mail – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 30 Apr 2025 12:08:19 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 mail – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Crypto Scammers Go Old School: Ledger Users Hit with New Seed Phrase Mail Scam https://earlybirdsinvest.com/crypto-scammers-go-old-school-ledger-users-hit-with-new-seed-phrase-mail-scam/ https://earlybirdsinvest.com/crypto-scammers-go-old-school-ledger-users-hit-with-new-seed-phrase-mail-scam/#respond Wed, 30 Apr 2025 12:08:18 +0000 https://earlybirdsinvest.com/crypto-scammers-go-old-school-ledger-users-hit-with-new-seed-phrase-mail-scam/

Owners of Ledger hardware wallets have reported receiving fake physical letters designed to trick them into revealing their wallet seed phrases as part of a new wave of crypto scams.

On April 29, tech analyst Jacob Canfield posted a warning on X, sharing a scam letter that had arrived at his home.

Disguised as official correspondence from Ledger, the letter instructed him to perform a “critical security update” by scanning a QR code and entering his 24-word recovery phrase.

Ledger Scam Letter Mimics Official Mail With Logo and Reference Number

The professionally designed letter included Ledger’s logo, a return address, and a reference number to lend credibility.

It warned that failure to complete the “validation” could result in restricted access to the user’s funds—an intimidation tactic meant to spur action.

Ledger responded directly to Canfield’s post, confirming the letter was fraudulent and part of a phishing attempt.

“Ledger will never ask for your 24-word recovery phrase,” the company reiterated, advising users not to trust unsolicited messages or individuals claiming to be Ledger representatives.

Seed phrases, often 12 to 24 words long, are the most sensitive component of a crypto wallet. Anyone who gains access to them can take full control of a user’s assets.

Some community members suspect the scam stems from Ledger’s infamous 2020 data breach, when the personal information of over 270,000 customers—including names, emails, and home addresses—was leaked online.

That incident was followed by numerous phishing campaigns, including one in which tampered Ledger devices were mailed to victims to install malware.

The recent mail scam appears to be another tactic targeting those affected by the breach, showing how long the consequences of data leaks can linger in the crypto world.

Phishing Scam Targets Coinbase, Gemini Users

In March, several crypto users flagged sophisticated phishing scam emails, which targeted Coinbase and Gemini users with legit-looking fraudulent emails.

The mass email reportedly arrived in various user inboxes on Saturday. The scam mail pointed to a class action lawsuit against Coinbase for allegedly involving in unregistered securities, adding that the court has mandated users to convert their assets into self-custody wallets.

Further, the mail also stressed that the deadline to transfer user assets to a self-custodial wallet is April 1st, 2025.

As reported, in the first three months of 2025, the crypto ecosystem lost a whopping $1,635,933,800 across 39 incidents, according to the blockchain security platform Immunefi.

The report claimed, “Q1 2025 marks the worst quarter for hacks in the history of the crypto ecosystem.”

Most of that was the result of only two hacks of two centralized exchanges. Phemex suffered a $69.1 million loss in January, while Bybit lost $1.46 billion in February.

Subsequently, the total number of losses in the first quarter marks a 4.7x increase compared to Q1 2024. At that time, hackers and fraudsters stole $348,251,217.

Notably, experts assume that the infamous North Korean Lazarus Group is behind the two largest attacks. They stole $1.52 billion, which is 94% of total losses.

The post Crypto Scammers Go Old School: Ledger Users Hit with New Seed Phrase Mail Scam appeared first on Cryptonews.

]]>
https://earlybirdsinvest.com/crypto-scammers-go-old-school-ledger-users-hit-with-new-seed-phrase-mail-scam/feed/ 0 33613
Fake BianLian ransom notes mailed to US CEOs in postal mail scam https://earlybirdsinvest.com/fake-bianlian-ransom-notes-mailed-to-us-ceos-in-postal-mail-scam/ https://earlybirdsinvest.com/fake-bianlian-ransom-notes-mailed-to-us-ceos-in-postal-mail-scam/#respond Wed, 05 Mar 2025 09:39:56 +0000 https://earlybirdsinvest.com/fake-bianlian-ransom-notes-mailed-to-us-ceos-in-postal-mail-scam/

Hacker sending postal mail

Scammers are impersonating the BianLian ransomware gang in fake ransom notes sent to US companies via snail mail through the United States Postal Service.

