Ledger’s 2020 data leak - Six years later, why are customer addresses still being retained for 10 years? France has now recorded 77 crypto-linked kidnapping/extortion cases in six months
I was one of the customers affected by Ledger’s 2020 customer data leak.
Here are the facts, because I think people have forgotten how serious this breach actually was.
Ledger says its e-commerce/marketing database was exploited on June 25, 2020. Ledger was notified of the breach on July 14, 2020.
Then, on December 20, 2020, the stolen database was publicly dumped online.
The full scope turned out to be much worse than initially reported: around 272,000 customer records containing names, postal addresses and phone numbers, plus more than 1 million email addresses.
This wasn't just an email leak.
It created a database identifying people as crypto/hardware-wallet owners and connecting many of them to their real names, phone numbers and physical home addresses.
And unlike a password, you cannot simply reset your home address after it has been copied and distributed.
In 2020, much of the discussion was about phishing.
Six years later, the physical-security implications look much less theoretical.
In early July 2026, French Interior Minister Laurent Nuñez said authorities had already recorded 77 crypto-related cases involving kidnapping, unlawful detention, extortion or attempted crimes since the beginning of 2026.
According to Chainalysis:
- The rate of documented attacks in France increased from about 1.9 per month in 2025 to 4.6 per month in the first half of 2026.
- Home invasions rose from 14% of violent crypto attacks in 2025 to 37% in 2026.
- In France, more than 40% of incidents targeted a family member or other relation of the crypto holder rather than the holder themselves.
- 93% of French victims were local residents, not tourists — consistent with criminals identifying and researching specific people.
- By mid-2026, French authorities had made around 200 arrests, with 88 people indicted.
In January 2025, Ledger co-founder David Balland and his partner were kidnapped from their home in France for a crypto ransom. Balland's hand was mutilated during the kidnapping.
In another French crypto kidnapping in May 2025, the father of a crypto entrepreneur was abducted, bound, beaten and held for more than two days. His kidnappers eventually cut off part of his finger while trying to obtain a ransom.
French prosecutors said in April 2026 that more than 135 crypto-related kidnapping/extortion cases had been recorded since 2023, and described evidence of structured criminal networks. Two separate victims in 2025 had fingers cut off during ransom attacks.
The point is that violent attacks against identified crypto holders are real. Once someone's identity and home address become permanently associated with cryptocurrency ownership, the consequences of a data breach are fundamentally different from somebody leaking a normal retail mailing list.
So I wanted to know: What did Ledger actually change after 2020?
To Ledger's credit, they did change some things.
Ledger says customer order data is moved into a more restricted/segregated environment after three months. They reassessed third-party providers, introduced data-access/deletion requests, and say they now use encryption, role-based access controls, 2FA, security testing and audits.
But then I read Ledger's current 2026 Privacy Policy.
Ledger still collects:
- Name
- Email address
- Shipping and billing addresses
- Phone number
- Order ID
- Product ordered
- Order amount
- Shipping/payment information
And Ledger says:
“We keep your data for 10 years to comply with our legal obligations. Your data is archived 3 months after completion of the order.”
That deserves an explanation.
Which of those fields are actually legally required for ten years?
Does Ledger genuinely need to retain a customer's phone number and shipping address for ten years?
If not, are those fields deleted independently of the accounting information that actually has to be retained?
And there is another uncomfortable detail.
In January 2026, Ledger customers were affected by another data-security incident — this time through Ledger's e-commerce partner Global-e. Unauthorized access exposed customer order-related personal data including names/contact information and order details.
So six years after Ledger promised to aggressively minimize third-party exposure, customer information was again exposed through an e-commerce partner.
I'm not interested in hearing that private keys and seed phrases weren't leaked. I know that.
This is about physical security.
Ledger sold people a product whose entire purpose was protecting valuable assets, while a database connected the buyers of those products to their identities and homes.
For customers affected in 2020, that information cannot be recalled.
It may circulate forever.
So these are the questions I would genuinely like Ledger to answer:
1. Exactly which customer fields are retained for ten years today?
2. Are shipping addresses and telephone numbers actually retained for the full ten years, or are they deleted earlier?
3. If I request deletion today, exactly what information about my historical purchase will Ledger still retain?
4. Which third parties currently receive customers' names, phone numbers and physical addresses, and how quickly are those parties contractually required to delete them?
5. After the Global-e incident in January 2026, what specifically changed in Ledger's third-party data-handling requirements?
6. Why doesn't Ledger offer an anonymous/privacy-preserving direct delivery option by default?
7. And what, if anything, does Ledger offer the people whose home addresses it already allowed to become permanently public in 2020?
I don't expect Ledger to somehow erase a database that criminals may already have copied.
But I do expect a company whose entire brand is built around security to treat leaking a crypto owner's physical address as something vastly more serious than an ordinary e-commerce privacy incident.
Because today we know what physical attacks against crypto holders can actually look like.
I would really like someone from Ledger to give concrete answers rather than “your private keys were not affected.”