Ledger Hardware Wallet Users Targeted in Sophisticated Mail-Based Phishing Scam
Scammers are exploiting data from Ledger’s 2020 breach by sending physical letters impersonating the company. The fraudulent correspondence, complete with official branding and unique reference numbers, instructs recipients to scan a QR code and input their 24-word recovery phrase under the guise of a "critical security update." Failure to comply threatens restricted access to crypto funds—a classic social engineering tactic.
This escalation from digital to physical phishing demonstrates attackers’ increasing sophistication. The letters’ authenticity suggests access to compromised user data, likely tied to Ledger’s 2020 security incident where 1 million email addresses were leaked. Hardware wallet users are advised to verify all communications directly through official channels.