TechNewsReel
Live

Ledger Faces $500 Million Lawsuit Over Data Leaks and Phishing Losses

A proposed class action alleges security failures enabled targeted attacks that cost one user nearly $2 million.

TechNewsReel Newsroom · September 4, 2026

Douglas Kim has filed a proposed class action lawsuit against Ledger SAS, alleging that the company's failure to secure customer data enabled devastating phishing attacks. Filed August 27, 2026, in the U.S. District Court for the Southern District of New York, the suit seeks at least $500 million in damages.

According to court documents in case 1:26-cv-07307, Kim claims he lost approximately $1.95 million in cryptocurrency in February 2025. The lawsuit alleges that scammers impersonated Ledger support representatives by utilizing compromised customer information to target Kim specifically. The filing links these vulnerabilities to a security incident involving the Ledger Connect Kit in December 2023.

A Pattern of Security Failures

This legal action follows a series of high-profile security lapses for the hardware wallet provider. In 2020, a breach exposed the names, phone numbers, and physical addresses of more than 270,000 customers. More recently, the December 2023 Connect Kit incident occurred after a former employee's NPMJS account remained active, allowing malicious code to be uploaded via a supply chain attack. These events have created a persistent trail of exposed personally identifiable information (PII) that attackers can leverage long after the initial technical vulnerabilities are patched.

The Vulnerability of the Ecosystem

Ledger built its reputation on providing a safer way to hold cryptocurrency, but the lawsuit argues that its internal data practices left customers easier to find, pressure, and drain. The case highlights a critical paradox in the hardware wallet industry: while the physical devices are designed to keep private keys offline and secure, the companies managing the surrounding customer data often create a different, social-engineering-based attack vector.

By exposing PII, companies provide scammers with the necessary context to build trust with victims, rendering the technical security of the hardware less effective against sophisticated human-centric attacks. This challenges the industry assumption that a security breach is fully resolved once a software patch is deployed, suggesting instead that data exposure creates a permanent risk profile for the affected users.

What's Next

Ledger SAS has not yet provided a detailed public response to the specific allegations in the Kim lawsuit. The court will now determine if the case can proceed as a class action, which would expand the scope of damages to other Ledger users who may have been targeted by similar phishing campaigns. Observers will be watching to see if the court accepts the argument that a company is legally liable for third-party phishing attacks resulting from historical data leaks.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.