CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Ledger Faces $500M Lawsuit Over Repeated Data Breaches

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING Ledger Faces $500M Lawsuit OverRepeated Data Breaches

A $500 million class action filed in the United States against hardware wallet manufacturer Ledger has brought three successive data security failures into sharp legal focus. The suit, filed on 27 August 2026 by a Ledger user who claims to have lost close to $2 million in stolen digital assets, alleges a sustained pattern of negligence, inadequate breach response, and failure to protect personally identifiable information (PII). For accounting firms, auditors, and CFOs who rely on crypto custody tools and third-party payment processors, the case carries implications that go well beyond the hardware wallet market and are directly relevant to how any firm using crypto accounting software governs its vendor relationships.

Ledger Faces $500M Lawsuit Over Repeated Data Breaches

What the Lawsuit Actually Alleges

The complaint names three distinct security incidents and argues that Ledger's response to each was insufficient, with lessons from one breach never properly applied before the next occurred.

The 2020 Customer Database Breach

In 2020, a breach exposed Ledger customer data that subsequently appeared on an online marketplace for stolen information. The plaintiff alleges that Ledger failed to notify affected users promptly and understated the scope of the incident. Criminals who obtained that data allegedly used it to identify high-value targets, including the lead plaintiff, and to mount targeted theft campaigns against their crypto holdings.

The 2023 Phishing and Malware Attack

The second incident, in 2023, arose from a phishing attack on a Ledger employee. The complaint states that the attack led to the distribution of malware capable of redirecting crypto stored in Ledger wallets to the attackers. Again, the lawsuit contends that Ledger's disclosure was delayed and its subsequent security remediation inadequate.

The 2026 Third-Party Processor Breach

A third breach, in 2026, is noted in the source reporting as occurring when payments processor Global-e was hacked, resulting in further exposure of Ledger users' personal data. The complaint as filed does not appear to address this incident directly, but its existence reinforces the lawsuit's central thesis: that Ledger's security posture remained structurally weak across a six-year window.

The Legal Framework Being Invoked

The claim does not rest on a single theory of liability. The plaintiff asserts negligence, arguing that Ledger owed a duty of care to safeguard customer PII and breached that duty repeatedly. The complaint also invokes New York's Stop Hacks and Improve Electronic Data Security Act, known as the SHIELD Act, which imposes specific data-security obligations on entities that hold New York residents' private information and requires timely notification following a breach.

SHIELD Act Obligations at Stake

New York's SHIELD Act extends breach notification requirements to any business that holds the private information of New York residents, regardless of where the business is incorporated or headquartered. It also requires companies to implement reasonable safeguards, meaning the standard is not purely procedural. A firm can be found liable not just for failing to notify, but for failing to maintain security practices commensurate with the sensitivity of the data it holds. The lawsuit contends Ledger fell short on both counts.

The damages sought range up to $500 million, and the plaintiff is demanding a jury trial. The class, if certified, would presumably encompass a large portion of Ledger's US customer base across all three breach events.

Why This Case Matters for Firms Using Digital Asset Accounting Software

It might be tempting to read this as a consumer hardware story, but the professional implications are wider. Accounting firms, audit practices, and corporate treasury functions that hold or process digital assets interact with a layered ecosystem of vendors: custody providers, wallet infrastructure, payment processors, and the crypto accounting software or digital asset accounting software that sits across all of them. Each of those vendors is a potential breach vector, and as the Ledger case shows, a downstream breach at a payments processor can expose users of an entirely separate product.

Third-Party Vendor Risk Is Now a Board-Level Issue

The 2026 Global-e breach illustrates a risk that many finance teams have not fully priced in: the weakest link in a custody or payments chain may not be the primary vendor at all. If a firm's crypto wallet infrastructure relies on a third-party processor for settlements, refunds, or identity verification, that processor's security posture becomes part of the firm's own risk profile. Auditors reviewing clients' digital asset operations should be asking for evidence of third-party vendor due diligence, including contractual data-security representations, audit rights, and incident-notification timelines.

PII and Crypto Overlap Creates Compounded Liability

What distinguishes crypto-related data breaches from conventional retail data breaches is the directness of the financial harm. When a retail customer's email address leaks, the harm is diffuse and often hard to quantify. When a crypto user's name, address, and wallet association leak, that individual becomes a precisely identified high-value target. The plaintiff in this case alleges losses of close to $2 million, losses he claims would have been prevented or mitigated by timely notification. That causal chain, from breach to targeted theft to quantified financial loss, is what makes this class action both legally and financially significant.

For firms that hold PII linked to digital asset positions, whether through a custody arrangement, a payroll crypto program, or client onboarding for a crypto fund, the lesson is that data minimisation and access controls are not just a cybersecurity matter. They are an accounting and liability matter. The potential for a direct, measurable financial loss attributable to a PII breach means that contingent liabilities arising from data incidents may need to be assessed and, in some cases, disclosed in financial statements.

Accounting and Audit Implications

Finance teams and their auditors should consider several practical angles arising from this case, even before any judgment is handed down.

