• About
  • FAQ
  • Landing Page
  • Buy JNews
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
Crypto News
No Result
View All Result
Home Bitcoin (BTC) News

Ledger data leak: A ‘simple mistake’ exposed 270K crypto wallet buyers

by
December 24, 2020
in Bitcoin (BTC) News
0
Ledger data leak: A ‘simple mistake’ exposed 270K crypto wallet buyers
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Ledger wallet users face mounting home invasion and other scareware threats as hacker dumps private customer information online.

Related articles

Former Canadian prime minister names Bitcoin as possible reserve currency

Former Canadian prime minister names Bitcoin as possible reserve currency

January 17, 2021
Former Ripple CTO may have lost much more than $220M in Bitcoin

Former Ripple CTO may have lost much more than $220M in Bitcoin

January 17, 2021

The hacker likely responsible for Ledger’s security breach in July recently dumped a large amount of data exposing the personal information of over 270,000 customers, including phone numbers and physical addresses. The leak also included 1 million emails of Ledger wallet owners and customers that were signed up to the company’s newsletter service.

Amid the furor caused by the incident, Ledger says its focus is on improving its security infrastructure rather than reimbursing users for any losses that may occur. Meanwhile, some affected customers are reportedly considering taking legal action against the company in the form of a class-action lawsuit.

The Ledger customer data leak also offers fresh fodder for the debate against implementing more Know Your Customer compliance protocols, critics of which argue that such measures encourage targeted cyber attacks aimed at exposing critical personal data.

Over 270,000 personal account details compromised

As mentioned, the hacker presumably responsible for breaching the Ledger e-commerce database back in July dumped the personal information of thousands of affected users online. The company was blamed on social media for not providing better protection of user data and downplaying the extent of the initial breach. At the time, the hardware wallet maker declared that only 9,500 customers were affected by the security breach.

Addressing the disparity in the reported number of people affected, Ledger issued a statement on Dec. 21 declaring that the leak covered more material than it was able to analyze earlier in the year. However, the company affirmed that customer funds remained safe, adding: “This data breach has no link nor impact on our hardware wallets, the app or your funds. Your crypto assets are safe. While very truly and sincerely regrettable, this breach concerns only e-commerce related information.”

Responding to the incident via Twitter, Ledger CEO Pascal Gauthier remarked that the leak was indicative of the growing threat of cyberattacks. Appearing on the What Bitcoin Did podcast with Peter McCormack, Gauthier commented on the nature of the breach, stating that it was the result of a mistake in the company’s e-commerce stack.

“It’s a wrong API key that got coded on the map client to import the database from the store that got coded in the wrong placements and so, therefore, was coded where it should not have been coded and exposed the database to a simple attack,” explained Gauthier.

Amid the reactions to the leak, some cybersecurity experts highlighted that the incident was another pointer to the lack of encryption deployment by database administrators in storing user data. The Ledger CEO addressed the lack of encryption on the API keys, adding that it was an honest mistake and not a deliberate attempt to jeopardize customer safety by failing to hash API keys.

Commenting on the leak, Ruben Merre, CEO of hardware wallet maker NGRAVE, remarked that the incident was reflective of rapid growth among crypto firms coming at the expense of security considerations. He added: “So many online platforms get hacked, and not necessarily because of the hackers’ skill. Often, platforms just have bad security governance, let alone implementation.”

‘Scareware’ and other risk factors

The data leak has triggered another round of phishing attacks as rogue actors, now armed with the emails of Ledger users, attempt to trick the wallet’s customers into revealing their 24-word seed phrase. Even before the data dump, such phony emails were a regular occurrence.

However, the exposure of phone numbers and personal addresses potentially opens up Ledger users to more risk factors. Some users have reported attempted SIM swapping attacks on their numbers with the hacker presumably trying to compromise two-factor authorization protocols.

Crypto investors have been targets of SIM swap attacks in the past. Back in June, Richard Yuan Li was charged with conspiracy to commit wire fraud in connection with a series of SIM swap attacks that targeted over 20 individuals.

Apart from phishing and SIM swap exploits, the data leak also opens up the possibility of the risk factors moving beyond scareware into the realm of actual physical attacks. Indeed, some users affected by the incident claim to have received threatening messages asking for payments or risk possible home invasions.

