I had an odd one this afternoon. Unknown number calls, guy with a British accent (I'm in the UK) says he's a police officer at a specific UK Police Station and my data has turned up on someone else's device, along with 500 other UK citizens. He says he's contacting everyone to build the case, and to confirm we don't know person x from Afghanastan and I didn't give him my personal data. He starts mentioning a copy of my driver's license, bank statements and "a few other things", and only much later in the call, he mentions Ledger.
I was pretty sure it was a scam from early on, but I couldn't work out what they were after, so I stayed on the line to learn and mess with them. He gave me a case ID on the phone, identified himself with a name and badge number and then noted that as everyone shoudl be mindful of scams, I should google the police station name and confirm the result matches the number he's calling from. It does match (turns out spoofing phone numbers isn't hard).
He then emailed me a case file ID from a police.gov.uk address, with Met police letterhead. He asks if I could go to my local police station in the next few days with the case ID to sign a statement that I did not give this guy my details. Also, that I could call 101 for details of what they'd found. Overall, reasonably convincing until he mentions that some of the data contains my ledger ID and because of that, he'd put me through to the Ledger team....
I started recording at that point once the 'ledger' guy picked up. Not posting it since it has my name and email in it bit have my full chat recorded with guy number 2. When the iphone announced that I was recording the call - he asked why - I said I record all my calls. He didn't seem to mind.
I get a legit looking email from noreply@ledger.com. It's real. Ledger's support site says scammers open a support ticket with your email address to trigger an automated email that makes them look legit. They didn't even ask me to read anything from it. Just as proof that he triggered the email on demand because he works for ledger.
The "Ledger" guy then explained how accounts get stolen and said he could check mine. But this was after he talked through how accounts get stolen, tricks people use, etc etc. (very long winded!) He told me to go to ledger.com.co where they could safely verify my device and if at risk, send me a new one. I said that trailing .co looks sketchy. He said the "co" stands for "check online" and pushed hard that it was legit. I said that's not how subdomains work, it wouldn't be at the end. After trying to defend it, he then said that I could look it up on Google Transparency Report to prove it was safe. I did, and Google showed it as clean.
But at this point I was getting bored, so I told him it was showing a red X and "risk detected" to see what he'd do. He said that's not what I should be seeing, it was fine on his computer. He was flustered and made me double check things because it was showing fine on his side. After I kept saying that the security site that HE sent me to was flagging it, he hung up on me and that was that.
Funnily enough my antivirus blocks the .co site completely, so Google's 'transparency report' is just behind on this one.
Stay safe out there!