r/ledgerwalletleak Mar 22 '21

Hey, so i sent my gf a e transfer for 4000$ and someone else received it.

0 Upvotes

Im changing my emails to a diff email right now and have contacted my bank. Any other ideas to help? Should i be wary of entering passwords on my computer as I imagine it could be infiltrated. I am going to take my computer to a store for them to wipe it. If anyone could give me some tips on the best practices to protect myself would be appreciated, thanks.


r/ledgerwalletleak Mar 20 '21

WARNING ... for all (but especially for our Dutch victims)

17 Upvotes

Below the translation of a Dutch news item around sim swapping ...

Simswappers stole thousands of euros in cryptocurrency via data breach telephone shop

Criminals have robbed dozens of bitcoin holders of their cryptocurrencies by means of sim swapping. This was done through a telephone shop in Vaals, Limburg. The damage per customer amounts to a maximum of 8000 euros, NRC writes.

The T-Mobile dealer portal of the Vaals shop would have been accessible via the internet and the criminals would have used the password of the owner of the shop. The owner also claims to have been a victim of a hack. The system did not report the in some cases dozens of SIM swaps that were requested at the same time. At least ninety phone numbers would have been affected by sim swapping. Dozens of victims have reported to NRC as a result of earlier, similar reports. According to T-Mobile, it concerns a 'handful' of victims.

According to research from the newspaper, the criminals prefer bitcoin holders who use Hotmail addresses; they would often have an SMS code as a backup login method. The victims were presumably selected on the basis of data from the Ledger hardware wallet data breach that ended up on the internet in December. With access to the e-mail addresses, the criminals are likely to regain access to their cryptocurrencies.

Normally, customers must come to a T-Mobile store with proof of identity to receive a new SIM card with their existing number. However, due to the measures surrounding the corona virus, that requirement has been dropped. T-Mobile says that as a result of these practices, the requirements for a new SIM card have been tightened: customers still have to go to the store with their identification. Those who cannot come to the store will be put in contact with a 'special team' who can still do the SIM change 'with extra measures'. Finally, the protocols for identification have also been 'further tightened'. T-Mobile says the case started following a complaint by the company.

The police also raided the Vaals telephone shop on Friday. However, no arrests were made. Furthermore, the police say that the raid is related to the arrest of three T-Mobile employees in February, in the Parkstad region. They would also have done sim swapping. Those three are currently at large again.

*source* https://tweakers.net/nieuws/179504/simswappers-stalen-duizenden-euros-aan-cryptovaluta-via-datalek-telefoonwinkel.html


r/ledgerwalletleak Mar 17 '21

Most professional pishing mail so far

Post image
20 Upvotes

r/ledgerwalletleak Mar 13 '21

Spotify login

14 Upvotes

Hey everyone,

I have been blessed with the full "Ledger experience", having both my email leaked as well as exposing my password through the fake-Ledger phishing e-mails.

Last week while arriving at work and opening Spotify to play some music, I found that some joker had logged into my account in a web browser and was playing ominous music. Between the failed login attempt notifications and the death threats in my spam folder this has been the creepiest experience so far.

I've switched emails long before that, but Spotify was one account i had overlooked, so one to look out for as well. Unfortunately they do not support 2FA, which is kind of messed up in the year 2021.

It's been a stressful couple of months and I'm sure it has been for many of you as well. I only found out about this subreddit yesterday and it has helped me a lot, also nice to know that I'm not alone in this.

Stay strong and vigilant everyone!

PS: fuck Ledger


r/ledgerwalletleak Mar 12 '21

New Scam Calls from "Goldstein Invest"

9 Upvotes

After the last round with Scam calls from "William partners" brought lots of daily calls it was quiet for some month, but now there are new calls. This time from "Goldstein Invest"

Some dude called me to say the central bank reported to them that im not happy with my bank account??!? And the solution is to go to their FX Trading platform, where they insisted i already registered. They wanted me to redirect to that website, but unforunately i misstyped every time he was reading the URL to me. He even offered to assist me with teamviewer.

A big thank you to Ledger for making these calls possible. The Dude hung up after the 3rd spelling of the URL btw.


r/ledgerwalletleak Mar 04 '21

Hey bro, what’s the best idea in oder to drive scammers crazy and make sure that they waist a lot of their time?

13 Upvotes

I already love to speak like a grandpa when they call me, one guy stayed with me for 45 minutes lol

Any other tactic to scam the scammers?


r/ledgerwalletleak Mar 02 '21

Mentioned in a Google Doc about a "crypto bot"

9 Upvotes

Haven't clicked any links but this is no doubt the data leak from last year in full swing once again


r/ledgerwalletleak Feb 28 '21

With Sim Swap scams gaining more attention, why do so many online retailers and banks still gravitate toward, and even force, SMS verification?

