Pocket Bitcoin, a regulated non-custodial Bitcoin purchasing service based in Switzerland, disclosed that a security breach in its support system exposed personal data belonging to 5,411 customers. The company says no misuse of the compromised information has been detected so far.
The incident, which unfolded over roughly a week in mid-August 2026, involved unauthorized access to an internal database tied to Pocket Bitcoin’s customer support infrastructure. The company cut off the intruder’s access by August 16 and publicly announced the breach on August 21.
What was exposed, and what wasn’t
A detailed breakdown released on August 31 split the affected users into two groups. The first, comprising 291 individuals, had their correspondence with financial institutions compromised. That correspondence included names, addresses, and pieces of documentation, the kind of material that tends to surface during compliance exchanges with partner banks.
The second and much larger group, 5,120 customers, had transaction lists exposed. These lists, provided by partner banks, contained personal data tied to bank transfers.











