Ledger Sued for $500m: Can UK Crypto Customers Claim Data Breach Compensation?
By Simon Bumford, Founder · · 16 min read
A Ledger customer is suing for $500m after losing $1.95m to a phone scam. What the case really alleges, and what UK Trezor and Ledger customers can claim.
The short version
On 27 August 2026 a Ledger customer filed a proposed class action in New York seeking at least $500 million, after losing about $1.95 million in crypto to a phone scam he says was made possible by his details leaking from Ledger. Three weeks earlier, Trezor had told roughly 80,000 customers, including some in the UK, that a shipping partner had leaked their names, home addresses and phone numbers. The obvious question for anyone on either list is whether they can claim anything. The honest answer, for a UK customer, has three parts. Yes, the right to compensation exists, it covers distress without financial loss, and it can be used against the company even when a supplier caused the leak. No, the sums are nothing like the American headline; the English courts have awarded between nothing and a few thousand pounds for breaches of this kind, and one Supreme Court hearing due in October 2026 could lower the bar further. And the practical route matters more than the legal theory: since 19 June 2026 you must complain to the company first, the regulator cannot award you money, and suing a Czech or French company from England has enforcement problems nobody has yet tested. This article explains what the Ledger lawsuit actually alleges, which is not quite what the headlines say, why it matters for Trezor and ShipMonk customers, and what a UK claim realistically looks like. It is about remedies. For what to do about the security risk itself, see our guide to the Trezor data breach.
What the Ledger lawsuit actually claims
The case is Kim v Ledger SAS, filed in the US District Court for the Southern District of New York, case number 1:26-cv-07307. The plaintiff, Douglas Kim of Los Angeles, sues Ledger SAS, the French parent, on behalf of a proposed class of US customers whose data or crypto was compromised and who lost money as a result. The complaint runs to 30 pages, pleads seven causes of action under New York consumer law and common law, and demands a jury trial. Two things in the complaint are widely misreported. First, the breach at its centre is not the 2020 leak of 272,000 customer addresses. It is the incident of 14 December 2023, when attackers phished a former Ledger employee whose access to a software publishing account had not been revoked and pushed a malicious version of the Ledger Connect Kit library. The 2020 leak is pleaded only as evidence of a pattern, and the complaint itself notes that it is being litigated separately in California. Second, the link between that incident and Kim's loss is pleaded "on information and belief", with an express reservation to amend once Ledger's forensic records are disclosed. Ledger's own incident report describes a five hour supply chain attack on code, not an exfiltration of customer contact data. Whether Kim's details came from Ledger at all is therefore the first thing the litigation will have to establish. What happened to Kim is not in dispute in the same way, and it is instructive. On 18 February 2025 he was telephoned by someone claiming to be from a department within Ledger, told that a person in the Netherlands had tried to enrol him in Ledger's recovery service, directed to an email that appeared to come from ledger.com, then to a look-alike website, and talked into entering his passphrase. Two days later $1,948,074 in crypto was gone. No device was hacked. No key was stolen from a database. A person who knew he owned a Ledger persuaded him to hand over the one thing that mattered. That is the pattern every hardware wallet customer on a leaked list should expect, and it is the subject of our playbook on persuasion attacks. The $500 million is a pleaded floor, not an assessed figure. The complaint reaches it by assuming 3% of Ledger's seven million units sold belong to affected customers and that a tenth of those lost $20,000 each. Ledger told Protos it does not comment on legal matters. As of 7 September 2026 nothing has been filed beyond the complaint and a summons.
