New fake Ledger data breach emails try to steal crypto wallets
ID: 100881a9-8d85-5483-ac49-8d58610ae1bf
STIX ID: report--100881a9-8d85-5483-ac49-8d58610ae1bf
Feed Name: Bleeping Computer
A widespread phishing campaign impersonating Ledger is sending fake data-breach emails that direct users to an AWS-hosted redirect and a phishing domain (ledger-recovery.info) which asks for 12/18/24-word recovery phrases; the site validates words against the BIP-39 wordlist and exfiltrates entered seed words to attackers, enabling theft of cryptocurrency from compromised wallets. Users are advised never to enter recovery phrases on websites and to only enter them directly on their Ledger device.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
