Ledger hardware wallet users are being targeted by phishing emails claiming to report a fake data breach. The new scam seeks to steal access to their funds.
How the Phishing Campaign Works
The phishing campaign involves emails impersonating Ledger support, aiming to trick users into 'verifying' their recovery phrases due to a fake security breach. Starting on December 15, 2024, the campaign uses Amazon AWS infrastructure to seem legitimate.
Details of the Scam
The emails appear official with the subject 'Security Alert: Data Breach May Expose Your Recovery Phrase.' Users are redirected to an Amazon AWS site with a suspicious URL: product-ledg.s3.us-west-1.amazonaws.com, then to a phishing site with a sophisticated word verification system.
Security Tips from Ledger
Ledger has reminded users that it will never ask for recovery phrases, which should only be used during wallet setup. Users are advised to type ledger.com directly into the browser and treat suspicious emails with caution.
The campaign highlights the importance of cybersecurity, particularly in the wake of past Ledger data breaches. Following security tips can significantly reduce risks.