# Ledger / Global-e Data Incident Class Action - Hall Attorneys, P.C. Canonical page: https://hallattorneys.com/ledger-data-breach Case docket: https://hallattorneys.com/dockets/ledger Complaint PDF: https://hallattorneys.com/dockets/ledger/01-complaint.pdf LLM/GEO source file: https://hallattorneys.com/llms-full-ledger-data-breach.txt Last reviewed: August 25, 2026 ## Summary Hall Attorneys, P.C. and Milberg PLLC filed a putative class action on August 24, 2026 in the United States District Court for the Southern District of New York against Global-E Online Ltd., Global-e US Inc., Ledger SAS, and Does 1-10. The matter is No. 1:26-cv-07222, ECF No. 1. The complaint alleges that a December 2025 compromise of a Global-e cloud system exposed shopper order data for several brands, including information associated with some Ledger.com purchases processed through Global-e as merchant of record. It alleges defendants failed to prevent, adequately disclose, and reasonably mitigate the foreseeable use of Ledger customer and order information in highly targeted cryptocurrency-theft schemes. The complaint contains allegations only. No findings have been made, and no class has been certified. ## Public case snapshot - Public label: Ledger / Global-e Data Incident Class Action. - Case number: 1:26-cv-07222. - Court: U.S. District Court, Southern District of New York. - Filed: August 24, 2026. - Docket entry: ECF No. 1. - Defendants: Global-E Online Ltd.; Global-e US Inc.; Ledger SAS; Does 1-10. - Counsel: Milberg PLLC; Hall Attorneys, P.C. - Jury trial demanded: Yes. - Complaint length: 39 pages. - Complaint posture: allegations only; no class certified and no findings made. ## What the complaint alleges happened The complaint alleges that Global-E Online Ltd. identified unauthorized access to one of its cloud systems in December 2025. It says Global-e later stated that names and contact information were impacted. The complaint says Ledger disclosed in January 2026 that the affected system contained shopper order data for several brands and that some affected records pertained to Ledger.com purchases processed through Global-e as merchant of record. The lawsuit alleges that identifying a person as a Ledger customer can reveal that the person likely holds cryptocurrency. It alleges names, contact details, shipping information, purchase timing, product or device details, and related customer information can help criminals select targets and make fraudulent calls, emails, websites, or support interactions appear legitimate. The complaint describes a February 2026 criminal-forum advertisement for a purported partial Ledger / Global-e dataset. It treats the advertisement as threat intelligence warranting discovery, not as conclusive proof of the exact record count, fields, or provenance. The complaint alleges that Ledger had warned by May 13, 2026 about impersonation campaigns in which scammers triggered genuine Ledger support messages and invoked Ledger Recover or CoinCover to make unsolicited calls appear legitimate. ## Direct wallet-compromise distinction The complaint states that Ledger hardware, software, private keys, recovery phrases, and blockchain balances were not reported as compromised in the Global-e incident. It likewise notes statements that payment-card data and account credentials were not accessed. The lawsuit instead focuses on shopper-order and customer information allegedly used to identify and authenticate targets in social-engineering campaigns. Never provide a recovery phrase, private key, PIN, password, or authentication code to an unsolicited caller, website, email sender, or ordinary intake form. ## Alleged targeted losses The complaint alleges two Ledger customers were targeted in 2026 with current Ledger-specific information and genuine Ledger communications. It alleges completed digital-asset thefts valued at more than US $2.6 million in total at filing-time values. The complaint does not allege that defendants participated in the criminal thefts. It also states that the current record does not conclusively identify the source of every fact used by the attackers. It alleges defendants' acts and omissions created or materially increased a foreseeable risk and that discovery should establish the relevant data lineage and causal contribution. ## Proposed classes The complaint proposes the following classes, subject to amendment after discovery: 1. North American Ledger/Global-e Data Breach Class: U.S. or Canadian residents whose personal, contact, shipping, order, purchase, device, product, price, or related Ledger customer information was allegedly accessed, acquired, exfiltrated, copied, or otherwise compromised in the December 2025 Global-e incident. 