User nano_cube shared a detailed story about how he became the target of a complex, multi-step scam. First, he received a call from the official Berlin police number. A woman introduced herself as a cybercrime officer and stated that a person had been detained at the airport with stolen databases that mentioned the 24-word key to the victim's hardware wallet. She asked him to check the keys and prepare them for a meeting at the police station to create the illusion of a real investigation and lull his vigilance.
The next day, the policewoman called back and said she had contacted the wallet manufacturer, and that a Ledger employee would now be reaching out to the victim. As user nano_cube writes, he immediately suspected something was wrong, independently called the real police, and confirmed it was a scam. Soon after, a "Ledger specialist" actually called, speaking professionally about vulnerabilities, and then directed the victim to a fake website to perform a "diagnostic scan".
The scammer convincingly explained that this was a secure, isolated subdomain, even though the top-level domain belonged to Cameroon. According to user nano_cube, the main goal was to get him to enter the 24 recovery words on this phishing resource.
In conclusion, user nano_cube reminds everyone of the main security rules: official Ledger support never calls customers on its own and never asks for a seed phrase. Furthermore, you cannot trust incoming calls, even if a real police number appears on the screen — it can easily be spoofed. If in any doubt, you should independently search for the organization's official contact number and call them back.
source
https://www.reddit.com/r/ledgerwallet/comments/1votx4x/psa_ledger_fake_support_diagnostic_site_scam/
https://www.reddit.com/r/ledgerwallet/comments/1vz6x6x/psa_sophisticated_fake_police_and_ledger_support/
Trust Rating
related to the category