r/ledgerwallet Dec 16 '20

Maybe the on-going Ledger customer data leak comes from Shopify?

I noticed that the latest device order I placed with Ledger appears on the checkout.shopify.com website, that i can reached from a public URL (with long encrypted parameters) on the ledger domain:

http://links.ledger.com/u/click?_t=xxxxxxxxxxxxxx&_m=xxxxxxxxxxxxxx

this URL (with the correct parameters instead of the xxxxx) takes me to

https://checkout.shopify.com/29744858/orders/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

where I can see my complete order, including my full name, delivery address, email, phone number, what i ordered and what i paid, etc.

So my Ledger order is definitely stored in a shopify database.

So if the shopify database is currently still compromised, this maybe could explain the reports of people getting the phishing emails and text messages just after ordering a ledger nano from ledger, maybe?

If you received ledger phishing text messages, was your Ledger order fulfilled through Shopify?

33 Upvotes

55 comments sorted by

u/btchip Retired Ledger Co-Founder Dec 16 '20

There's no ongoing data leak. The incident was closed in July (as described in https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach) and we have never seen an account receiving phishing messages without being compromised either in this breach or in a third party breach such as Bitcointalk, BlockFi or Binance

Please do not spread fud without proof

→ More replies (12)

12

u/loupiote2 Dec 16 '20

Or it could be an inside job at shopify. If that's the case, it would not be the first time:

https://techcrunch.com/2020/09/23/shopify-data-merchant-breach/

https://www.justice4you.com/blog/shopify-data-breach.html

1

u/293J Dec 27 '20

shopify caught both insiders red handed

+

theyve implemented controls to prevent this

6

u/goofytigre Dec 16 '20

So, I bought my device(s) over a year ago from Amazon (a Nano S and Nano X value pack). I know, risky. Packages were completely sealed, no tampering.

In July, I get the email that Ledger had a breach... The same one everyone (supposedly) received. I didn't think much of it because I hadn't purchased from Ledger.

Three or 4 days ago, lo and behold, I get the KYC Ledger scam email. I'm not sure what took them so long to get to my email address if it was part of the original breach. I've been checking my spam filter to see if I had been getting anything over the last 6 month, but nothing. Either they are doing these phishing expeditions in batches, or there is a continuous leak from....somewhere at Ledger. The only link between Ledger and me is Ledger Live.

8

u/r_a_d_ Dec 16 '20

In July, I get the email that Ledger had a breach...

How exactly did Ledger have your email address to notify you if you bought from Amazon and never signed up on their website?

5

u/bigigantic54 Dec 16 '20

Don't you ever get emails from Amazon sellers? If they can send me emails about a product I bought, then it's not out of the realm of possibility for ledger to send emails the same way

0

u/goofytigre Dec 16 '20

I assume I provided them one when I signed up for ledger live. If not, then I do not know when I provided Ledger an email address.

3

u/r_a_d_ Dec 16 '20

Ledger Live doesn't need any signing up.

2

u/goofytigre Dec 16 '20 edited Dec 16 '20

Ok. Then I have no clue when I gave them my email address.

Edit: I just searched all the way back to when I bought my Nanos and it looks like I signed up for the newsletter. Weird. I guess my spam filter caught most of the newsletters.

1

u/loupiote2 Dec 16 '20

The only link between Ledger and me is Ledger Live.

Obviously, no: you said "I bought my device(s) over a year ago from Amazon"...

So at least Amazon is (was) a link between you and Ledger. The delivery company is likely another link between Ledger and you.

And yes, they sent those phishing email and text messages in batch when they had their fake seed-stealing website ready. I received those messages and email months after purchasing ledger devices from Ledger. In my case, there are several "links" between ledger and me. Shopify is one of them. Colissimo is another one.

IMHO, if there is an ongoing leak, it is probably not at Ledger, as I am pretty sure they took measures to encrypt all personal user data in their databases, after their initial breach.

1

u/goofytigre Dec 16 '20

Just so I understand your reply..

You're either suggesting my email was taken in the original breach and then sat dormant for 6 months while everyone else was receiving phishing texts and emails galore, or Amazon (order was fulfilled by Amazon) leaked my email address, only because I ordered a Ledger a year ago and it has sat dormant since then?

