The crypto data breach France threat has reached a dimension few executives had anticipated. However, attackers are no longer solely targeting digital assets themselves. They are targeting the data that identifies who holds them. And when that data lands in the hands of organised crime, the threat stops being digital.
Crypto Data Breach in France: A Sector Hit by Supply Chain Attacks
In every incident documented since the start of the year, attackers did not target the final victim directly. They compromised a trusted intermediary to gain access to the data of all its clients. This is what the MITRE ATT&CK framework calls Supply Chain Compromise (T1195): strike the link that thousands of organisations depend on rather than attacking them one by one. Maximum leverage, minimal cost.
This vector has struck the French financial sector repeatedly. In November 2025, Itelis, a healthcare reimbursement network used by two major French insurers, suffered unauthorised access through the impersonation of a partner optician. In February 2025, Harvest, a wealth management software widely used by independent financial advisers, was compromised in identical conditions.
More recently, on March 25, in the healthcare sector, Cerballiance, which serves 28 million patients annually, experienced unauthorised access via an IT service provider. In all three cases, the entry point was not the main target but a provider that had been trusted without question.
Ledger: A French Crypto Data Breach via Supply Chain
On 5 January 2026, Ledger, the Paris-based company whose hardware wallets are used by millions of cryptocurrency holders worldwide, disclosed a customer data breach. The intrusion did not come from its own systems. It came through Global-e, its e-commerce payment provider, whose cloud systems were compromised (T1195.002, T1530). Names, email addresses, postal addresses and order information were exposed. Private keys and seed phrases were not affected.
But the exposed data is sufficient to precisely identify crypto hardware holders, including their home addresses. For an attacker planning an extortion operation, this is exactly the profile needed.
Waltio: Crypto Tax Data as an Attack Surface
On 23 January 2026, Waltio’s 120,000 users received a sober and alarming email: “a particularly sophisticated attack by a malicious actor” had led to the theft of user data. Waltio, based in Clermont-Ferrand, helps cryptocurrency holders meet their legal obligation to declare digital assets to the French tax authorities.
The stolen data includes email addresses and 2024 tax reports containing the complete financial profile of each user: asset volumes, transaction history and portfolio valuations. The ShinyHunters group, the alleged perpetrator, claims to hold the data of 50,000 users. A preliminary investigation was opened at the instruction of the cybercrime unit (J3) of the Paris Public Prosecutor’s Office, assigned to the National Cyber Unit of the French Gendarmerie (UNCyber).
A file called waltio.json has been circulating on Telegram channels since the incident. Observers describe it as the digital equivalent of a directory reading “who owns bitcoin and where do they live”. It has already been used to identify and target high-value victims in France. A business executive who held crypto assets, speaking anonymously to Le Monde on 27 January 2026, described how he had trusted Waltio as a reliable third party, recommended by major specialist media. He learned of the full extent of the breaches through the press.
ZenLedger: The Same Vulnerability, at American Scale
On 10 January 2026, a database from ZenLedger, an American crypto tax software, was put up for sale on Breach Forums. Nine hundred and fourteen entries exposed: names, emails, phone numbers, full postal addresses, job titles and employer organisations. Among the victims are accountants, audit firm partners, independent wealth managers and corporate finance executives.
From an attacker’s perspective, this user profile is a prime target. These are identifiable professionals whose role, employer and involvement in managing digital assets, for themselves or their clients, is precisely documented. Cross-referenced with other databases available on criminal markets, this breach enables the construction of attack profiles with remarkable precision.
Waltio and ZenLedger illustrate the same blind spot. Crypto tax data is not perceived as sensitive in the traditional sense. It contains no social security number, no banking credentials. Yet it constitutes a precise map of a person’s digital wealth: who holds what, for how much, and where that person can be found.
How Attackers Turn Your Data Into Criminal Capital
In the criminal economy surrounding cryptocurrencies, data is not valued for what it contains. It is valued for what it enables. This is why a crypto tax report, seemingly less sensitive than a bank card number, has become one of the most sought-after items on underground markets.
Reconnaissance: building a target portfolio.
Before any attack, threat actors aggregate information from multiple sources: data breaches from exchanges, crypto tax software databases, hardware wallet buyer lists and social media where influencers publicly display their positions. The objective is not to compromise a system. It is to build a precise map of cryptocurrency holders in France, ranked by estimated wealth, geographic location and public exposure level. The waltio.json file is exactly that: a directory of pre-qualified targets, with addresses and asset volumes attached.
Intrusion: targeting the weakest link.
