Tell HN: Data from ZenLedger customers leaked
I get that this is a a "vendor breach", but still inexcusable. If you send my PII to someone else without my explicit consent, then it's your responsibility to ensure the vendor will protect it properly (and your fault when it doesn't).
---
Dear ZenLedger Customer,
A third party vendor suffered a data breach resulting in the exposure of some of your personal contact information. We have ended our relationship with this vendor and are actively working to understand further details.
This was not a breach of ZenLedger or our systems. Your ZenLedger account and transactional information is safe and unaffected.
The information gathered from the breach included items such as name, address, email address and phone number. The download did not include any passwords, password hashes, or credit card numbers.
As a best practice, be aware of phishing attempts from outside parties and always double check the address of the sender/domain. Messages from our team will always come from @zenledger.io.
Never provide anyone with your personal information or sensitive details without first verifying the authenticity of the request. ZenLedger will never ask for your private keys or access to your accounts.
If you have any questions or concerns, please reach out to security@zenledger.io
Thank you,
Pat Larsen CEO, ZenLedger