Hardware wallet provider Ledger has once again been targeted by cybercriminals , with its users falling victim to a phishing attack . Several people shared their experiences on social media , describing the attack as particularly convincing.

The criminals sent emails to users claiming that their Ledger Wallets had been affected by a data breach affecting thousands of users. They also stated that the company’s team was not yet able to know the exact extent of the breach.
“To protect your information, download the latest version of Ledger Live and follow the instructions to set up a new PIN on your Wallet,” the email states. It then directs the user to a download link on a fake website created to steal credentials .
A Ledger user, developer Andreas Tasch, detailed the phishing attack in a tweet .
A company spokesperson revealed that an internal investigation has been launched into the attack. Ledger continued to experience phishing, with criminals “seeking to compromise the integrity and information of its customers.”
The spokesperson added, “The investigation is ongoing and we are unable to provide additional information at this time, but one thing is for sure, Ledger will never ask you to provide the 24-word recovery phrase, which is a blatant indication of a phishing scam.”
Back in June, Ledger was once again the victim of a data breach, resulting in the exposure of personal information of more than 1 million users. As CoinGeek, the company claimed that hackers accessed its e-commerce and marketing database via an API key. The company didn’t discover the breach until three weeks later, when a security researcher participating in a bug bounty reported it.
It is not known whether the two breaches are related and Ledger has not yet confirmed the fact.
