The manufacturer of hardware cryptocurrency wallets, Ledger, has found itself at the center of a high-profile legal dispute. A class-action lawsuit has been filed in the U.S. District Court for the Southern District of New York, accusing the company of negligence and incomplete disclosure of information regarding a serious data breach that occurred in December 2023.
The plaintiff is Douglas Kim, who claims that the incident affected confidential client data: names, email addresses, phone numbers, and other personally identifiable information (PII). The key allegation is that Ledger allegedly deliberately downplayed the scale and consequences of the breach and reported it with a significant delay, violating consumer protection laws.
The lawsuit draws a direct connection between the breach and a wave of attacks using social engineering techniques. According to the plaintiff, attackers, having gained access to personal data, impersonated official Ledger representatives. They convinced wallet owners to approve fraudulent transactions, leading to the direct loss of crypto assets. Thus, the company, by failing to ensure proper data protection, indirectly contributed to these thefts.
Special attention in the court documents is also given to an earlier incident. The lawsuit recalls the 2020 breach, which affected approximately 270,000 clients. The plaintiff insists that the recurrence of a similar situation three years later points to systemic shortcomings in Ledger's security measures, rather than isolated errors.
In addition to violating consumer legislation, Ledger is accused of negligence, negligent misrepresentation, and unfair business practices. This case could set a precedent for the entire industry, highlighting the growing responsibility of companies to protect user data.
My expert commentary: This lawsuit is a wake-up call for the entire hardware wallet industry. The PII breach itself does not automatically mean the hacking of funds, but it creates fertile ground for highly targeted phishing attacks. If the court finds Ledger guilty of concealing information, it could lead to significant financial costs and damage the reputation of a company that positions itself as a benchmark of security. The question now is not only about compensation for damages but also about how this case will affect incident disclosure standards in the future.