The fake ransom notes were first reported by Guidepoint Security today, with BleepingComputer later being sent a scan of the note from a CEO who received the same letter.

The envelopes for these ransom notes claim to be from the “BIANLIAN Group” and have a return address located in an office building in Boston, Massachusets:

BIANLIAN GROUP
24 FEDERAL ST, SUITE 100
BOSTON, MA 02110

In the letter shared with BleepingComputer, the envelope shows it was mailed on February 25th, 2025. This mailing date is the same as the one seen by Arctic Wolf, who also reported on the scam today.

The letters are being mailed to the CEO of the companies at their corporate mailing address and show that they were processed through a postal facility in Boston, with the envelope marked, “Time Sensitive Read Immediately.”

Envelope for fake BianLian ransom  note
Envelope for fake BianLian ransom  note
Source: BleepingComputer

The envelopes contain a ransom note addressed to the company’s CEO or another executive, claiming to be from the BianLian ransomware operation. According to notes reviewed by BleepingComputer, they are tailored to the company’s industry, with different types of allegedly stolen data corresponding to the company’s activities.

For example, fake BianLian ransom notes sent to healthcare companies claim that patient and employee information was stolen, while those targeting product-based businesses allege the exposure of customer orders and employee data.

“I regret to inform you that we have gained access to [REDACTED] systems and over the past several weeks have exported thousands of data files, including customer order and contact information, employee information with IDs, SSNs, payroll reports, and other sensitive HR documents, company financial documents, legal documents, investor and shareholder information, invoices, and tax documents,” reads a fake BianLian ransom note.

Fake BianLian ransom note sent via snail mail
Fake BianLian ransom note sent via snail mail
Source: GuidePoint Security

The mailed ransom notes are very different from BianLian’s, but the scammers attempt to make them look convincing by including the real Tor data leak sites for the ransomware operation in the notes.

However, unlike typical ransomware demands, these fake notes state that BianLian is no longer negotiating with victims. Instead, the victim has 10 days to make a Bitcoin payment to prevent data from being leaked.

Each ransom note includes a ransom demand ranging between $250,000 and $500,000, a freshly generated Bitcoin address to send payment, and a QR code for the Bitcoin address.

Arctic Wolf said that all healthcare organizations had their ransom demand set to $350,000, which is the same as the one shared by a healthcare company with BleepingComputer, as shown below.

Payment information in fake BianLian ransom note
Payment information in fake BianLian ransom note
Source: BleepingComputer

Furthermore, Arctic Wolf states that two ransom notes the researchers saw included legitimate compromised passwords to add legitimacy to the demand.

“In at least two letters, the threat actor included a compromised password within the How did this happen? section, almost certainly in an attempt to add legitimacy to their claim.” explained Arctic Wolf.

The consensus in the reports is that these ransom notes are fake and are only designed to scare executives into paying a ransom, as there are no signs of an actual breach.

“While GRIT cannot confirm the identity of the letter’s authors at this time, we assess with a high level of confidence that the extortion demands contained within are illegitimate and do not originate from the BianLian ransomware group,” explains GuidePoint Security researcher Grayson North.

However, this does not mean the emails should be ignored. Due to the widespread mailing of these notes, all IT and security admins should notify executives about the scam so that they are aware and do not waste time and resources worrying about them.

These fake ransom notes are an evolution of the email extortion scams that have become so popular since 2018. However, instead of targeting personal emails, they are now targeting the CEOs of corporations.

BleepingComputer contacted the BianLian ransomware operation to see if they were involved with these mailings, but a reply was not immediately available.

]]>
https://earlybirdsinvest.com/fake-bianlian-ransom-notes-mailed-to-us-ceos-in-postal-mail-scam/feed/ 0 23363