Contingent Liability Assessment

Under US GAAP, a loss contingency must be accrued when it is probable that a liability has been incurred and the amount can be reasonably estimated. A class action of this scale, even one in its early stages, warrants careful assessment against those criteria. For Ledger itself, the accounting question is whether any provision is required now. For firms advising companies in the crypto hardware or custody space, this case sets a useful precedent for how to frame that analysis.

Vendor Due Diligence Documentation

Auditors examining digital asset operations should expect to see documented evidence that management has assessed the data-security posture of all material vendors. That means reviewing contracts for breach notification clauses, checking whether vendors carry cyber liability insurance, and confirming that incident response procedures have been tested. In the absence of that documentation, auditors may need to consider whether a reportable condition or material weakness exists in the client's internal control environment.

Insurance Coverage Review

The Ledger litigation also highlights the importance of confirming that cyber liability policies cover scenarios where a data breach at a vendor, rather than directly at the insured firm, leads to customer or client losses. Policy language on this point varies considerably, and many firms have not stress-tested their coverage against a third-party processor scenario of the type described in the 2026 Global-e incident.

For a broader view of how crypto exploit events generate AML and accounting obligations, the AML and accounting implications of crypto wallet exploits piece published earlier this year sets out the core analytical framework. And for context on how investigators follow the trail after funds are stolen, our analysis of how blockchain analytics is reshaping AML investigations is worth reading alongside this case.

What Firms Should Do Now

The lawsuit is in its early stages and no liability has been established. But the underlying facts, three breaches over six years, delayed notifications, and alleged failure to remediate, are not disputed at a high level. That timeline is enough to prompt a practical review across several dimensions.

Review Your Crypto Vendor Stack

Map every third-party vendor that touches client PII in the context of digital asset operations. That includes custody providers, wallet infrastructure suppliers, KYC verification services, and payment processors. For each, confirm the contractual breach notification period, assess whether it meets SHIELD Act standards for any New York-resident clients, and request evidence of the vendor's most recent penetration test or security audit.

Assess Notification Obligations

If a vendor breach does occur, the firm's own notification obligations under state law, including the SHIELD Act, may be triggered independently of whatever the vendor does. Legal counsel should have a pre-prepared playbook that identifies which jurisdictions' notification timelines apply, who the notification lead is internally, and what the content of a compliant notification must include.

Document the Risk Assessment in Writing

Whether or not the firm uses crypto accounting software, digital asset accounting software, or any crypto bookkeeping software that connects to external wallet infrastructure, the risk assessment should be documented, dated, and signed off at a senior level. That documentation becomes critical if the firm is ever involved in litigation or regulatory inquiry following a third-party breach.

Ledger Faces $500M Lawsuit Over Repeated Data Breaches

Frequently Asked Questions

What is the Ledger class action about?

A US plaintiff filed a $500 million class action on 27 August 2026 alleging that Ledger was negligent in its response to data breaches in 2020 and 2023, failed to notify affected customers in a timely manner, and did not take adequate steps to fix the underlying security vulnerabilities. A separate 2026 breach involving a third-party payments processor is noted in reporting but not addressed directly in the complaint as described.

What is the New York SHIELD Act and why does it matter here?

New York's Stop Hacks and Improve Electronic Data Security Act imposes data-security obligations and breach notification requirements on any entity that holds private information of New York residents, regardless of where the entity is based. The lawsuit alleges Ledger violated these requirements by failing to notify customers promptly and failing to maintain reasonable security safeguards.

Does this affect firms that use crypto accounting or digital asset accounting software?

Indirectly, yes. The case highlights that any firm operating in the digital asset space, including those using crypto accounting software or crypto bookkeeping software connected to external custody or payment infrastructure, carries third-party vendor risk. A breach at a vendor can expose the firm's own clients and trigger the firm's independent notification obligations under applicable state law.

What accounting entries might a company like Ledger need to make?

Under US GAAP ASC 450, a loss contingency must be accrued when a liability is probable and the amount is reasonably estimable. With a $500 million claim and a putative class, management and auditors would need to assess whether any provision is required at each reporting date as the litigation progresses. Disclosure in the notes to financial statements is likely required even if accrual is not yet warranted.

What should an auditor ask when reviewing a client with crypto custody arrangements?

Auditors should request evidence of third-party vendor due diligence, including contracts covering breach notification timelines, evidence of vendor cyber insurance, results of any recent penetration tests or security audits, and documented incident response procedures. Where that evidence is absent or inadequate, auditors should consider whether a control deficiency exists and how it should be communicated.

Source: Protos

USGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
FBI Seizes $560K in Hamas Crypto: What It Means for AML Compliance
AML/KYC & Licensing
Crypto, Sanctions and War: How Russian Actors Funnel Digital Assets
AML/KYC & Licensing
Bitcoin Ransomware Response: A Four-Step Plan for Firms
AML/KYC & Licensing
US Sanctions Iran's Entire Crypto Sector Over $100M in Oil Payments