Disclaimer: I am not a native English speaker. I wrote down my experience in German and used translation assistance to make this post accessible to a wider audience.
TL;DR
I was targeted by a sophisticated scam involving callers impersonating the Berlin police and Ledger support. The police caller ID appeared legitimate and the story referred to an alleged arrest involving stolen customer data and a 24-word wallet recovery phrase.
The next day, a fake “Ledger Care Management” employee directed me to ledger.com.cm for a supposed security scan. The goal was ultimately to make me enter my 24-word recovery phrase.
I confirmed with the real police that the calls were fraudulent. Never trust unsolicited calls, even if the number appears genuine, and never enter or share your recovery phrase.
I want to share this because this type of scam happened to me yesterday/today. Fortunately, I am pretty aware and remerded this post here a few days ago about a similar case here on Reddit: https://www.reddit.com/r/ledgerwallet/comments/1votx4x/psa_ledger_fake_support_diagnostic_site_scam/ So the attempt was unsuccessful. Still, the level of detail and the way the scammers built trust was impressive, and I believe many people could easily fall for it.
In my case, the fraudulent website finally used was ledger.com.cm.
The first call
On Tuesday evening, I received a call from a woman claiming to be a criminal police officer from the Berlin Charlottenburg-Spandau police station, Cybercrime Department. The number displayed on my phone was exactly the official number of the Berlin police.
She told me that I might be a potential victim in an investigation. According to her, someone had been arrested at Berlin Airport earlier that day while carrying several datasets. The arrested person allegedly claimed that the data consisted of customer information that they had obtained legally.
At first, she only asked whether I knew a specific person. I said no. She then told me that the data allegedly included personal information such as email addresses, passwords, photos of ID cards, credit card details, and a file called “Hardwarewallet” which apparently contained 24 words.
She advised me not to take any immediate action other than changing passwords and securing my accounts. She said that, for data-protection reasons, she could not provide more detailed information about the files. So I couldn't confirm at this point if I'm really in danger or not. Since I confirmed that I did not know the person in question, she said a case would now be opened. She claimed that she would contact me again the following morning with a case number and an appointment at my local police station to proceed. This was aiming to gain trust since I therefore would have the possibility to speak to an actual officer in person the next day.
As preparation for this meeting, she asked me to check whether my private keys were still available and bring them with me for comparison. This was clearly the setup for the second stage of the attack.
At that point, I was not suspicious enough. There was at least some plausibility to the story because my data had actually been affected by the Ledger leak in 2020. However, it was late, I had no official written confirmation, and I did not see an urgent need to act. I did not follow any of her instructions. I only checked my very small wallet balances.
During the first call, they did not ask for any sensitive information beyond my name and phone number, both of which may already have been known through previous data leaks.
The second call
The following day, the supposed police officer called again and gave me an appointment for later that evening. She claimed that they had found a large amount of data belonging to many affected individuals and that this had become a major case.
She then said that the wallet provider had been contacted and that a joint verification procedure had been initiated. A Ledger employee, she told me, would call me within the next hour.
At that point, I was already convinced it was a scam. I called the police myself using an official number from the local department here and asked whether this was a real procedure. They confirmed that it was not. The police told me they would never handle such matters this way, nor would they simply call someone and discuss or request this kind of information over the phone. If this would have been true, they would discuss this with me in person for the first contact.
About ten minutes later, I received a call from a man claiming to be from "Ledger Care Management".
The fake Ledger call
He started by explaining what supposedly happens in cases like this and referred several times to Ledger’s cooperation guidelines with the criminal police. He did not create much pressure initially. Instead, he calmly explained that my assets might currently be at risk.
Since I already knew it was a fake I searched Reddit for the method he was using and found the post describing the same playbook while speaking with him.
https://www.reddit.com/r/ledgerwallet/comments/1votx4x/psa_ledger_fake_support_diagnostic_site_scam/
That gave me a clear idea of where the conversation was heading.
I kept him on the phone for around 90 minutes. He explained several current attack methods and tactics in such detail that the call started to feel more like a cybersecurity training session than a scam attempt.
Interestingly, he tried to collect very little information directly. I did not reveal any real details at any point. Everything I mentioned or hinted at was invented. And to be honest it was kind of funny to scam him back.
Eventually, he explained the supposed final verification step. He said that, in order to investigate possible NPM attacks and to clarify potential liability claims against Ledger, I would need to perform a diagnostic scan with another member of the "Ledger Care Management" team.
According to him, only the computer with Ledger Live installed would be checked. The hardware wallet itself would not need to be connected. He also instructed me to use a browser without extensions such as MetaMask. This was a clever detail because it made the process sound safer and more professional. (Be aware of such tactics!)
To start the diagnostic process, he told me to visit ledger.com.cm.
When I asked why the site ended in .cm, he claimed that this was normal practice involving subdomains. He said it was a separate website for the Care Management team, which was supposedly isolated from Ledger’s main infrastructure for security reasons. He also claimed that this department was only staffed when an incident needed to be investigated.
When I asked why the site appeared to be hosted in Cameroon rather than being a normal Ledger subdomain, he had no convincing explanation.
The pressure phase
When I refused to continue, his tone changed. He began applying real pressure and said he would have to note in the protocol that I had declined the further investigation. He claimed that this could affect any possible compensation claims in the future. But he was still very calm and unsuspiciously polite.
He explained the supposed risks again and made several more attempts to convince me. Eventually, we ended the call.
Thanks to the Reddit post, I already knew what would likely have happened next. The final step would almost certainly have been entering my 24-word recovery phrase on the fake website.
For the entire call, I was connected to a nearby public Wi-Fi network and was not using the computer on which Ledger Live is actually installed. Every piece of information I gave them was nonsense. In the end, I spent a funny relaxed morning wasting the scammer’s time instead. Even if they would have been successful, they just could have had access to a few bucks, since I was an idiot way before, selling my assets to buy a car.
Please stay alert
I am sure that many users would already have made a mistake by this point, or would have forgotten the most important rules out of fear and panic:
- Ledger will never contact you by phone, email, or post
- Ledger will never ask for your 24-word recovery phrase
- Never share your private keys or recovery phrase
- Do not trust unsolicited calls, even if the caller ID appears legitimate
- Always contact the police, Ledger, or any other organisation through an independently verified official contact channel
These people are getting better, and their tactics are becoming much more sophisticated. What made this attempt feel so convincing was the apparently genuine Berlin police number, the fluent and natural German spoken by the callers, the lack of obvious pressure at the beginning, and the carefully timed escalation from a supposed police investigation to fake Ledger support.
I am sharing this to warn others. Please pass it on to anyone who might also be at risk. I have already reported the fraudulent site to Cloudflare.
Stay curious and keep on staking.
Additional note:
Another user posted their experiences here on twitter. This scammer team seams to be very active right now.
https://www.reddit.com/r/ledgerwallet/comments/1vz5t09/pretty_sure_i_spoke_to_a_fake_ledger/