Ledger customers impacted by third-party Global-e data breach
嗯,用户让我帮忙总结一篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。首先,我需要理解文章的主要内容。 文章讲的是Ledger公司通知一些客户,他们的个人数据被黑客入侵了。黑客攻击的是第三方支付处理器Global-e的系统。Ledger强调自己的网络没有受到影响,平台的硬件和软件都是安全的。被泄露的数据包括客户的姓名和联系方式,但不涉及财务信息或加密钱包的私钥。Ledger提醒客户注意钓鱼攻击,并建议不要泄露24字种子词。 接下来,我需要将这些信息浓缩到100字以内。要抓住关键点:Ledger通知客户数据泄露,原因第三方Global-e被黑,Ledger自身系统安全,泄露的数据类型,以及提醒客户防范钓鱼攻击。 可能的结构是:Ledger通知部分客户数据因Global-e被黑而泄露,未影响自身系统,泄露信息不含财务或私钥,提醒防范钓鱼攻击。 这样应该可以控制在100字以内,并且直接描述内容。 </think> Ledger通知部分客户因第三方支付处理器Global-e遭黑客入侵导致个人数据外泄,其自身网络未受影响,泄露信息不含财务或私钥,提醒用户警惕钓鱼攻击。 2026-1-5 15:15:24 Author: www.bleepingcomputer.com(查看原文) 阅读量:5 收藏

Ledger customers impacted by third-party Global-e data breach

Ledger is informing some customers that their personal data has been exposed after hackers breached the systems of third-party payment processor Global-e.

In a statement for BleepingComputer, the blockchain company underlines that its network has not been impacted and that the platform's hardware and software systems remain secure.

"Some of the data accessed as part of this incident pertained to customers who purchased on Ledger.com using Global-e as a Merchant of Record," the company told BleepingComputer.

Wiz

Out of an abundance of caution, Ledger, the maker of the namesake self-custodial hardware wallets, is warning its customers that the third-party data breach exposed their names and contact information.

On-chain investigator ZachXBT published a community alert with the notification from Ledger:

Tweet

The Global-e platform handles checkout, order processing, localization, taxes, duties, and compliance for multiple online retailers and brands. Among its customers are Bang&Olufsen, adidas, Disney, Givenchy, Hugo Boss, Ralph Lauren, Michael Kors, Netflix, and M&S.

These services require storing customer order data, though Ledger specified that the exposed details do not include financial information.

According to Ledger, the hackers had access to order data present on Global-e's systems. However, neither Global-e nor Ledger had access to customers' 24-word seed phrases for accessing the crypto wallet, the blockchain balance, or any secrets related to digital assets.

"Importantly, no payment information was involved," the company said, noting that attackers may try to target customers in phishing campaigns designed to steal their passphrases.

“We encourage everyone to be alert to any potential phishing campaigns, never disclose their 24 words, and always Clear Sign transactions where possible.” - Ledger

It was also specified that Ledger was not the only brand whose customer data was affected, and that the unauthorized party gained access to a Global-e cloud-based information system containing shopper order data from several brands.

BleepingComputer reached out to Global-e to learn more about the incident and the affected brands, but we have not received a response by publication time.

Ledger says that affected users will receive direct communication from Global-e about the incident and its impact. They are recommended to contact Global-e for more details.

Wiz

Secrets Security Cheat Sheet: From Sprawl to Control

Whether you're cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start.

Get the cheat sheet and take the guesswork out of secrets management.


文章来源: https://www.bleepingcomputer.com/news/security/ledger-customers-impacted-by-third-party-global-e-data-breach/
如有侵权请联系:admin#unsafe.sh