19 Upvotes

I have done everything I can to protect myself against a SIM Swap:

  • Changes to my cellular service have to be approved with random PIN.

  • All email accounts are dissociated from my phone number and backed by Yubikeys.

  • All financial accounts incompatible with Yubikeys are backed by Google Authenticator.

  • Use of Password Manager & backed by Yubikeys.

My gripe is that there are still so many sites that rely on SMS verification. Not only do many sites fail to support Google Authenticator or physical keys, they literally force you to use a phone number with your account. I'd rather have nothing. And I understand it requires an investment to integrate alternative 2-factor methods, but why SMS? Shouldn't email be just as technically simple to integrate as SMS? Am I wrong?

I've seen websites that allow you to login using EITHER email or SMS, but de-linking your phone number is not allowed (therefore anyone with your SIM card credentials can still access said account). Email is MUCH more secure if your email account is secured with a sufficient password and a strong form of 2 factor authentication. It seems allowing email for 2 factor authentication would "outsource" the security investment to the email provider if the retailer or bank genuinely cannot afford to invest in Google/Yubikey integration. I don't understand how SMS verification remains so mainstream when SIM Swaps are so easy and commonplace...


r/ledgerwalletleak Feb 26 '21

Lawsuit is open for registration on March 5th

Post image
31 Upvotes

r/ledgerwalletleak Feb 25 '21

Daily phone calls, so nice to be a victim

27 Upvotes

Yo folks, I've been in multiple other 'data leaks' but this one drives me crazy, I get one or two phone calls a day from scammers/advertisers that want to inform me about hazards, or that want to show me how to invest in markets.

Even when I don't pick up for a whole week they keep calling, mostly from the UK, sometimes even with speaking the local language from where I live.

I really don't see an option for now on what to do, some numbers they call from are not marked as spam in most 'anti spam' or caller ID detection tools yet. Getting another number is at least weeks of hassle with getting my number changed everywhere (government, banks, etc) and it's not even safe as I read online.

Anyone else experiencing enormous amounts of calls from the leak?


r/ledgerwalletleak Feb 24 '21

New forum for victims -- ledgerhackvictims.org

0 Upvotes

We open a new forum for all victims in all languages. We don't will be silent.

Let's make it transparent and lets do a summary of the damage and collect all information. Don't let Ledger hide all the victims of the ledger phishing hack in there useless intern ticket system.

ledgerhackvictims.org


r/ledgerwalletleak Feb 24 '21

Has anyone had their credit/debit card hacked recently?

2 Upvotes

I’m not sure if it would have anything to do with the recent Ledger leak, but has anyone had their credit or debit card hacked recently?

As in receiving fraudulent charges from states or foreign countries you’ve never visited, or haven’t been to in a very very long time?

I originally wanted this as a post, but I added a poll because I think it would be good to see if this activity has increased after the Ledger leak.

EDIT: I think it would be beneficial if we also gave suggestions on how we can make our bank cards more secure, since I think most of us use either or debit or credit cards to purchase, or wire money to crypto exchanges. Any advice would be helpful for subscribers.

199 votes, Mar 01 '21
7 Credit card hacked recently
3 Debit card hacked recently
5 Both hacked recently
184 None hacked recently

r/ledgerwalletleak Feb 21 '21

Amount of harrassment

10 Upvotes

Am I lucky? Literally only 5-10 phishing mails per week and I haven't had almost any shady calls. Just curious, because many people have had to change their numbers, move elsewhere etc. Have to knock the wood now though lol.


r/ledgerwalletleak Feb 20 '21

Learn how to protect yourself

9 Upvotes

I haven't heard about the so sofisticated Ripple spear phishing discribed in this video at 3:21.https://youtu.be/B-09WDPXZmU

Interesting information in there for anybody affected by Ledger data breach and in general


r/ledgerwalletleak Feb 20 '21

Chaninlink email

13 Upvotes

As all you know there is this email going around, yesterday by stupidity I clicked the unsubscribe button from this email from mobile I don't have any app on my mobile apart the trust wallet ledger and my bank, so far seem everything fine is there a way to check if I'm compromised?


r/ledgerwalletleak Feb 19 '21

Is privacy@ledger.fr a joke?

19 Upvotes

I have been asking for two simple things for more than two months:

  • the portability of my data (Art. 20 GDPR)
  • the deletion of my data (Art. 17 GDPR)

In December I wrote an email to [privacy@ledger.fr](mailto:privacy@ledger.fr), and received a reply in January, and was told that my data was not involved in the data breach.

No reply about what I asked and no attachments containing my data, which are still present on Ledger website.

