Ledger purchase records
Keep Ledger.com order confirmations, receipts, shipping notices, device details, purchase dates, and records showing Global-e as seller or merchant of record.
Hall Attorneys and Milberg filed a putative class action alleging a December 2025 compromise of a Global-e cloud system exposed Ledger customer and order information later used in targeted impersonation and cryptocurrency-theft schemes.
Answer at a glance
The complaint alleges that Global-e identified unauthorized access to a cloud system in December 2025. Ledger later said the system contained shopper order data for several brands and that some records concerned Ledger.com purchases processed through Global-e as merchant of record.
The lawsuit alleges that order and customer information can reveal that a person likely owns cryptocurrency and make a highly tailored impersonation campaign more credible. It further alleges criminals used current Ledger-specific facts and genuine Ledger communications in attacks that resulted in completed digital-asset losses.
The complaint contains allegations only; no findings have been made. It does not allege that defendants participated in the criminal thefts or that the current record conclusively identifies the source of every fact used by the attackers.
Case documents
Alleged data categories
The complaint says the precise fields associated with each affected shopper remain to be established through discovery and distinguishes shopper-order data from a direct compromise of wallet cryptography.
According to the complaint, Global-E Online Ltd. identified unauthorized access to a cloud system. Global-e later said names and contact information were impacted.
The complaint says Ledger disclosed that the affected Global-e system contained shopper order data for several brands and included records relating to some Ledger.com purchases processed through Global-e as merchant of record.
The complaint describes a criminal-forum advertisement for a purported partial dataset. It treats the advertisement as threat intelligence requiring discovery, not as proof of the exact record count, fields, or provenance.
The complaint alleges Ledger published a warning about scammers using genuine Ledger support emails and references to Ledger Recover or CoinCover to make unsolicited calls appear legitimate.
The complaint alleges two Ledger customers were targeted with current, customer-specific details and genuine Ledger communications and lost digital assets valued at more than US $2.6 million in total at filing-time values.
Hall Attorneys and Milberg filed the putative class action in the Southern District of New York. The matter is No. 1:26-cv-07222, ECF No. 1.
Who may want to contact us
The complaint proposes a North American data-breach class, a targeted-impersonation subclass, and a digital-asset-loss subclass. The proposed definitions may change, and no class has been certified.
U.S. or Canadian residents whose Ledger customer, contact, shipping, order, purchase, device, product, or price information was allegedly compromised in the December 2025 incident
Ledger customers who received targeted calls, emails, texts, physical mail, or support contacts using customer-, order-, device-, service-, or address-specific details
People whose targeted impersonation involved a genuine Ledger communication or verification workflow
People who suffered an attempted or completed unauthorized transfer or theft of cryptocurrency or other digital assets after targeted impersonation
What to preserve
Preserve the records below. Never send a recovery phrase, private key, PIN, password, authentication code, complete account number, or unredacted identity document through an ordinary website form or email.
Keep Ledger.com order confirmations, receipts, shipping notices, device details, purchase dates, and records showing Global-e as seller or merchant of record.
Preserve incident notices, account messages, support emails, verification emails, Ledger Recover communications, and any follow-up from Ledger or Global-e.
Save call logs, voicemails, emails, texts, physical mail, domains, screenshots, and recordings involving Ledger-, Global-e-, police-, security-, CoinCover-, or recovery-themed contacts.
Preserve transaction exports, transaction hashes, wallet addresses, timestamps, exchange-rate records, and reports made to exchanges or blockchain-analysis services. Never send a recovery phrase or private key.
Keep police, FBI IC3, exchange, insurer, and support reports, along with records of steps taken to secure remaining assets and accounts.
Track time spent investigating or reporting the incident, professional fees, transaction costs, lost assets, and other out-of-pocket harm.
Filed claims
The complaint pleads five counts and seeks damages, restitution, declaratory relief, and prospective security, notice, data-minimization, monitoring, and support-workflow measures. These are allegations and requests, not findings.
Public filing reviewed
This page summarizes the allegations and requested relief in the filed complaint. It does not treat disputed allegations as established facts.
U.S. District Court, Southern District of New York ·
The 39-page filed complaint is the source for the allegations, proposed class definitions, causes of action, requested relief, incident chronology, and alleged losses summarized on this page.
Read the complaint: Ledger / Global-e Data Incident Class Action ComplaintContact the firm
Contact Hall Attorneys with your state or province, purchase timeframe, device or service involved, and a short description of any notice, targeted communication, attempted theft, or loss. Do not include wallet secrets or unredacted sensitive records in an initial message.
Common questions
Yes. Hall Attorneys and Milberg filed a putative class action on August 24, 2026 in the U.S. District Court for the Southern District of New York. The case is No. 1:26-cv-07222, ECF No. 1.
The complaint names Global-E Online Ltd., Global-e US Inc., Ledger SAS, and Does 1-10 as defendants. The complaint contains allegations only; no findings have been made.
The complaint proposes a North American Ledger/Global-e Data Breach Class for U.S. and Canadian residents whose specified Ledger customer information was allegedly compromised, a Targeted Impersonation Subclass, and a Digital-Asset Loss Subclass. No class has been certified.
The complaint states that Ledger hardware, software, private keys, recovery phrases, and blockchain balances were not reported as compromised in the Global-e incident. It alleges instead that customer and order information could be used to identify and convincingly impersonate trusted parties to Ledger customers.
The complaint describes names and contact information, shopper-order data, and potentially Ledger-specific shipping, purchase, device, product, price, service, and customer-relationship information. It says the precise fields associated with each affected person remain to be established through discovery.
The complaint does not treat any public advertisement as proof of an exact class count. It alleges the class is sufficiently numerous based on the reported multi-brand system and threat intelligence, while stating that defendants' records should establish the actual number.
The complaint asserts negligence, breach of implied contract, breach of confidence, restitution and unjust enrichment, and declaratory and injunctive relief. These are allegations, not court findings.
Preserve purchase and shipping records, notices, support and verification emails, suspicious communications, call logs, transaction exports, transaction hashes, reports, and loss records. Never provide a recovery phrase, private key, PIN, password, or authentication code through an ordinary website form or email.
Attorney Advertising
Hall Attorneys is not affiliated with Ledger, Global-e, or CoinCover. The complaint contains allegations only; no findings have been made, and no class has been certified. Sending information does not create an attorney-client relationship. Never send a recovery phrase, private key, PIN, password, authentication code, or other wallet secret.