NewsCryptoPocket Bitcoin Says August Data Breach Exposed Information of More Than 5,400 Customers

Pocket Bitcoin Says August Data Breach Exposed Information of More Than 5,400 Customers

Author: Hokanews·

Key Takeaways

  • Pocket Bitcoin disclosed that an August security incident exposed data of more than 5,400 customers, including banking details for 5,120 of them.
  • A subset of 291 customers had more sensitive information exposed, potentially including identity documents, source-of-funds records, Bitcoin addresses, and residential addresses.
  • The company stated its customer and transaction databases were not compromised and that Bitcoin holdings and private keys were unaffected because customers hold self-custody.
  • Pocket Bitcoin reported the incident to data protection authorities in Switzerland and Liechtenstein and to the police.
  • The company said there is currently no indication that the exposed information has been misused, though privacy and security risks remain for affected customers.
Pocket Bitcoin Says August Data Breach Exposed Information of More Than 5,400 Customers

Swiss Bitcoin financial services provider Pocket Bitcoin has disclosed that an August security incident exposed personal and financial information belonging to more than 5,400 customers, including banking details and, in a smaller number of cases, more sensitive records.

According to information published by @WuBlockchain, Pocket Bitcoin said data from 5,120 customers was exposed in the incident. The affected information included names, addresses, bank transfer amounts and dates, while some records also contained IBANs.

A further 291 customers had more sensitive information exposed. According to the company, this data potentially included identity documents, source-of-funds records, Bitcoin addresses and residential addresses. Records of this kind are typically collected by regulated crypto financial firms to satisfy anti-money-laundering and know-your-customer requirements, which is why even firms that never touch customer private keys still hold large volumes of sensitive personal data.

Customer and Transaction Databases Were Not Compromised, Company Says

Pocket Bitcoin stated that its customer and transaction databases were not compromised during the incident. Instead, the exposed information originated from bank correspondence and transaction lists stored within the company's affected support system.

The distinction is significant because, according to the company, the incident did not involve the core databases containing customer transaction records. Pocket Bitcoin also said that Bitcoin holdings and private keys were not affected. Pocket Bitcoin operates a model in which customers buy Bitcoin through the platform and hold it in self-custody, meaning the company does not manage customer private keys — a design that limits the direct financial exposure of a breach such as this one to personal data rather than funds.

The company said there is currently no indication that the exposed information has been misused. However, the disclosure of banking information, residential addresses and source-of-funds records could create potential privacy and security risks for affected customers, particularly if the information is later combined with data obtained from other sources.

Data Protection Authorities and Police Notified

Pocket Bitcoin said it has reported the incident to data protection authorities in Switzerland and Liechtenstein, as well as to police. Disclosure to regulators of this kind aligns with the obligations companies face under Swiss data protection law, which since its 2023 revision requires notification of breaches involving personal data in many circumstances, as well as the European Union's General Data Protection Regulation, which applies to firms serving EU customers and generally requires notification of qualifying breaches within 72 hours.

The response places the incident within the broader regulatory focus on cybersecurity and personal-data protection across financial services. Crypto companies handling banking information and identity records face additional risks, because compromised personal data can potentially be used for fraud, social engineering or targeted attacks even when digital assets and private keys remain secure. Similar incidents at other crypto firms, including exchange-level breaches that exposed customer identity records, have shown that data-only compromises can still cause significant customer harm and reputational damage.

The immediate focus for Pocket Bitcoin and affected customers will therefore be determining the full scope of the exposed information and monitoring whether any misuse emerges following the disclosure.

Source: Hokanews