logo

New fake Ledger data breach emails try to steal crypto wallets

ID: 100881a9-8d85-5483-ac49-8d58610ae1bf

STIX ID: report--100881a9-8d85-5483-ac49-8d58610ae1bf

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-12-17

Date Updated: 2026-03-27

Author: Lawrence Abrams

...
...

A widespread phishing campaign impersonating Ledger is sending fake data-breach emails that direct users to an AWS-hosted redirect and a phishing domain (ledger-recovery.info) which asks for 12/18/24-word recovery phrases; the site validates words against the BIP-39 wordlist and exfiltrates entered seed words to attackers, enabling theft of cryptocurrency from compromised wallets. Users are advised never to enter recovery phrases on websites and to only enter them directly on their Ledger device.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.