Hooded figure viewed from behind sitting at multiple monitors showing code and a world map
TECHNOLOGY

Pocket Bitcoin breach exposes records of 5,411 customers

Image Credit: Shutterstock

Pocket Bitcoin has confirmed that an August cyberattack exposed personal and transaction information belonging to 5,411 customers, including identity documents, Bitcoin addresses and bank transfer records in some cases.

The Swiss Bitcoin service said no private keys or customer funds were compromised. Its forensic investigation is complete, and it has found no evidence so far that the exposed information has been misused.

291 Customers Had Identity Documents and Bitcoin Addresses Exposed 

The smaller group includes 291 customers whose correspondence with Pocket Bitcoin’s partner banks was stored in the affected support system.

Depending on the customer, the exposed material included names, postal addresses, Bitcoin addresses used for transactions, copies of identity documents and source-of-funds records.

Pocket Bitcoin said its core KYC and transaction databases were not breached. The sensitive information was exposed because copies of bank correspondence containing those details had been retained inside the compromised support infrastructure.

Where a Bitcoin address was exposed alongside identifying information, the breach can link that customer to the address and its publicly visible transaction history. It does not give the attacker control over the associated Bitcoin.

Bank Transfer Lists Exposed Another 5,120 Customers 

A second group of 5,120 customers appeared in transaction lists that partner banks had sent Pocket Bitcoin during compliance checks.

Those records contained names, addresses and individual bank transfers, including transaction amounts and dates. Some also included the IBAN of the bank account used to make a transfer.

The two groups bring the confirmed number of affected customers to 5,411. Pocket Bitcoin said both categories have now been fully reviewed, and it does not expect another group to emerge.

Attackers Accessed Support Systems for About One Week 

The breach unfolded over roughly one week in August. Pocket Bitcoin cut off the attacker’s access by August 16 and discovered on August 19 that an internal database containing email addresses and support communications had been copied.

The company first disclosed the incident on August 21 before expanding its findings on August 31 and updating them again on September 3. Pocket Bitcoin reported the breach to Switzerland’s Federal Data Protection and Information Commissioner and Liechtenstein’s Data Protection Office and also filed a police report.

The company said the vulnerability has been closed, and additional safeguards have been added. Affected customers are being contacted directly, with Pocket Bitcoin warning that exposed names, addresses, and transaction details could make fraudulent approaches more convincing.

More For You

Explore More News