> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Ledger Customer Data Allegedly Exposed via Global-e Third-Party Breach Affecting 50K+ Orders
- URL: https://darkwebinformer.com/ledger-customer-data-allegedly-exposed-via-global-e-third-party-breach-affecting-50k-orders/
- Published: 2026-01-12T17:32:19.000Z
- Updated: 2026-01-12T18:06:13.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Dark Web Informer - Cyber Threat Intelligence

# Ledger Customer Data Allegedly Exposed via Global-e Third-Party Breach Affecting 50K+ Orders

January 12, 2026 - 4:24:02 PM UTC 

France 

Computer & Network Security 

### 🧩 Standalone API Access Now Available

Access high-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more – independently from the above standard subscriptions. 

[View API Access ](https://darkwebinformer.com/api-details/) 

## Unlock Exclusive Cyber Threat Intelligence

Powered by [DarkWebInformer.com](https://darkwebinformer.com/)

Foundational access to breach intelligence. Track breaches, leaks, and threats in real time with high quality screenshots and concise expert summaries. 

📚

**5,100+ Blog Posts (PRO/ELITE)**  
Continuously updated breach reports and threat summaries.

📢

**52,200+ Alerts (PRO/ELITE)**  
Daily breach, leak, and DDoS alerts.

📤

**Unredacted Threat Feed**  
Live tracking with JSON export.

🔍

**Leak and Breach Coverage**  
Direct access to claims and posts.

📡

**Snippets and Quick Facts**  
Concise summaries of DDoS, defacements, and breaches.

🌐

**500+ Onion and Clearnet Resources**  
Verified index of dark web sites and services.

📊

**Real Time Uptime Dashboard**  
Live status of 500+ sites.

🤖

**WhiteIntel.io API**  
Integrated checks inside breach posts.

🖼️

**High Resolution Images**  
Uncompressed, watermark free evidence.

🔑

**Keyword Notifications**  
Browser alerts for tracked terms.

[💳 Subscribe Now](https://darkwebinformer.com/#/portal/signup) [🪙 Pay with Crypto](https://darkwebinformer.com/crypto-payments) 

##  Quick Facts

Date and Time of Alert

2026-01-12 16:24:02 UTC

Threat Actor

ShiJiayi

Victim Country

France

Industry

Computer & Network Security

Victim Org.

ledger

Victim Site

[ledger.com](https://ledger.com)

Category

Data Breach

Severity

High

Network

Tor

##  Incident Overview

A threat actor using the handle "ShiJiayi" claims to be selling customer order data allegedly belonging to Ledger, a cryptocurrency hardware wallet company. The compromised data reportedly originates from a breach at Global-e, a third-party e-commerce and order processing provider used by Ledger. According to Ledger's official statement, Global-e experienced a security incident on January 12, 2026\. 

- **Official Statement:** Ledger references the Global-e incident at https://support.ledger.com/article/Global-e-Incident-to-Order-Data---January-2026
- **Third-Party Breach:** Data allegedly obtained from Global-e, not directly from Ledger
- **Total Records:** Slightly over 50,000 records
- **Data Contents:** Order information and email addresses (every line contains these)
- **Partial Data:** Not all lines contain phone numbers, names, or country information
- **Email Addresses:** Customer email addresses
- **Phone Numbers:** Customer phone numbers (where available)
- **Names:** Customer names (where available)
- **Country Information:** Customer country data (where available)
- **Order Information:** Details related to customer orders
- **Pricing:** 1 BTC (price is not firm and negotiable)
- **Conditions:** Serious offers only with Proof of Funds or from past clients
- **Sample Data:** Available (shown in screenshot but blurred)
- **Contact Requirement:** Telegram or Signal contact required for serious buyers

##  Indicators of Compromise (IOCs)

No IOCs were disclosed by the threat actor in this claim.

##  Breach Claim URL

For Subscribers Only 

If you are [a subscriber](https://darkwebinformer.com/tag/subscribers/), check the Threat Feed or Ransomware Feed in the subscribers area.

##  Image Preview

[ ![Ledger customer data sale by ShiJiayi allegedly from Global-e breach showing over 50K order records](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/01/9872635789263589762398572.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/01/9872635789263589762398572.png) 

## Unlock Exclusive Cyber Threat Intelligence

Powered by [DarkWebInformer.com](https://darkwebinformer.com/)

Foundational access to breach intelligence. Track breaches, leaks, and threats in real time with high quality screenshots and concise expert summaries. 

📚

**5,100+ Blog Posts (PRO/ELITE)**  
Continuously updated breach reports and threat summaries.

📢

**52,200+ Alerts (PRO/ELITE)**  
Daily breach, leak, and DDoS alerts.

📤

**Unredacted Threat Feed**  
Live tracking with JSON export.

🔍

**Leak and Breach Coverage**  
Direct access to claims and posts.

📡

**Snippets and Quick Facts**  
Concise summaries of DDoS, defacements, and breaches.

🌐

**500+ Onion and Clearnet Resources**  
Verified index of dark web sites and services.

📊

**Real Time Uptime Dashboard**  
Live status of 500+ sites.

🤖

**WhiteIntel.io API**  
Integrated checks inside breach posts.

🖼️

**High Resolution Images**  
Uncompressed, watermark free evidence.

🔑

**Keyword Notifications**  
Browser alerts for tracked terms.

[💳 Subscribe Now](https://darkwebinformer.com/#/portal/signup) [🪙 Pay with Crypto](https://darkwebinformer.com/crypto-payments) 

Dark Web Informer © 2026 | Cyber Threat Intelligence 

[DarkWebInformer.com](https://darkwebinformer.com/)