The Ledger CEO has acknowledged the possibility of physical attacks as a result of the company’s oversight, and has also assured users that their hardware wallet devices contained several protective protocols to safeguard against the theft of funds. Among these security measures is the use of incorrect pincode entries to format devices or a second password that displays a dummy account, leaving the owner’s actual funds safe from bad actors.

Additionally, the consensus among security experts on social media is that consumers should be using post office box addresses or other public pickup locations instead of their actual home addresses for sensitive items like a Ledger hard wallet. For those with compromised phone numbers, the best line of action appears to be getting a new number and using a new email address to communicate the change to important contacts.

While affected customers continue to deal with the fallout of the leak, Ledger says it is working to prevent future occurrences. In a statement to Cointelegraph, the company stated:

“We are doing everything in our power to cease these attacks and avoid situations like this in the future. Ledger has a set of measures in place to protect our users from falling victims to phishing attacks. We have set up a webpage sharing the anatomy of phishing attacks so users can avoid falling for them and report any new attacks.”

Affected users threaten legal action

Some affected users began advocating for legal action against Ledger immediately following the reported leak. There is even a “Ledger wallet leak” subreddit on the Reddit platform, where users are discussing possible modalities for a class-action lawsuit.

With its headquarters in Paris, Ledger falls under the laws of the European Union. In November, the European Parliament adopted legislative amendments that will allow EU customers to institute class-action lawsuits against companies operating in the region within the next two years.

According to the ruling at the time, once passed into law, class-action lawsuits can be filed against companies operating in the EU for cases involving financial services, tourism and data protection, among others.

Ledger’s EU customers will require a qualified consumer protection body or some other recognized entity to represent the complainants. However, unlike U.S. laws, punitive damages from EU class-action lawsuits are restricted to the actual losses incurred by the class of plaintiffs.

Apart from customers filing a lawsuit against the company, the data leak might also constitute a breach of privacy in the eyes of European regulators, specifically under the EU General Data Protection Regulation. In such situations, the EU has the ability to fine Ledger up to 4% of its revenue.

Indeed, with the Ledger CEO having admitted to the company anonymizing user data improperly, the company could come under scrutiny from EU officials. Recital 26 of the GDPR mandates all companies to ensure complete removal of all the information that can identify users from their cache of stored or processed data.

Share76Tweet47

Related Posts

Former Canadian prime minister names Bitcoin as possible reserve currency

Former Canadian prime minister names Bitcoin as possible reserve currency

by
January 17, 2021
0

Bitcoin could be part of a basket of reserve alternatives to the U.S. dollar, according to Stephen Harper. Stephen Harper,...

Former Ripple CTO may have lost much more than $220M in Bitcoin

Former Ripple CTO may have lost much more than $220M in Bitcoin

by
January 17, 2021
0

Current CTO David Schwartz claims Stefan Thomas created hundreds of accounts with 1.0 BTC "because that was the fastest and...

Hedge fund predicts $115K Bitcoin price and the fall of ‘speculative’ altcoins

Hedge fund predicts $115K Bitcoin price and the fall of ‘speculative’ altcoins

by
January 17, 2021
0

Analysts say Bitcoin and Ether’s growing dominance of the crypto market are signals that the current bull market is drastically...

Strategist: Bitcoin more likely to be successful ‘in the long run’ than Ethereum

Strategist: Bitcoin more likely to be successful ‘in the long run’ than Ethereum

by
January 17, 2021
0

Lyn Alden likens Ethereum to the Concorde aircraft: functional, but not "an economically sustainable project." One reason strategist and investment...

Top 5 cryptocurrencies to watch this week: BTC, LINK, UNI, XTZ, ATOM

Top 5 cryptocurrencies to watch this week: BTC, LINK, UNI, XTZ, ATOM

by
January 17, 2021
0

Bitcoin's brief period of consolidation has opened a path for select altcoins to rally higher. Bitcoin (BTC) price has yet...

Load More
  • Trending
  • Comments
  • Latest
Privacy Coins Monero, Dash, and Zcash to be Delisted on Bittrex, Dash Unhappy with Decision

Privacy Coins Monero, Dash, and Zcash to be Delisted on Bittrex, Dash Unhappy with Decision

January 4, 2021
SushiSwap’s SUSHI Surges 20% Again After Ethereum Price Correction

SushiSwap’s SUSHI Surges 20% Again After Ethereum Price Correction

December 6, 2020

Services Could Help Investors Rate Crypto Currencies

December 6, 2020

3 Factors That Made Bitcoin Become so Valuable Last Year

December 6, 2020
Former Canadian prime minister names Bitcoin as possible reserve currency

Former Canadian prime minister names Bitcoin as possible reserve currency

0

China Is Reportedly Moving To Clamp Down On Bitcoin Miners

0

Inside the Chinese Bitcoin Mine That’s Grossing $1.5M a Month

0

All You Need to Know About This Whole SegWit vs. SegWit2x Thing

0
Former Canadian prime minister names Bitcoin as possible reserve currency

Former Canadian prime minister names Bitcoin as possible reserve currency

January 17, 2021
Ethereum is About to Flip a Key Resistance Level into Support; New Highs Imminent?