The 2020 breach is a different case, and it is still running
The lawsuit over the leak most people remember, the 2020 exposure of about 272,000 Ledger customers' names, postal addresses and phone numbers, is Baton v Ledger SAS in the Northern District of California, filed in April 2021. Its history is a useful corrective to anyone expecting a quick result. It was dismissed in November 2021 for lack of jurisdiction over a French company. The Ninth Circuit partly reversed that in December 2022, noting that Ledger had sold about 70,000 wallets directly to Californians, but upheld Ledger's French forum clause for everything except California consumer claims. In February 2025 the judge let one claim proceed, a single plaintiff's unfair practices claim, and dismissed the rest. Ledger filed a defence in April 2025. Five years on, no class has been certified and nothing has been paid. In France, around fifty customers sued Ledger in the Paris civil court under the GDPR in 2021. That case has been slowed by a fight over the data regulator's decision: CNIL fined Ledger 750,000 euros in October 2024, reported by French press but never published, and in May 2026 the court refused to hand the full decision to the claimants on trade secrets grounds. A judgment is not expected before 2027. A Liechtenstein lawyer filed about twenty individual GDPR claims in German courts in 2021; no outcome has ever been published. Ledger's position on compensation has been consistent since the week of the leak. Its chief executive told Decrypt in December 2020 that reimbursing a million users "would just kill the company", and the company's own statement said it would not be refunding customers. What the leak did produce, documented at the time, was extortion emails and by mid 2021 tampered devices posted to leaked home addresses. That history is why the Trezor disclosure matters more than a shipping company's error normally would.
Why this matters for Trezor and ShipMonk customers
Nobody has sued Trezor or ShipMonk over the August and September 2026 breach as of 7 September. No US filing appears on the federal court record, no claims firm is advertising, and no regulator has published anything. That may change, particularly in the United States, where the September expansion added roughly 67,000 US customers from orders placed between 2019 and 2021. The reason the Ledger cases matter is that they describe the road the Trezor incident is now on. A hardware wallet vendor's contact list is uniquely useful to a criminal because it identifies people who almost certainly hold crypto and tells them where those people live. Kim's loss came fourteen months after the incident he blames. The tampered Ledger devices arrived six months after the 2020 dump. The value of the ShipMonk data does not expire when the news cycle does. There is also a detail in Trezor's disclosure that would matter in any claim. Trezor says it had "repeatedly requested and received written assurance confirming the deletion of the data" from ShipMonk, and that the data was nonetheless retained for years. For a customer that cuts both ways: it is evidence that the processor acted against instructions, and it raises the question of what checking the controller did beyond asking. The full facts are in Trezor's disclosure and our analysis of the September update.
Can a UK customer claim? The right exists
Yes. Article 82 of the UK GDPR gives "any person who has suffered material or non-material damage as a result of an infringement" the right to compensation from the controller or processor. Section 168 of the Data Protection Act 2018 adds, in a single sentence, that non-material damage "includes distress". So a UK customer does not need to have lost money. Anxiety, the burden of dealing with the aftermath, and well-founded fear of what the data might be used for are all, in principle, compensable. Three further points from the statute matter here. The right runs against the controller even when a supplier caused the problem: Article 82(2) makes "any controller involved in processing" liable, and the controller escapes only if it "proves that it is not in any way responsible for the event giving rise to the damage". The Court of Justice of the EU, in a 2023 ruling that English courts have since followed, put that burden squarely on the company and held that a disclosure by criminals does not by itself let the controller off. And the UK GDPR applies to a foreign company that offers goods to people in the UK, under Article 3(2), which both Ledger and Trezor plainly do. Trezor is the controller of its customers' delivery data and ShipMonk is its processor. Article 28 required Trezor to use only processors giving "sufficient guarantees" and to bind them by contract. Trezor's statement that it obtained written deletion assurances is exactly the kind of evidence a controller relies on to argue it was not responsible. Whether asking for assurances, without auditing them, is enough has never been decided by an English court.