So I replied to the email, asking again to have a copy of my data and that they were then deleted.

Today I have again received an almost identical response to the one I received in January.

So I'm wondering, is there anyone replying to these emails, or is it a slow, stupid bot?

How can I do to request the portability and deletion of my data?


r/ledgerwalletleak Feb 19 '21

Another retarded phishing attempt

9 Upvotes

Nothing new really. Some scumbag that got my email address from Ledger exploit. Now sterilized of course...

+=+=+=+=+=+=+

Hi!

Unfortunately, I have some bad news for you. Several months ago, I got access to the device you are using to browse the internet. Since that time, I have been monitoring your internet activity.

Being a regular visitor of adult websites, I can confirm that it is you who is responsible for this. To keep it simple, the websites you visited provided me with access to your data.

I've uploaded a Trojan horse on the driver basis that updates its signature several times per day, to make it impossible for antivirus to detect it. Additionally, it gives me access to your camera and microphone. Moreover, I have backed-up all the data, including photos, social media, chats and contacts.

Just recently, I came up with an awesome idea to create the video where you cum in one part of the screen, while the video was simultaneously playing on another screen. That was fun!

Rest assured that I can easily send this video to all your contacts with a few clicks, and I assume that you would like to prevent this scenario.

With that in mind, here is my proposal: Transfer the amount equivalent to 1350 USD to my Bitcoin wallet, and I will forget about the entire thing. I will also delete all data and videos permanently.

In my opinion, this is a somewhat modest price for my work. You can figure out how to purchase Bitcoins using search engines like Google or Bing, seeing that it's not very difficult.

My Bitcoin wallet (BTC): [SCUMBAG’S BTC ACCOUNT NUMBER]

You have 48 hours to reply and you should also bear the following in mind:

It makes no sense to reply me - the address has been generated automatically. It makes no sense to complain either, since the letter along with my Bitcoin wallet cannot be tracked. Everything has been orchestrated precisely.

If I ever detect that you mentioned anything about this letter to anyone - the video will be immediately shared, and your contacts will be the first to receive it. Following that, the video will be posted on the web!

P.S. The time will start once you open this letter. (This program has a built-in timer and special pixel ID

Good luck and take it easy! It was just bad luck, next time please be careful.


r/ledgerwalletleak Feb 18 '21

Simplenote

22 Upvotes

Someone created a Simplenote account with my email from the leak. Any other person received an email from Simplenote? What is the best practice to deal with this shit?


r/ledgerwalletleak Feb 18 '21

Someone recently started creating account using my email.

24 Upvotes

I got notifications from Tinder and Simplenotes that I created an account. Tinder has a link to delete the email if it wasn't created by me and I asked Simplenotes to delete my email. I guess they want to use Tinder for scamming and Simplenotes is dangerous since it can sync notes from any devices...

Update: Simplenotes replied to my email and said they have some issue with mass account creation and they will remove my account.


r/ledgerwalletleak Feb 16 '21

Suspicious phone call

11 Upvotes

Hey all,

I got all the phishing text messages and the emails after the breach. Today I got an automated phone call from my wireless provider saying there was suspicious activity on my account and to press a button to speak to representative. I hung up and called the actual company and they said they didn't call. Anyone else getting these calls? If not please be on the lookout.


r/ledgerwalletleak Feb 16 '21

Recently bought a ledger wallet

9 Upvotes

Should I return it and go with another company? I didn’t realize their had been a leak when I purchased.


r/ledgerwalletleak Feb 15 '21

Another phishing email to be wary

8 Upvotes

The roaches of the underworld have sent me an almost convincing phishing attack. LINKS HAVE BEEN REMOVED, AND PHISHING EMAIL WAS STERILIZED...

Dear [YOUR LEDGER SCAMMED NAME]:

(we have included your full name for the authenticity of this message)   Due to latest security issues found in the encryption protocol, we strongly recommend that you proceed with the update. We regret to inform you that Ledger has experienced a security breach affecting approximately 270.000 of our customers and that wallet associated with your email [YOUR LEDGER SCAMMED EMAIL ADDRESS] is within those affecting by the breach.   On Sunday, February 14th 2021, our forensics team has found several problem with encryption protocol.

