Lego website hacked in crypto scam incident

The unauthorized banner promoting a fictional “Lego coin” appeared on Lego’s website while the company’s headquarters were closed.

Advertisement

On the evening of October 4, visitors to Lego’s official website encountered a surprising and misleading banner that claimed the launch of a new cryptocurrency called “Lego coin.” The banner featured illustrated golden coins adorned with the Lego logo and touted enticing “secret rewards” for users who purchased the fictitious currency. However, this announcement was not an official move by Lego but rather a scheme orchestrated by malicious actors who had hijacked the website to promote a crypto scam.

According to reports from, clicking on the “buy now” button led unsuspecting users to an external cryptocurrency website selling “LEGO Tokens” using Ethereum. The incident appears to have been a calculated attempt to exploit the Lego brand’s popularity to mislead users into investing in a fraudulent crypto venture.

As discussions unfolded on the Lego subreddit, it became evident that the unauthorized banner appeared overnight while Lego’s headquarters were closed. Thankfully, Lego responded quickly to the situation, removing the scam banner and restoring the website to its normal state, featuring a collaboration with Fortnite instead.

Advertisement

In a statement, Lego confirmed that no user accounts were compromised during the incident and assured customers that the issue had been resolved promptly. The company acknowledged that it had identified the root cause of the hack and was implementing measures to enhance its website security and prevent such occurrences in the future. However, specific details regarding the cause of the hack and the security measures being put in place have not been disclosed.

In an official statement issued on October 5, the company noted, “On October 5, 2024 (evening of October 4 in the US), an unauthorized banner was briefly visible on LEGO.com. It was promptly taken down, and the matter has been addressed. No user accounts were compromised, and customers can continue their shopping experience without interruption. We have identified the cause of the issue and are taking steps to ensure it does not occur again.”

This incident highlights the vulnerabilities that even well-established brands like Lego can face in the digital landscape. As cyber threats continue to evolve, it serves as a reminder for companies to remain vigilant and proactive in safeguarding their online presence to protect their customers and their reputation.