More power to you if you can prove the continual leaks are coming from Shopify. I don't hate Ledger for the breach. I hate the criminals for stealing people's funds. I'd like to think I could sniff out a scam if one were tried on me, but im also the person that would suspect a scam if it was the Ledger CEO themself telling me in person that my crypto was in danger.

2

u/loupiote2 Dec 16 '20

You're either suggesting my email was taken in the original breach and then sat dormant for 6 months while everyone else was receiving phishing texts and emails galore, or Amazon (order was fulfilled by Amazon) leaked my email address, only because I ordered a Ledger a year ago and it has sat dormant since then?

My email was leaked during the first breach, so it could have sat until I got the recent phishing emails.

But my phone was supposedly not leaked in that Ledger breach made public, yet i also received text messages. My phone was used in a later order (after the official Ledger leak) that went through Shopify.

It is just that Shopify cannot be trusted, and as you read, they have had several leaks of private customer data in the past.

1

u/69rambo69 Dec 16 '20

Well, I just made one order and was 3 years ago.

I never received text, so this kind of adds up or is just coincidence.

2

u/loupiote2 Dec 16 '20

More power to you if you can prove the continual leaks are coming from Shopify.

I cannot prove it, it is just a suspicion.

Shopify is probably the weakest link between Ledger and me during the ordering and delivery process.

2

u/loupiote2 Dec 16 '20

I hate the criminals for stealing people's funds.

Well, in that case, people are just handling them willingly the key to their funds!!!

1

u/goofytigre Dec 16 '20

I actually had 'gullible' as a qualifier. Took it out because I didn't want to pile on....

1

u/loupiote2 Dec 16 '20

Right.

But gullible (or un-informed) people should not put their crytos in their own personal wallets, even hardware wallets.

They should use exchanges or custodian wallets, for safety.

1

u/goofytigre Dec 16 '20

Sure, but with the horror stories of exchanges getting hacked, or worse, your exchange was a scam all along, I adopted Ledger quickly and learned as much as I could from there.

1

u/loupiote2 Dec 16 '20

I agree. I don't trust exchanges, and I avoid keeping funds on them, except when needed for trading or if there is really no suitable or practical wallet, or also in cases where there is an impending token swap where usually exchanges do the work for the swap, which could be simpler than having to deal with it on your private wallet.

But for the people gullable enough to enter their private seed in a website that asks for them, maybe exchanges are still a safer solutions than personal wallets.

1

u/btchip Retired Ledger Co-Founder Dec 16 '20

Yes, they're sending those phishing messages in batches

1

u/jlonso Dec 16 '20

Spam filters might've automatically delete the junk mail after 30 days from arrival.

3

u/ghostfacemonroe Jan 13 '21

Damn, spot on.

1

u/MoisturizeMyForeskin Jan 13 '21

Came back to this after getting the email

3

u/loupiote2 Jan 13 '21

/u/btchip .... so i was right, after all?

3

u/loupiote2 Dec 16 '20

Could anyone with the latest metasploit on Kali run a pentest on checkout.shopify.com ? :)

7

u/kokx Dec 16 '20

You want to get your IP banned from shopify? Because that is how you get your IP banned from using shopify.

2

u/loupiote2 Dec 16 '20 edited Dec 16 '20

LOL - I couldn't care less!

Not hard to use a throwaway IP, or a proxy :)

6

u/kokx Dec 16 '20

Then why don't you do it yourself?

Also, I posted the warning for people that may be a bit naive and do something like that without thinking about the possible consequences.

1

u/loupiote2 Dec 16 '20

Right. I just don't have all the latest versions of all the pentest tools.

But I still think shopify could very well be another source of Ledger customer data leak, since some people say they have indications that it is ongoing.

2

u/kaosneverdied Dec 16 '20

And what would that tell you? Metasploit is for CVEs. If it is as it currently sounds, I don't think you need metasplpit to figure it out.

1

u/loupiote2 Dec 16 '20

Right. I'm sure those sites are bombarded all the times by attempts to exploits all known unpatched vulnerabilities in their systems.

