Filed Class Action · S.D.N.Y.

Ledger / Global-e Data Incident Class Action

Hall Attorneys and Milberg filed a putative class action alleging a December 2025 compromise of a Global-e cloud system exposed Ledger customer and order information later used in targeted impersonation and cryptocurrency-theft schemes.

Answer at a glance

What happened in the Ledger / Global-e data incident?

The complaint alleges that Global-e identified unauthorized access to a cloud system in December 2025. Ledger later said the system contained shopper order data for several brands and that some records concerned Ledger.com purchases processed through Global-e as merchant of record.

The lawsuit alleges that order and customer information can reveal that a person likely owns cryptocurrency and make a highly tailored impersonation campaign more credible. It further alleges criminals used current Ledger-specific facts and genuine Ledger communications in attacks that resulted in completed digital-asset losses.

The complaint contains allegations only; no findings have been made. It does not allege that defendants participated in the criminal thefts or that the current record conclusively identifies the source of every fact used by the attackers.

Alleged data categories

What information may have been involved?

The complaint says the precise fields associated with each affected shopper remain to be established through discovery and distinguishes shopper-order data from a direct compromise of wallet cryptography.

Identity and contact data
Names, email or other contact details, and shipping addresses associated with Ledger.com orders
Order and purchase data
Purchase timing, products, devices, prices, and related shopper-order information
Customer relationship data
Information capable of identifying a person as a Ledger customer or connecting a customer to a device, service, or support workflow
Important limitation
The complaint states that Ledger hardware, software, private keys, recovery phrases, payment-card data, account credentials, and blockchain balances were not reported as directly accessed in this incident
  1. Global-e identifies unauthorized cloud access

    According to the complaint, Global-E Online Ltd. identified unauthorized access to a cloud system. Global-e later said names and contact information were impacted.

  2. Ledger describes affected shopper-order data

    The complaint says Ledger disclosed that the affected Global-e system contained shopper order data for several brands and included records relating to some Ledger.com purchases processed through Global-e as merchant of record.

  3. Purported Ledger / Global-e dataset advertised

    The complaint describes a criminal-forum advertisement for a purported partial dataset. It treats the advertisement as threat intelligence requiring discovery, not as proof of the exact record count, fields, or provenance.

  4. Ledger warns about impersonation calls

    The complaint alleges Ledger published a warning about scammers using genuine Ledger support emails and references to Ledger Recover or CoinCover to make unsolicited calls appear legitimate.

  5. Targeted digital-asset losses alleged

    The complaint alleges two Ledger customers were targeted with current, customer-specific details and genuine Ledger communications and lost digital assets valued at more than US $2.6 million in total at filing-time values.

  6. Class action filed

    Hall Attorneys and Milberg filed the putative class action in the Southern District of New York. The matter is No. 1:26-cv-07222, ECF No. 1.

Who may want to contact us

Ledger customers in the United States and Canada

The complaint proposes a North American data-breach class, a targeted-impersonation subclass, and a digital-asset-loss subclass. The proposed definitions may change, and no class has been certified.

U.S. or Canadian residents whose Ledger customer, contact, shipping, order, purchase, device, product, or price information was allegedly compromised in the December 2025 incident

Ledger customers who received targeted calls, emails, texts, physical mail, or support contacts using customer-, order-, device-, service-, or address-specific details

People whose targeted impersonation involved a genuine Ledger communication or verification workflow

People who suffered an attempted or completed unauthorized transfer or theft of cryptocurrency or other digital assets after targeted impersonation

What to preserve

Keep records, but never share wallet secrets

Preserve the records below. Never send a recovery phrase, private key, PIN, password, authentication code, complete account number, or unredacted identity document through an ordinary website form or email.

Ledger purchase records

Keep Ledger.com order confirmations, receipts, shipping notices, device details, purchase dates, and records showing Global-e as seller or merchant of record.

Ledger and Global-e notices

Preserve incident notices, account messages, support emails, verification emails, Ledger Recover communications, and any follow-up from Ledger or Global-e.

Suspicious communications

Save call logs, voicemails, emails, texts, physical mail, domains, screenshots, and recordings involving Ledger-, Global-e-, police-, security-, CoinCover-, or recovery-themed contacts.