2. Targeted Impersonation Subclass: members of the proposed North American class who allegedly received an actual or attempted Ledger-, Ledger Recover-, CoinCover-, Global-e-, police-, or security-themed impersonation contact using customer-, order-, device-, service-, address-, or genuine-communication information reasonably traceable in whole or material part to defendants' systems or data. 3. Digital-Asset Loss Subclass: members of the proposed targeted-impersonation subclass who allegedly suffered a completed unauthorized transfer or theft of cryptocurrency or other digital assets as a result of the targeted impersonation. No class has been certified. ## Claims pleaded The complaint pleads five counts: 1. Negligence against all defendants. 2. Breach of implied contract against the Global-e defendants and Ledger. 3. Breach of confidence against all defendants. 4. Restitution and unjust enrichment against all defendants, pleaded in the alternative. 5. Declaratory and injunctive relief against all defendants. ## Requested relief The complaint requests certification of the proposed classes; damages; restitution; disgorgement; an accounting; declaratory and injunctive relief; interest; fees and costs; and other available relief. The requested prospective measures include independent security assessments, vulnerability remediation, merchant-tenant segmentation, least-privilege access, logging and anomaly detection, data minimization and secure deletion, identification of affected records and fields, complete individualized notice, periodic compliance validation, victim assistance, and safeguards for Ledger support and Ledger Recover verification workflows. These are requests for relief, not court orders or findings. ## Who may want to contact Hall Attorneys U.S. or Canadian Ledger customers may want to contact the firm if they: - made a Ledger.com purchase processed through Global-e; - received notice relating to the December 2025 Global-e incident; - received a Ledger-, Global-e-, Ledger Recover-, CoinCover-, police-, or security-themed contact using current customer, order, device, service, address, or support details; - received a genuine Ledger email or verification message during an unsolicited call or suspicious support interaction; - experienced an attempted or completed cryptocurrency or digital-asset theft after targeted impersonation; or - spent substantial time or money investigating, reporting, or mitigating a targeted incident. In an initial message, provide your state or province, general purchase timeframe, device or service involved, and a short description of the notice, targeted communication, attempted theft, or loss. Do not send a recovery phrase, private key, PIN, password, authentication code, complete account number, government identification, or unredacted financial records. ## Records to preserve - Ledger.com order confirmations, receipts, shipping records, product and device details, and purchase dates. - Records showing Global-e as seller or merchant of record. - Ledger and Global-e incident notices. - Support, verification, and Ledger Recover communications. - Call logs, voicemails, recordings, emails, texts, physical mail, domains, and screenshots relating to suspicious contacts. - Transaction exports, transaction hashes, wallet addresses, timestamps, and exchange-rate records. - Police, FBI IC3, exchange, insurer, support, or blockchain-analysis reports. - Records of time, expenses, professional fees, transaction costs, attempted theft, and completed loss. Never provide wallet secrets to anyone claiming to investigate the matter. ## Frequently asked questions Question: Is this a filed lawsuit? Answer: Yes. The putative class action was filed August 24, 2026 in the Southern District of New York as No. 1:26-cv-07222, ECF No. 1. Question: Who are the defendants? Answer: Global-E Online Ltd., Global-e US Inc., Ledger SAS, and Does 1-10. Question: Were wallets or recovery phrases directly compromised? Answer: The complaint states that Ledger hardware, software, private keys, recovery phrases, and blockchain balances were not reported as compromised in this incident. It focuses on the alleged misuse of shopper-order and customer information in targeted impersonation. Question: How many people are affected? Answer: The complaint does not treat any public advertisement as proof of an exact count. It alleges the class is sufficiently numerous and states that defendants' records should establish the actual number. Question: Has the court certified a class or found defendants liable? Answer: No. The complaint contains allegations only. No class has been certified, and no findings have been made. Question: Where is the complaint? Answer: https://hallattorneys.com/dockets/ledger ## Notice Attorney advertising. Past results do not guarantee a similar outcome. The complaint contains allegations only; no findings have been made, and no class has been certified. Hall Attorneys is not affiliated with Ledger, Global-e, or CoinCover. Sending information does not create an attorney-client relationship. Never share a recovery phrase, private key, PIN, password, authentication code, or other wallet secret.