a flaw in its order-tracking system was exploited to steal personal information. The incident impacts users who placed orders between March 2, 2025, and April 11, 2026, exposing names, email addresses, shipping details, phone numbers, and purchase information. The breach did not compromise wallet seed phrases, private keys, passwords, payment details, or government-issued IDs. SafePal confirmed that no evidence suggests unauthorized access to customer funds or wallets. Impacted users were notified via email on August 16, 2026, and the company released an online verification tool to check if order data was exposed. A threat actor is now selling the stolen data on a cybercrime forum, matching SafePal’s disclosed timeline and customer count. The seller offered to verify order details using SafePal’s tool to prove legitimacy. While the data’s authenticity has not been independently confirmed, customers reported phishing attempts including fake firmware update emails and fraudulent calls as early as May 2026. SafePal first detected suspicious activity in early May 2026 but initially treated it as an isolated case. A full investigation in July 2026 uncovered an authorization flaw in a third-party order-tracking plugin, which allowed unauthorized access to customer data. The company patched the vulnerability and implemented additional security measures, later discovering a separate configuration error that caused order data to be retained longer than intended back to March 2025. SafePal has since purged exposed personal data from active servers, retaining an encrypted offline copy for potential law enforcement use. The company also took down over 30 fraudulent websites and phishing links tied to the breach. While customers do not need to replace hardware wallets or move funds, those who shared seed phrases or private keys in response to phishing attempts should transfer assets to a new wallet. SafePal is working with a third-party security firm to validate fixes and review its order-processing systems. The incident highlights risks of targeted phishing and social engineering attacks using stolen order data.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain (data sold on dark web), potential for phishing/social engineering
IMPACT
Data Compromised: Names, email addresses, shipping details, phone numbers, purchase informationSystems Affected: Order-tracking system, third-party pluginOperational Impact: Purged exposed data, took down fraudulent websites/phishing links, implemented additional security measuresCustomer Complaints: Phishing attempts reported (fake firmware update emails, fraudulent calls)Brand Reputation Impact: Yes (public disclosure, phishing attacks, fraudulent websites)Identity Theft Risk: Moderate (PII exposed, but no government-issued IDs or payment details)Payment Information Risk: None (payment details not compromised)
DATA BREACH
NamesEmail addressesShipping detailsPhone numbersPurchase informationNumber Of Records Exposed: 39,798Sensitivity Of Data: Moderate (PII, but no financial or highly sensitive data like seed phrases/private keys)Data Exfiltration: Yes (data sold on cybercrime forum)Data Encryption: Encrypted offline copy retained for law enforcementPersonally Identifiable Information: Yes (names, email addresses, phone numbers, shipping details)
FEBRUARY 2025
671Before Incident
Breach
18 Feb 2025 • Ledger
Ledger: Ledger sued for $500M over alleged data breach and crypto theft

Ledger Faces $500M Class Action Over Alleged Security Failures and Crypto Theft

481After Incident
CRITICAL-190
LED1788441237
Ledger Faces $500M Class Action Over Alleged Security Failures and Crypto Theft Ledger, the hardware wallet manufacturer, is facing a proposed class action lawsuit seeking at least $500 million in damages over alleged security and disclosure failures tied to a December 2023 breach. The complaint, filed on August 27 in the U.S. District Court for the Southern District of New York by plaintiff Douglas Kim, accuses Ledger of negligence, deceptive practices, and failing to protect customer data leading to nearly $1.95 million in stolen cryptocurrency from Kim alone. The lawsuit centers on a December 2023 incident involving Ledger’s Connect Kit, a software library used to link hardware wallets with decentralized applications. Attackers compromised a former employee’s NPMJS account via phishing, exploiting Ledger’s failure to revoke access post-employment. The hackers then deployed a malicious version of the Connect Kit, tricking users into approving transactions that drained their wallets. While Ledger initially estimated losses at $480,000–$600,000, the company later committed to reimbursing affected users and announced plans to phase out blind signing for Ethereum-based dApps. Kim’s complaint alleges that the breach exposed customer personally identifiable information (PII), including names, emails, and phone numbers, which scammers later used to impersonate Ledger representatives. In February 2025, Kim received a fraudulent call from individuals posing as Ledger’s Coincover department, warning of a security threat and directing him to a phishing site. After entering his passphrase, Kim lost $1.95 million in cryptoassets none of which have been recovered. The lawsuit also highlights Ledger’s 2020 data breach, which exposed over 270,000 customers’ PII, as evidence of a pattern of inadequate security. Kim argues that Ledger’s public claims about encryption, employee training, and monitoring were misleading, given its failure to address foreseeable risks. The complaint includes seven causes of action, including violations of New York’s SHIELD Act and General Business Law, negligence, and breach of good faith. The proposed nationwide class covers U.S. customers whose PII or cryptoassets were compromised, with a subclass for New York-based victims. Kim estimates collective damages could exceed $500 million, potentially reaching billions, depending on the number of affected users. The lawsuit seeks actual, compensatory, statutory, treble, and punitive damages, along with attorneys’ fees and a jury trial.
INCIDENT DETAILS -
TYPE
Data Breach, Phishing, Supply Chain Attack, Fraud
MOTIVATION
Financial gain
IMPACT
Financial Loss: $1.95M (plaintiff alone), $480K–$600K (initial Ledger estimate), $500M+ (proposed class action damages)Data Compromised: Personally Identifiable Information (PII) including names, emails, phone numbers, and crypto wallet credentialsSystems Affected: Ledger Connect Kit (software library), User wallets linked to decentralized applicationsOperational Impact: Loss of customer trust, Reimbursement commitments, Phasing out of blind signing for Ethereum-based dAppsCustomer Complaints: Fraudulent calls impersonating Ledger representatives, Phishing attacks targeting customersBrand Reputation Impact: Significant (allegations of negligence, deceptive practices, and repeated security failures)Legal Liabilities: Class action lawsuit ($500M+ sought), Violations of New York SHIELD Act and General Business Law, Potential regulatory finesIdentity Theft Risk: High (PII exposed, used for phishing and fraud)Payment Information Risk: High (crypto wallet credentials compromised, direct theft of assets)
DATA BREACH
Personally Identifiable Information (PII)Crypto wallet credentialsNumber Of Records Exposed: 270,000+ (from 2020 breach), Unknown (2023 breach)Sensitivity Of Data: High (PII, financial/crypto credentials)Data Exfiltration: Yes (used for follow-up phishing attacks)NamesEmailsPhone numbers
JANUARY 2024
663Before Incident
Cyber Attack
01 Jan 2024 • Ledger
Ledger

