Skip to main content
AVOID.NET
← Back to search
[TOPIC]

Third Party Vendor

Investigations tagged with this subject. A topic describes what a page is about — an attack type, a jurisdiction, a regulator, a named actor — as distinct from the source that produced it.

2 investigations on this topic

avoid.net/transak55/100[CAUTIONARY]

Transak is a fiat-to-crypto on-ramp infrastructure provider founded in 2019 and serving over 8 million users across 160+ countries, with integrations into major platforms including MetaMask, Phantom, and Uniswap. In October 2024, a phishing attack on an employee's laptop led to unauthorized access to a third-party KYC vendor's dashboard, exposing the personal identity documents of approximately 92,554 users globally, including names, dates of birth, government-issued IDs, and selfie photos. The breach resulted in a $601,000 class action settlement covering U.S.-based affected users, and the Stormous ransomware group claimed responsibility, alleging extraction of over 300GB of data.

avoid.net/ledger58/100[CAUTIONARY]

Ledger is a France-based manufacturer of hardware cryptocurrency wallets (Nano S, Nano X, Stax, Flex) and maker of the Ledger Live companion app, reportedly securing over $100 billion in client assets across more than 7 million devices sold and preparing a US IPO targeting a valuation above $4 billion. The company has a strong core security record for its hardware products but has been repeatedly implicated in data-handling and supply-chain incidents: a 2020 breach of its own e-commerce/marketing database exposed roughly 1 million emails and 270,000 physical addresses, leading to years of phishing and alleged extortion attempts against customers and an ongoing US class action; a December 2023 npm supply-chain compromise via a former employee's account led to roughly $600,000 in DeFi losses; a May 2023 product announcement ('Ledger Recover') triggered a major trust backlash over perceived key-extraction capability; and in January 2026 a breach at third-party processor Global-e exposed customer order data. Separately, third parties impersonating Ledger — including a fraudulent 'Ledger Live' app that passed Apple App Store review in April 2026 — have caused further customer losses that Ledger did not directly control.

avoid.net — verified advice for a post-truth world