Once targets are identified, the attacker looks for the most cost-effective path to their data. Rarely the main platform, which typically has the strongest defences. More often the peripheral provider: the tax software, the payment provider, the reporting tool. These actors handle high-value data with security capabilities that often fall short of their clients’. A poorly secured portal, an exposed API, an admin interface protected by a weak password: the intrusion may take a few hours. Access to the data of tens of thousands of users, a few minutes more.
Exfiltration: invisible until it appears on Telegram.
Data does not exit in one go. It moves in fragments, disguised as ordinary web traffic, through legitimate channels that standard monitoring tools do not flag. This explains the delay between intrusion and disclosure: by the time a file appears on a criminal forum or a Telegram channel, the attack typically occurred weeks or months earlier. For both Waltio and Ledger, the existence of the breach was discovered by journalists and users, not through internal detection.
Monetisation: multiple markets, escalating levels of violence.
This is where the crypto data breach diverges fundamentally from any other sector. Crypto data is monetised simultaneously at multiple levels: resale on criminal markets, personalised phishing, fake adviser fraud, and for high-wealth profiles, physical extortion. The same file can be used to send a fraudulent text message to 40,000 people and to plan the abduction of a handful of them. It is a criminal economy with variable returns depending on the buyer’s appetite and capabilities.
From Screen to Street: When Crypto Data Breaches Fund Kidnappings
This is where the picture shifts. Since late 2025 and through the early months of 2026, French law enforcement has recorded a series of kidnappings and physical extortion operations targeting cryptocurrency holders. The Balland case, the Noizet case, an abduction in the Drôme department. In each case, victims were identified and located using personal data from prior leaks, cross-referenced with public information about their digital holdings.
The SIRASCO (France’s strategic intelligence service on organised crime) has documented the modus operandi: digital reconnaissance from leaked data, identification of high-value targets, then physical action. Cybermalveillance.gouv.fr is also receiving numerous reports through its 17Cyber helpline: fake bank advisers, fake crypto platform employees and, in the most serious cases, individuals impersonating law enforcement officers seeking to obtain seed phrases, sensitive documents or access to assets. Kidnappings and unlawful detention cases were still being reported to French authorities in January 2026.
Attackers do not need to compromise a wallet. They need to know who owns one, where that person lives, and what their wealth level is. A tax report, a delivery address linked to a hardware wallet purchase, a JSON file circulating on Telegram: that is sufficient to plan an operation.
What MiCA and DORA Now Require from Crypto Operators
The crypto data breach risk is no longer theoretical from a regulatory standpoint. Since January 2025, MiCA (Markets in Crypto-Assets) imposes formal obligations on CASPs (Crypto-Asset Service Providers) regarding the security of digital assets, technology risk management and client fund segregation. DORA, which applies to crypto service providers on the same basis as financial institutions, requires enhanced operational resilience and documented third-party risk management.
Three Workstreams Crypto Operators Cannot Defer
The 2026 incidents raise very concrete questions in light of these frameworks. Ledger’s e-commerce provider and the subcontractor involved in the Waltio compromise fall squarely within the third-party risk management scope that MiCA and DORA make enforceable. Critical supplier mapping, contractual security clauses, audit rights and continuity plans are no longer optional best practices.
For sector players, three workstreams cannot wait. First, map every provider handling data that could identify digital asset holders and formally assess their security posture. Second, actively monitor for data leaks on criminal markets: the waltio.json file was circulating on Telegram before most of the platform’s users had been notified. Third, build a tested, operational incident response process, as MiCA and DORA impose notification timelines that few players are currently capable of meeting.
The real question for a crypto company executive or a financial adviser supporting clients with digital assets is this: if your clients’ data appeared on a Telegram channel tomorrow, would you know in time to act?
Stroople is an Expert Cyber certified firm and member of the Cybermalveillance.gouv.fr network. We support financial and crypto organisations in monitoring their data breach exposure and achieving MiCA and DORA compliance.
Key Takeaways – Crypto data breach France incidents in 2026: Ledger, Waltio, ZenLedger.
Ledger (Jan. 2026): crypto data breach via provider Global-e. Names and home addresses exposed. Digital assets not compromised. Waltio (Jan. 2026): tax records of 50,000 French users exfiltrated. File circulating on Telegram. Investigation opened by the Paris Public Prosecutor’s Office, assigned to UNCyber. ZenLedger (Jan. 2026): data from accountants, wealth managers and finance executives on sale on Breach Forums. Crypto tax data is high-value criminal intelligence, even without private keys or seed phrases. In France, kidnappings have been planned using leaked data. The digital risk has materialised into documented physical threat. MiCA and DORA now make third-party risk management mandatory for crypto operators: mapping, contractual clauses, audit rights.
Share:
External Attack Surface Management
See your exposure before attackers do. Know what's already compromised.
of successful breaches start from publicly exposed assets.