What the English courts actually award
This is where the American figures stop being useful. The English position was set by the Supreme Court in Lloyd v Google in 2021: there is no compensation for the bare "loss of control" of data, a claimant must show damage or distress, and opt-out representative actions on behalf of everyone affected do not work because each person's loss has to be assessed individually. The £750 per person that case proposed was never awarded. The awards that do exist are small. In Rolfe v Veale Wasbrough Vizards a single misdirected email produced no damages, a finding that the claim was trivial, and an order that the claimants pay £11,000 towards the defendant's costs. In Driver v Crown Prosecution Service the High Court awarded £250 for a breach "at the lowest end of the spectrum". The Court of Appeal's award in Halliday in 2013, £750 for distress, is the figure most often cited as a floor. Higher sums have gone to people with a rational fear for their safety: in TLT v Home Office, where the Home Office published the details of asylum seekers, awards ran from £2,500 to £12,500, benchmarked against personal injury awards for psychological harm. The "£750 to £2,000" range that claims firms quote online is not from any judgment; it is trade shorthand assembled from those cases. The most important recent decision cuts the other way, and it is not yet final. In Farley v Paymaster in August 2025 the Court of Appeal held that there is no threshold of seriousness a data claim must cross, that a claimant does not have to prove the leaked information was ever read by anyone, and that "fear of the consequences of an infringement" is compensable "if the alleged fear is objectively well-founded but not if the fear is purely hypothetical or speculative". The same court sent those claims to the County Court small claims track, where costs are barely recoverable. The Supreme Court has granted permission to appeal and will hear the case on 7 and 8 October 2026. Until it rules, the Court of Appeal's test stands, but anyone issuing a claim now is doing so with the law in motion.
The well-founded fear point, and why it is stronger here than usual
Most low-value data claims fail because the fear is speculative: a letter went to the wrong address, nobody opened it, nothing happened. The Trezor data is different in a way that matters under the Farley test. It is a list of people who bought a device whose only purpose is to hold cryptocurrency, with their home addresses and phone numbers, at a time when UK courts have sentenced offenders for home invasions and false imprisonment of crypto holders, and when Trezor itself has warned of "physical security risks". A fear of targeted phishing or worse is not hypothetical for this group. It is the documented consequence of the last comparable leak. That is an argument, not a result. No English court has assessed damages for a hardware wallet customer, and no UK court has yet found that a physical attack on a crypto holder was caused by a vendor's breach. What the argument does is move a Trezor customer's claim out of the trivial category where Rolfe sits and towards the safety-fear category where TLT sits. The difference between those categories is the difference between nothing and a few thousand pounds, with costs risk in between.
The route, step by step
The procedure changed on 19 June 2026, when the Data (Use and Access) Act 2025 brought section 164A of the Data Protection Act into force. You must now complain to the company first. The controller must acknowledge within 30 days and respond "without undue delay". Put the complaint in writing, say what happened, what data you believe was involved, and what you want. At the same time make a subject access request asking exactly what personal data of yours was in the breached dataset. Trezor's own statement gives you the hook: ask whether your data was in the deletion assurances it received. If the answer is unsatisfactory you can complain to the ICO, and you should, because complaints shape enforcement. But be clear about what it gives you. The ICO's own page says: "The ICO cannot award compensation, even when we give our opinion that an organisation has broken data protection law." Its guidance for people affected by a breach, updated in August 2026, also tells you to contact the police if you are concerned for your safety. The legal claim is a court claim, in the County Court for anything under £10,000, on the small claims track. Send a letter before claim first, as the pre-action rules require, giving the company 14 days to respond. Under the small claims costs rules you will not recover solicitor's costs if you win and, unless you behave unreasonably, will not pay the other side's if you lose, which is why Farley routed claims there. The limitation period is six years under the Limitation Act 1980. Keep everything: the notification email, any phishing you receive quoting your details, dates, screenshots, and a note of the time and worry it has cost you. That evidence, not the statute, is what a judge will assess.
The jurisdiction problem with a Czech company
Trezor is Trezor Company s.r.o., based in Prague. Its shop terms choose Czech law and the Czech courts, while acknowledging that a consumer keeps the protection of their home country's mandatory law. In England, section 15B of the Civil Jurisdiction and Judgments Act 1982 lets a UK consumer sue a trader that directs its business here in the courts of the UK, and a pre-dispute clause choosing foreign courts does not bind the consumer. So issuing in England is possible in principle. Enforcement is the untested part. An English judgment against a company with no UK assets has to be recognised in the Czech Republic. The Hague Judgments Convention has applied between the UK and the EU since July 2025, but its filters were not written with data protection distress claims in mind, and no case has tested whether such a judgment passes them. For a small sum the practical route may be the one Trezor's terms invite: a claim in Prague under the EU GDPR, which gives identical rights and where Trezor's assets are. ShipMonk, a US processor with no visible UK presence, is harder still. Ledger SAS presents the same structure from France. None of this makes a claim impossible. It means a UK customer should weigh the cost of pursuing a company abroad against an award that may be in the hundreds of pounds, and should treat the group and funded routes, if any emerge, as the realistic vehicle for anything larger.