Wallet and transaction evidence

Preserve transaction exports, transaction hashes, wallet addresses, timestamps, exchange-rate records, and reports made to exchanges or blockchain-analysis services. Never send a recovery phrase or private key.

Reports and mitigation

Keep police, FBI IC3, exchange, insurer, and support reports, along with records of steps taken to secure remaining assets and accounts.

Time, expenses, and loss

Track time spent investigating or reporting the incident, professional fees, transaction costs, lost assets, and other out-of-pocket harm.

Filed claims

Claims and requested relief

The complaint pleads five counts and seeks damages, restitution, declaratory relief, and prospective security, notice, data-minimization, monitoring, and support-workflow measures. These are allegations and requests, not findings.

  1. Negligence against all defendants
  2. Breach of implied contract against the Global-e defendants and Ledger
  3. Breach of confidence against all defendants
  4. Restitution and unjust enrichment, pleaded in the alternative
  5. Declaratory and injunctive relief
  6. Requested measures addressing security assessments, merchant-tenant segmentation, access controls, logging, data minimization, individualized notice, victim assistance, and Ledger support-verification safeguards

Public filing reviewed

Source for this case overview

This page summarizes the allegations and requested relief in the filed complaint. It does not treat disputed allegations as established facts.

U.S. District Court, Southern District of New York ·

Ledger / Global-e Data Incident Class Action Complaint

The 39-page filed complaint is the source for the allegations, proposed class definitions, causes of action, requested relief, incident chronology, and alleged losses summarized on this page.

Read the complaint: Ledger / Global-e Data Incident Class Action Complaint

Contact the firm

Were you targeted after a Ledger purchase?

Contact Hall Attorneys with your state or province, purchase timeframe, device or service involved, and a short description of any notice, targeted communication, attempted theft, or loss. Do not include wallet secrets or unredacted sensitive records in an initial message.

Contact Hall Attorneys

Common questions

Ledger / Global-e lawsuit FAQ

Is this a filed Ledger / Global-e lawsuit?

Yes. Hall Attorneys and Milberg filed a putative class action on August 24, 2026 in the U.S. District Court for the Southern District of New York. The case is No. 1:26-cv-07222, ECF No. 1.

Who are the defendants?

The complaint names Global-E Online Ltd., Global-e US Inc., Ledger SAS, and Does 1-10 as defendants. The complaint contains allegations only; no findings have been made.

Who is included in the proposed classes?

The complaint proposes a North American Ledger/Global-e Data Breach Class for U.S. and Canadian residents whose specified Ledger customer information was allegedly compromised, a Targeted Impersonation Subclass, and a Digital-Asset Loss Subclass. No class has been certified.

Were Ledger wallets or recovery phrases directly compromised?

The complaint states that Ledger hardware, software, private keys, recovery phrases, and blockchain balances were not reported as compromised in the Global-e incident. It alleges instead that customer and order information could be used to identify and convincingly impersonate trusted parties to Ledger customers.

What information does the complaint say was involved?

The complaint describes names and contact information, shopper-order data, and potentially Ledger-specific shipping, purchase, device, product, price, service, and customer-relationship information. It says the precise fields associated with each affected person remain to be established through discovery.

How many people may be affected?

The complaint does not treat any public advertisement as proof of an exact class count. It alleges the class is sufficiently numerous based on the reported multi-brand system and threat intelligence, while stating that defendants' records should establish the actual number.

What claims does the complaint assert?

The complaint asserts negligence, breach of implied contract, breach of confidence, restitution and unjust enrichment, and declaratory and injunctive relief. These are allegations, not court findings.

What should Ledger customers preserve?

Preserve purchase and shipping records, notices, support and verification emails, suspicious communications, call logs, transaction exports, transaction hashes, reports, and loss records. Never provide a recovery phrase, private key, PIN, password, or authentication code through an ordinary website form or email.

Attorney Advertising

Hall Attorneys is not affiliated with Ledger, Global-e, or CoinCover. The complaint contains allegations only; no findings have been made, and no class has been certified. Sending information does not create an attorney-client relationship. Never send a recovery phrase, private key, PIN, password, authentication code, or other wallet secret.