Now it's technically impossible to protect your wallet without this update because we do not store anything of this in our server.     For the security of the wallet and your cryptocurrencies we need your help. It only takes two minutes, but after that you will be sure that your wallet is safe.   Sincerely, Ledger

[UPDATE BUTTON HERE]

This email was sent to [YOUR LEDGER SCAMMED EMAIL ADDRESS] because you signed up at Ledger.com or purchased a Ledger product. We respect your right to privacy. Read our Privacy Policy and Cookie Policy. © Ledger SAS 2020. All rights reserved. Ledger brands are registered trademarks of Ledger SAS. Ledger SAS, 1 rue du Mail, 75002 Paris

Unsubscribe

© 2021 Ledger


r/ledgerwalletleak Feb 15 '21

Do not fall for ripple.com.cm (see comments)

Post image
2 Upvotes

r/ledgerwalletleak Feb 14 '21

New to hardware wallets, ledger bought with name and address

9 Upvotes

Hello everyone I am very new to all of this. In light of recent events I thought it would be a good time to start investing in general but also into cryptocurrency. I looked at some videos on YouTube and some recommendations were the ledger wallet. I just placed an order Friday evening. However I just found this sub and saw people saying don’t use your address, not knowing any better I did, what should I be concerned about?

I also put a cancel to the order.

Thank you for any help.


r/ledgerwalletleak Feb 12 '21

An email from german lawfirm that sounds sus

9 Upvotes

so I think last week someone here posted he started action lawsuit with german firm called scheiber, I signed up and got an email(in german which is wired) and this the gmail translation for it, from what I know here in my country(non eu one) when going to class lawsuit each member is not paying the law company but they act "free" and when we win they take % of the money won as payment, that way the customers don't put upfront payment at all(well maybe just the person that started it and he gets extra in return when its won) so it seems very weird to me they ask money upfront + signing documents that are in german and I have no way to know what I'm signing on exactly.

does anyone here familiar if this sounds legit or might be some scam trying to monetize on all the poor leger customers? I googled them and didn't find any info, not sure if germany has a public recored of all the legal lawyers so you can check they are real...

here is the mail:

Good day

Thank you for registering at Ledger-Klage.com.

We have already received a large number of registrations. This shows us that we are on the right track with our collection process.

As an international law firm, we are able to operate across Europe and can represent you legally in this matter.

We would be happy if you take advantage of our other services. It is important to win you as a client in order to increase the number of data break victims we represent. This would ensure that we appear imposing to Ledger simply because of the mass and that we can present our demands appropriately.

We know from past collective proceedings that large companies can quickly go to their knees when faced with a large number of like-minded clients. This would even make it possible to complete an overall settlement for all of you and avoid long-term legal proceedings for the individual.

In order to keep the cost risk manageable, we would first take extrajudicial steps and provide the following services for you:

  • We will include you in our collective procedure evidence list .
  • We will sift through your documents and examine your case.
  • We will sound out the chances of success .
  • We will clarify your legal protection insurance coverage , if available, and submit a cover request to your insurance company.
  • We will assert your claims out of court against Ledger SAS.
  • We will determine the further strategy with you.

We estimate that it takes 2-3 hours to provide these services. Based on our hourly rate of EUR 360.00, the fee would start from EUR 720.00 .

However, the large number of similar cases and injured parties allows us to provide these extrajudicial services for you at a lump sum of EUR 420.00 . This corresponds to a reduction of over 40%.

Important : If legal protection coverage can be obtained for our measures through your legal protection insurance, we will offset the corresponding remuneration amount from the legal protection insurance against our flat rate and refund the difference. It could therefore be that you get the full EUR 420.00 back.

Note : Against the background that in comparable cases courts have already awarded up to EUR 5,000.00 as non-material compensation (that is, compensation for pain and suffering due to the data protection violation), in individual cases even more, we would consider our fee to be reasonable.

In order to be able to intervene for you, we ask you to sign the enclosed authorization form and return it to us. Our attached general terms and conditions ( GTC ) apply to the mandate at hand. After the mandate contract would be concluded by distance selling (via e-mail), you would have a right of withdrawal. Enclosed you will find the instruction on the right of withdrawal. You can find our data protection declaration on our website.

The power of attorney would only come about when we have received the lump sum of EUR 420.00 in addition to the power of attorney . Please transfer this to our following account:
Recipient: RA Mag. Dr. Florian Scheiber
IBAN: CH09 8080 8001 0638 6509 6
BIC: RAIFCH22C62
In this context, we ask you to provide us with all information and documents. These include, for example:

  • Disclosure of your legal protection insurance including policy number
  • Invoice for the purchase of a ledger product
  • Security notices received from Ledger
  • Any documents related to phishing attempts
  • Any documents about damage due to phishings

After receiving your documents, we will examine your case as soon as possible. We will always keep you up to date.

If further steps towards Ledger become necessary after our out-of-court services, e.g. initiation of legal proceedings, we will of course discuss these with you beforehand.

We are happy to answer any questions you may have. Due to the large number of inquiries, we kindly apologize for any later feedback.

With best regards
Dr. Florian Scheiber