Ethereum is About to Flip a Key Resistance Level into Support; New Highs Imminent?

January 17, 2021
Former Ripple CTO may have lost much more than $220M in Bitcoin

Former Ripple CTO may have lost much more than $220M in Bitcoin

January 17, 2021
Hedge fund predicts $115K Bitcoin price and the fall of ‘speculative’ altcoins

Hedge fund predicts $115K Bitcoin price and the fall of ‘speculative’ altcoins

January 17, 2021
Crypto News

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Categories tes

  • Abra
  • Altcoin News
  • altcoins
  • Altseason
  • Binance
  • Binance (BNB) News
  • Binance Coin (BNB)
  • Binance Smart Chain
  • bitcoin
  • Bitcoin
  • Bitcoin (BTC) Adoption
  • Bitcoin (BTC) General News
  • Bitcoin (BTC) News
  • Bitcoin (BTC) Predictions
  • Bitcoin Cash (BCH)
  • Bitcoin Cash (BCH) General News
  • Bitcoin dominance
  • bitcoin network
  • Bitcoin price
  • Bitstamp
  • Bittrex
  • Blockchain
  • Blockchain News
  • bloomberg
  • Brad Garlinghouse
  • Business
  • Cameron Winklevoss
  • ChainLink
  • ChainLink (LINK)
  • Chainlink (LINK) News
  • Chainlink Price Prediction
  • Changpeng Zhao
  • charlie lee
  • CME Group
  • coinbase
  • Coinmarketcap
  • cryptocurrency
  • Dash (DASH)
  • DeFi
  • DeFi Pulse
  • Electric Coin Company
  • ETH 2.0
  • ETH2.0
  • Ethereum
  • Ethereum (ETH)
  • Ethereum (ETH) News
  • Ethereum 2.0
  • Ethereum Classic (ETC)
  • Ethereum Futures
  • Ethereum Network
  • ethereum price
  • Ethereum price analysis
  • Ethereum Staking
  • Ethereum Upgrade
  • Ethereum Upgrades
  • Flare Networks
  • Flare Networks Snapshot
  • Gemini
  • google
  • Grayscale
  • Grayscale Bitcoin Trust (GBTC)
  • Guide
  • Guides
  • Institutional Investors
  • justin sun
  • JustSwap
  • LINK Marines
  • Litecoin
  • Litecoin (LTC)
  • Litecoin (LTC) News
  • Litecoin Development
  • litecoin foundation
  • Litecoin MimbleWimble
  • Market
  • MicroStrategy
  • MimbleWimble
  • Mining
  • Monero (XMR)
  • News
  • NFT
  • NFTs
  • Non-Fungible Tokens
  • Other
  • Poloniex
  • Prices
  • Regulation
  • ripple
  • Ripple
  • Scams and Hacks
  • sec
  • Securities and Exchange Commission
  • Spark Token (FLR)
  • Spark Token Airdrop
  • Spark Tokens (FLR)
  • Tron (TRX)
  • TRON (TRX) News
  • Tron Foundation
  • Twitter
  • Tyler Winklevoss
  • Wallets and Exchanges
  • XRP
  • XRP News
  • XRP Price Prediction
  • Yearn Finance (YFI)
  • Zcash (ZEC)
  • ZCash Halving
  • Zeus Capital
  • Zilliqa (ZIL)
  • Zilliqa (ZIL) News
  • Zilliqa Staking

Tags

Altcoin Bitcoin drops Bitcoin Wallet Cointelegraph Cryptocurrency ICO Investment Lending Market Stories Mining Bitcoin

Newsletter

[mc4wp_form]

  • About
  • FAQ
  • Support Forum
  • Landing Page
  • Buy JNews
  • Contact Us

© 2017 JNews - Crafted with love by Jegtheme.

No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© 2018 JNews by Jegtheme.