If you actually lost money
A claim for financial loss is a different proposition from a claim for distress, and a more serious one. Article 82 covers "material damage", so the loss is recoverable in principle. The difficulty is proof: you have to show that the breach caused the loss, which means showing that the criminal's knowledge of you came from that dataset and not from anywhere else. Kim's complaint illustrates the problem; his lawyers could not plead the source of his details as a fact and had to reserve the right to prove it later. If you have lost crypto to a phishing call or a fake site, the order of business is the same regardless of any future claim. Follow the NCSC's steps for people who have shared information, tell your bank, and report to Report Fraud on 0300 123 2040. Preserve every message, number and address the criminals used. A police report and a documented timeline are what turn "I was scammed after the breach" into evidence that can carry a claim. And be ready for the second wave: "recovery" services that contact victims offering to get funds back are, in the FCA's experience, usually the same people.
What the lawsuit does not change
Whatever happens in New York, Paris or Prague, the leaked data is already in circulation and no judgment retrieves it. The protective steps are the same as they were on the day of the disclosure: treat every unsolicited message as hostile, never give a recovery phrase or passphrase to anyone for any reason, secure the email account tied to the order, and think about the physical layer if your home address was exposed. Our Trezor breach guide sets those out for UK customers, and our piece on who knows you own bitcoin explains why a hardware wallet purchase is only one of several records that link your name to your holdings. The lawsuit is worth watching for one reason above all. If Kim can prove that a Ledger incident put his contact details into a criminal's hands, and that this led to a $1.95 million loss, it will be the first time a court has traced that chain from a wallet vendor's breach to a customer's emptied wallet. Every hardware wallet customer, and every company that outsources its shipping, has an interest in the answer.
Frequently Asked Questions
Can I sue Ledger over a data breach?
In the US, a proposed class action was filed on 27 August 2026 in New York (Kim v Ledger SAS) and a separate case over the 2020 leak has been running in California since 2021. In the UK, a customer has a statutory right to compensation under Article 82 of the UK GDPR, including for distress, but there is no UK group action and awards for breaches of this kind have ranged from nothing to a few thousand pounds.
Is there a class action against Ledger?
Yes, two. Kim v Ledger SAS, filed in the Southern District of New York on 27 August 2026 over the December 2023 Connect Kit incident, seeks at least $500 million for a proposed class of US customers. Baton v Ledger SAS, filed in California in April 2021 over the 2020 address leak, is still running with a single claim surviving. Neither has certified a class or paid anything as of September 2026.
Can UK Trezor customers claim compensation for the ShipMonk breach?
In principle, yes. UK GDPR Article 82 applies to Trezor because it sells to UK customers, it makes the controller liable for a processor's failure unless the controller proves it was not responsible in any way, and distress is expressly compensable. In practice you must complain to Trezor first, the ICO cannot award money, and enforcing an English judgment against a Czech company is untested. Nobody has sued Trezor or ShipMonk as of 7 September 2026.
How much compensation can you get for a data breach in the UK?
Reported awards for distress without financial loss run from nothing (Rolfe, 2021) and £250 (Driver, 2022) through £750 (Halliday, 2013) to £2,500 to £12,500 where claimants had a rational fear for their safety (TLT, 2016). The £750 to £2,000 range quoted by claims firms is not from any judgment. Claims under £10,000 go to the small claims track, where legal costs are not recoverable.
Can I claim GDPR compensation for distress alone?
Yes. Section 168 of the Data Protection Act 2018 says non-material damage includes distress, and the Court of Appeal held in Farley v Paymaster (August 2025) that there is no seriousness threshold and that objectively well-founded fear of the consequences is compensable. That ruling is under appeal to the Supreme Court, with a hearing on 7 and 8 October 2026.
