Pocket Bitcoin Says August Breach Exposed More Customer Data Than First Reported
Pocket Bitcoin issued a new update on 3 September. The Swiss Bitcoin service said an August security incident affected more personal and financial information than its first notice described. Forensic work identified two groups of customers. Bank transaction details from 5,120 clients formed the first group. Correspondence involving 291 clients formed the second. Together, the two groups cover 5,411 users.
Partner banks had sent transaction lists to Pocket Bitcoin during routine checks. Those lists make up the larger set. The records included names, home addresses, transfer amounts, and transfer dates. In some cases, they also included the IBAN tied to a transfer.
The smaller set came from messages between Pocket Bitcoin and its partner banks. That correspondence exposed different details for different people. Some files included names and mailing addresses. Others included Bitcoin addresses or copies of identity documents. The company said the leaked items appeared in mixed combinations. Not every person in the group of 291 had every type of record.
Pocket Bitcoin has contacted affected customers one by one. Some users named in an earlier notice may not appear in this new count. Anyone who received no new message should rely on the company’s first notice.
The firm said attackers did not breach its main customer and transaction database. The exposed material came from emails and from bank-generated lists stored in a backup copy. That is why some records look like transaction or identity files even though the core databases stayed closed. The leaked support files were copies created or received for regulatory checks.
Pocket Bitcoin also said the attacker never reached Bitcoin accounts. Buy and sell services continue to operate. So far, the company has seen no sign that the published information has been used for further harm.
The firm reported the case to the Swiss Federal Data Protection and Information Commissioner. It also notified the Liechtenstein Data Protection Authority. In addition, it filed a police report. It did not name a suspected attacker.
A separate August case involved SafePal. That company said a flaw in an order-tracking plugin put order data from about 39,798 customers at risk. The records covered orders placed from 2 March 2025 through 11 April 2026. They included names, email addresses, shipping addresses, phone numbers, and purchase details.
Both notices point to the same lesson. Companies should limit how long they keep copies of identity and payment records. Customers should watch for unexpected messages and should change passwords on related email accounts when a firm reports a leak.
Leave a comment