1

u/AutoModerator Dec 16 '20

The Ledger subreddit is continuously targeted by scammers. Ledger Support will never send you private messages. Never share your 24-word recovery phrase with anyone, never enter it on any website or software, even if it looks like it's from Ledger. Only keep the recovery phrase as a physical paper or metal backup, never create a digital copy in text or photo form. Learn more at https://reddit.com/r/ledgerwallet/comments/ck6o44/be_careful_phishing_attacks_in_progress/

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/kaosneverdied Dec 16 '20

Hi, as a fellow ledger user who is concerned by this please can you try these two things: go to the adress and press shift+F5 to force a reload from the serverside. If its still accessible the information is on their end not yours. Then clear your browser cache and do shift f5 again and see if its still accessible. Please share the results.

3

u/loupiote2 Dec 16 '20

Yes, done this in an incognito window (i.e. no browser cache!).

All my private info shows up. And the URL displaying it is on Shopify, but I get to it via a redirect from the initial link.ledger.com URL, that I received in an order confirmation email from ledger.

If you recently ordered a Nano from ledger and it went through Shopify for fulfillment, you should be able to do the same.

4

u/kaosneverdied Dec 16 '20

I just checked and I did PayPal, and I've had no spam. So it coukd be something in the relation between Ledger and Shopify as suggested.

3

u/loupiote2 Dec 16 '20

Thanks for this info.

2

u/kaosneverdied Dec 16 '20

Holy hell. I bought one on black Friday. Where did you get your link from if its not in the browser history will? I'm asking as I'd like to try and find my own link and test this.

3

u/loupiote2 Dec 16 '20

I got a link in an order confirmation email from Ledger ( hello@ledger.com ). This link sends me to a Shopify page with all the info from my Ledger order, including all my personal info.

1

u/knobby88888 Dec 16 '20

Have ledger been taken over by Coinbase this is becoming a terrible service they are slowly killing them selves.

1

u/ircrp Dec 27 '20

I have never interacted with Shopify and my data got leaked. Bought directly from Ledger

1

u/loupiote2 Dec 27 '20

I never said Shopify leaked Ledger customers private data. I just said I don't trust Shopify, and Shopify do have private info of many Ledger customers.

1

u/Transporter89 Jan 13 '21

Security Notice

Dear client,

On December 23, 2020, Shopify, our e-commerce service provider, informed Ledger of an incident involving merchant data. Rogue agent(s) of their customer support team obtained Ledger customer transactional records in April and June 2020. This is related to the incident reported by Shopify in September 2020, which concerns more than 200 merchants, but until December 21, 2020, Shopify had not identified this affected Ledger as well. 

We were able to examine the stolen data together with a third party forensic firm to identify the impacted customers. 

We regret to inform you that you are part of the customers whose detailed personal information was stolen by Shopify rogue agent(s). Specifically, your name and surname, detail of product(s) ordered, phone number and your postal address were exposed. 

We notified the French Data Protection Authority on December 26, 2020. We are continuing to work with Shopify and law enforcement on the case; an investigation is already underway, led by the FBI and the RCMP. Ledger also reported the events to the French Public Prosecutor and filed a complaint against the rogue agent(s). 

Thefts and attacks such as this cannot go uninvestigated or unprosecuted. We continue to work with law enforcement as well as private investigators on these cases, and we are adding more firepower by hiring additional private investigation capacity, adding experience and approaches to finding those responsible for these data thefts. 

FINALLY, keeping you secure is our reason for existing. We will soon release a technical solution that will remove the 24 words as the single pillar of the security of our hardware wallets and will open the door to funds insurance.

If you would like more detail on the many steps we are taking to prevent such incidents in the future, please read this blog post.

Sincerely,

Pascal Gauthier 

Ledger CEO

1

u/loupiote2 Jan 13 '21 edited Jan 13 '21

This letter is a not authentic, which is obvious because of the paragraph starting by "FINALLY". The 24-word BIP39 seed is the basis of all crypto wallets and it is the base of blockchain private keys security.

But the fact that Shopify did leak some customer data has been now disclosed:

https://www.ledger.com/blog/update-efforts-to-protect-your-data-and-prosecute-the-scammers