Will Ledger compensate customers affected by the 2020 leak?
Ledger has said no since December 2020, when its chief executive told Decrypt that reimbursing a million users would kill the company and Ledger's own statement said it would not be refunding customers. French regulator CNIL fined Ledger 750,000 euros in October 2024 over the leak; that fine goes to the state, not to customers.
Does the ICO pay compensation for data breaches?
No. The ICO states that it cannot award compensation even when it finds an organisation broke the law. Compensation comes either from the organisation agreeing to pay or from a court claim. Since 19 June 2026 you must complain to the organisation first, and it must acknowledge within 30 days.
Is my crypto at risk because of the Trezor or Ledger breach?
Not directly. Neither breach exposed private keys or recovery phrases. The risk is deception: criminals who know you own a hardware wallet and where you live can run convincing phone, email and postal scams, which is exactly how the Ledger plaintiff says he lost $1.95 million. Never share a recovery phrase or passphrase with anyone. See our Trezor breach guide for the full UK checklist.
Sources
- Kim v Ledger SAS, S.D.N.Y. 1:26-cv-07307, docket (CourtListener)
- Kim v Ledger SAS, class action complaint, 27 Aug 2026 (PDF)
- Ledger: security incident report on the December 2023 Connect Kit attack
- Protos: Ledger sued for $500M over its many data breaches (3 Sep 2026)
- Baton v Ledger SAS, N.D. Cal. 3:21-cv-02470, docket (CourtListener)
- Ninth Circuit memorandum, Baton v Ledger SAS, 1 Dec 2022 (PDF)
- Bloomberg Law: Ledger must face claims it failed to safeguard consumer data (7 Feb 2025)
- Decrypt: Ledger won't reimburse users after major data hack (21 Dec 2020)
- Ledger: message from Ledger's CEO on the data leak (21 Dec 2020)
- ICI / France 3: Ledger fined 750,000 euros by CNIL (29 Oct 2024)
- FrenchBreaches: Paris court refuses to release the CNIL decision to Ledger claimants (5 Jun 2026)
- BleepingComputer: criminals are mailing altered Ledger devices (16 Jun 2021)
- Trezor: recent customer data exposed in shipping provider incident (13 Aug 2026, updated 4 Sep 2026)
- UK GDPR Article 82: right to compensation and liability
- UK GDPR Article 3: territorial scope
- UK GDPR Article 28: processor
- Data Protection Act 2018 s.168: compensation, non-material damage includes distress
- Data Protection Act 2018 s.164A: complaints to controllers (in force 19 Jun 2026)
- Lloyd v Google LLC [2021] UKSC 50
- Farley v Paymaster (1836) Ltd [2025] EWCA Civ 1117 (judgment PDF)
- Farley v Paymaster, Supreme Court appeal UKSC/2025/0185, hearing 7 to 8 Oct 2026
- Rolfe v Veale Wasbrough Vizards [2021] EWHC 2809 (QB)
- Driver v Crown Prosecution Service [2022] EWHC 2500 (KB)
- TLT v Secretary of State for the Home Department [2016] EWHC 2217 (QB)
- Halliday v Creation Consumer Finance [2013] EWCA Civ 333
- CJEU press release, Case C-340/21 (14 Dec 2023): fear of misuse can be non-material damage
- ICO: taking your case to court and claiming compensation
- ICO: what steps can I take if I have been affected by a personal data breach? (Aug 2026)
- Civil Procedure Rules Part 27: small claims track costs
- Practice Direction: pre-action conduct
- Limitation Act 1980 s.9
- Civil Jurisdiction and Judgments Act 1982 s.15B: consumer contracts
- Trezor shop terms and conditions (governing law and jurisdiction)
- Report Fraud (replaced Action Fraud, Dec 2025)
- NCSC: what to do if you have shared sensitive information
Ready to plan your crypto inheritance?
Speak to our UK-based team about your situation. No obligation, no pressure.
Speak to us