4 Вересня, 2026
Pocket Bitcoin breach exposes 5,411 customer records thumbnail
Бізнес

Pocket Bitcoin breach exposes 5,411 customer records

Pocket Bitcoin said on Sept. 3 that its August security incident exposed additional personal and financial information involving 5,411 customers, expanding the scope described in its initial disclosure. Summary Pocket Bitcoin confirmed that two exposed data groups contained records involving 5,411 customers in total. Bank transaction lists exposed names, addresses, transfer amounts, dates and sometimes”, — write on: www.crypto.news

Pocket Bitcoin said on Sept. 3 that its August security incident exposed additional personal and financial information involving 5,411 customers, expanding the scope described in its initial disclosure.

Summary

  • Pocket Bitcoin confirmed that two exposed data groups contained records involving 5,411 customers in total.
  • Bank transaction lists exposed names, addresses, transfer amounts, dates and sometimes customer IBAN account numbers.
  • Another 291 customers faced possible exposure of identity documents, Bitcoin addresses and sensitive funding records.
  • Pocket said its customer databases, transaction systems, private keys and customer Bitcoin remained directly unaffected.
  • Authorities in Switzerland and Liechtenstein received notifications, while Pocket also formally filed a police report.

The Swiss Bitcoin services provider identified two distinct groups after completing its forensic investigation. One contained bank transaction information involving 5,120 customers. The other covered correspondence containing potentially more sensitive records from 291 customers.

Pocket Bitcoin breach exposed two data groups

The larger group consisted of transaction lists that partner banks sent to Pocket Bitcoin during compliance checks. Those lists contained customer names, residential addresses, transfer amounts and transaction dates. Some also included the IBAN connected to a transfer.

⚠️ Update zum Sicherheitsvorfall bei Pocket Bitcoin

Unsere Untersuchung ist abgeschlossen.
Dabei hat sich gezeigt, dass in einzelnen Fällen weitere Daten betroffen sind als in unserem ersten Beitrag beschrieben.

Wir haben dazu zwei betroffene Gruppen identifiziert. https://t.co/XASbu1wTQH

— PocketBitcoin.com 🏦👉🔑 (@PocketBitcoin) September 3, 2026

The smaller group involved correspondence Pocket Bitcoin sent to partner banks. Depending on the customer, the exposed material included names, postal addresses, public Bitcoin addresses, identity document copies and source-of-funds records.

The company said the information appeared in different combinations, meaning every customer in the 291-person group did not necessarily have every listed data type exposed. Pocket Bitcoin has contacted affected customers individually with details about their cases.

The two groups cover 5,411 customers combined. Other customers may have had email addresses or support conversations exposed under the company’s original disclosure, but Pocket said those without a new personal notification should continue relying on that initial notice.

Core databases and customer Bitcoin were unaffected

Pocket Bitcoin said attackers did not compromise its main customer or transaction databases. Instead, the records came from correspondence and bank-generated lists stored in a copied backup within the affected support system.

This distinction explains why data resembling transaction and identity records was exposed even though the underlying databases remained secure. The affected support material contained copies of information produced or received during regulatory compliance procedures.

Pocket Bitcoin operates as a noncustodial service and does not hold customers’ private keys. The company said Bitcoin balances were never accessible to the attacker, while buying and selling services continue to operate normally.

A disclosed Bitcoin address cannot authorize a transfer. However, linking a public address to a customer’s identity may allow another person to inspect its visible blockchain activity. Pocket noted that moving Bitcoin cannot erase the address’s existing transaction history.

Exposed records create physical phishing risks

Pocket Bitcoin said it currently has no indication that the exposed information has been misused. That statement reflects information available after its investigation and does not guarantee that misuse will not occur later.

“As things stand, we have no indication that any of the affected information has been misused,” Pocket Bitcoin said.

The company identified forged letters and other physical communications as particular risks because names and postal addresses were included. A fraudster could refer to a genuine bank transfer or Bitcoin transaction to make an impersonation attempt appear credible.

Email addresses and login credentials were not linked to the two newly identified data groups, according to Pocket Bitcoin. The company therefore said it does not see a direct targeted email-phishing risk arising specifically from those records.

The incident follows several disclosures involving customer information held outside core crypto systems. As crypto.news reported, three recent breaches exposed 253,487 records, raising concerns that residential and transaction data could support phishing or physical targeting years later.

A separate August incident at Bits of Gold potentially exposed customer identity, banking and wallet information through a third-party system. That investigation similarly found that customer funds and passwords remained unaffected.

Pocket Bitcoin notified regulators and police

Pocket Bitcoin reported the incident to Switzerland’s Federal Data Protection and Information Commissioner and Liechtenstein’s Data Protection Office. It also filed a police report but did not identify the suspected attacker or provide details about the investigation.

The company said the vulnerability behind the incident has been closed and additional safeguards have been installed. It is reviewing how bank correspondence and related compliance records are stored and transferred.

Pocket expects to publish more information about those changes in the coming weeks. It does not expect to identify further exposure categories, although it said it would notify customers if later findings changed that assessment.

Affected users should monitor bank activity and treat unexpected letters, calls or messages cautiously. Pocket Bitcoin said it will never ask customers to disclose a seed phrase or transfer Bitcoin through an unsolicited telephone call or letter.

ПОВ'ЯЗАНІ НОВИНИ

Earning Bitcoin: The best BTC yield opportunities

cryptonews

Russen-Visum-Boom in der EU – Diese drei Länder lassen die meisten Russen rein

bild.de

Float Protocol hit by $28K flash loan attack through Uniswap V3 manipulation

cryptonews

Залишити коментар


Цей веб-сайт використовує файли cookie, щоб покращити ваш досвід. Ми припустимо, що ви з цим згодні, але ви можете відмовитися, якщо хочете. Прийняти Читати більше