# Ledger / Global-e Data Incident Class Action Complaint - LLM-Readable Summary Canonical docket: https://hallattorneys.com/dockets/ledger Authoritative complaint PDF: https://hallattorneys.com/dockets/ledger/01-complaint.pdf Case overview: https://hallattorneys.com/ledger-data-breach ## Filing information - Public case label: Ledger / Global-e Data Incident Class Action. - Court: United States District Court for the Southern District of New York. - Case number: 1:26-cv-07222. - Document: ECF No. 1. - Filed: August 24, 2026. - Defendants: Global-E Online Ltd.; Global-e US Inc.; Ledger SAS; Does 1-10. - Counsel: Milberg PLLC; Hall Attorneys, P.C. - Jury trial demanded: Yes. - Length: 39 pages. This file intentionally summarizes the complaint without repeating individual plaintiff names. The authoritative filed PDF contains the complete caption, allegations, class definitions, counts, prayer for relief, and signatures. ## Nature of the action The complaint alleges a December 2025 compromise of a Global-e cloud system containing shopper order data for several brands, including Ledger. It alleges defendants failed to prevent, adequately disclose, and reasonably mitigate the foreseeable use of Ledger customer and order information in highly targeted cryptocurrency-theft schemes. It describes Global-e as an integrated, white-label, cross-border e-commerce platform and merchant of record that collects and processes shopper and order information. It alleges Ledger selected and integrated Global-e for Ledger.com transactions while retaining responsibilities relating to its products, customer support, customer communications, and data. ## Incident and alleged risk The complaint says Global-E Online Ltd. identified unauthorized access to a cloud system in December 2025 and later disclosed that names and contact information were impacted. It says Ledger stated that shopper order data from several brands was involved and that some affected records related to Ledger.com purchases processed through Global-e. The complaint states that Ledger hardware, software, private keys, recovery phrases, and blockchain balances were not compromised and that the known incident involved e-commerce and order data rather than a direct compromise of wallet cryptography. It nevertheless alleges that information identifying a person as a Ledger customer can expose that person to a special risk of targeted impersonation and digital-asset theft. The complaint describes a purported partial Ledger / Global-e dataset advertisement as threat intelligence requiring discovery, not conclusive proof of exact scope or provenance. It also alleges that criminals may enrich one dataset with older cryptocurrency-sector datasets. ## Targeted impersonation allegations The complaint alleges Ledger had warned by May 13, 2026 about telephone impersonation campaigns in which scammers triggered genuine Ledger communications, invoked Ledger Recover or CoinCover, and used the authentic message to make fraudulent calls appear legitimate. It alleges two Ledger customers later suffered completed digital-asset thefts after attackers used current Ledger-specific facts and genuine Ledger communications. The complaint values the two alleged losses at more than US $2.6 million in total at the time of the transfers. The complaint does not allege defendants participated in the criminal thefts or that the current record conclusively identifies the source of every fact used by the attackers. It alleges defendants created or materially increased a foreseeable risk and that their acts or omissions were a substantial factor in the alleged harm. ## Proposed classes The complaint proposes: 1. A North American Ledger/Global-e Data Breach Class for U.S. and Canadian residents whose specified Ledger customer information was allegedly compromised in the December 2025 incident. 2. A Targeted Impersonation Subclass for members of the proposed class who allegedly received a targeted Ledger-, Ledger Recover-, CoinCover-, Global-e-, police-, or security-themed impersonation contact using specified customer or genuine-communication information. 3. A Digital-Asset Loss Subclass for members of the targeted-impersonation subclass who allegedly suffered completed unauthorized transfers or theft of cryptocurrency or other digital assets. The proposed definitions are subject to amendment. No class has been certified. ## Counts Count I: Negligence against all defendants. Count II: Breach of implied contract against the Global-e defendants and Ledger. Count III: Breach of confidence against all defendants. Count IV: Restitution and unjust enrichment against all defendants, pleaded in the alternative. Count V: Declaratory and injunctive relief against all defendants. ## Prayer for relief The complaint requests class certification; damages; restitution; disgorgement; an accounting; declaratory and injunctive relief; prejudgment and post-judgment interest; fees, expenses, and costs; continuing jurisdiction; and other relief. Requested prospective measures include security assessments, vulnerability remediation, merchant-tenant segmentation, least-privilege access, logging and anomaly detection, data minimization and secure deletion, affected-record identification, individualized notice, compliance validation, victim assistance, and safeguards for Ledger support and Ledger Recover verification workflows. ## Litigation notice The complaint contains allegations only. No findings have been made, and no class has been certified. Consult the authoritative PDF for the complete filing.