13% Increase in Ransomware Attacks on European Organizations (2024-2025)

638After Incident
CRITICAL-25
LED1832718110325
In January 2025, Ledger, a Paris-based crypto-wallet vendor, fell victim to a Violence-as-a-Service (VaaS) attack orchestrated by Russia-linked groups Renaissance Spider and The Com. The co-founder of Ledger was kidnapped in France as part of an extortion scheme tied to cryptocurrency theft. The attack was executed via Telegram-coordinated networks, leveraging physical violence, arson threats, and ransom demands. This incident was among 17 recorded VaaS attacks since January 2024, with 13 occurring in France alone, prompting Europol to establish a dedicated taskforce to counter the escalating threat. The attack not only endangered the executive’s life but also exposed Ledger to reputational damage, operational disruption, and potential financial losses due to ransom pressures. The incident underscores the convergence of cyber extortion and physical violence, targeting high-profile individuals in the crypto sector to exploit digital and real-world vulnerabilities.
INCIDENT DETAILS -
TYPE
ransomwaredata breachextortionvishingphysical threats (Violence-as-a-Service)
MOTIVATION
financial gain (ransomware payouts, avg. $3.6M)data theft for extortioncryptocurrency theft (Violence-as-a-Service)geopolitical leverage (exploiting GDPR compliance)
IMPACT
Data Compromised: 2100+ victims (92% involved data theft)VMware ESXi infrastructure (Linux ransomware)unmanaged systems (used for lateral movement)backup/restore configuration databases (credential dumping)Operational Impact: disruption across manufacturing, professional services, technology, industrials/engineering, and retail sectorsBrand Reputation Impact: high (public disclosure of 1380+ victims on leak sites)Legal Liabilities: potential GDPR violations (used as leverage for ransom)Identity Theft Risk: high (PII likely exposed in 92% of cases with data theft)
DATA BREACH
corporate datapersonally identifiable information (PII)potential payment dataNumber Of Records Exposed: 2100+ victims (92% with data theft)Sensitivity Of Data: high (PII, corporate secrets, potential GDPR-regulated data)Data Exfiltration: yes (92% of ransomware cases)Data Encryption: yes (92% of cases involved file encryption)Personally Identifiable Information: likely (used for extortion leverage)
DECEMBER 2023
725Before Incident
Breach
01 Dec 2023 • Ledger
Ledger

Phishing Attack on Ledger Connect Kit Software

661After Incident
HIGH-64
LED743221223
The Ledger Connect Kit software of the Paris-based business was compromised by a phishing attempt targeting a former worker. During transactions using decentralised applications, or dapps, that utilised the compromised software, the hacker released malicious code that routed user funds to their own wallet.
INCIDENT DETAILS -
TYPE
Phishing Attack
MOTIVATION
Financial gain
IMPACT
Ledger Connect Kit Software
JUNE 2020
757Before Incident
Data Leak
01 Jun 2020 • Ledger
Ledger

Ledger Data Breach

680After Incident
CRITICAL-77
LED213813123
Major cryptocurrency hardware wallet provider Ledger experienced a data breach. The company said it was made aware of the breach on July 14 when a researcher participating in its bounty program reached out with details of a potential vulnerability on their website. While they were able to fix the breach immediately, a further investigation found that an authorized third party carried out a similar action on June 25. The individual used an API key to access the marketing and e-commerce database the company used to send promotional emails. This compromised the email addresses of almost one million people. For a subset of 9,500 customers, details such as first and last name, postal address, and phone number were also exposed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Email addressesFirst and last namesPostal addressesPhone numbers
DATA BREACH
Email addressesFirst and last namesPostal addressesPhone numbersAlmost one million9,500 with additional detailsFirst and last namesPostal addressesPhone numbers

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Ledger ?
?
What was Ledger's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Ledger's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Ledger's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Ledger's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Ledger's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Ledger's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Ledger's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Ledger's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Ledger's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Ledger's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Ledger's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Ledger's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Ledger ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Ledger's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?