Sat, September 5

Pocket Bitcoin Data Breach Reveals Personal and Financial Data of 5,411 Customers

Bitcoin Market News
  • Pocket Bitcoin found two datasets that were breached, affecting 5,411 customers following its investigation process.
  • There was no compromise to core databases, customer Bitcoin, and private keys, and the authorities have been notified about the breach.

The Pocket Bitcoin has now widened its August security breach scope following its full forensic analysis. According to the Swiss Bitcoin company, there were two data sets in connection to the security issue involving 5,411 users. While the first dataset included bank transactions records for 5,120 users, the second one consisted of communication records of an additional 291 users.

Exposed Bank Records During Compliance Checks

The bigger data set was collected through transaction lists that Pocket Bitcoin received from partner banks during the compliance checks. The list comprised customers’ names, residence address, amount of transactions and dates. Some of these lists also had the IBAN number related to the individual transactions. Second data set was gathered through the correspondence of Pocket Bitcoin and its partner banks. Depending on customers, the correspondence contained information about postal addresses, Bitcoin public addresses, and copies of identity documents. Some of the correspondence also contained the source-of-funds information.

Pocket Bitcoin explained that the customers did not necessarily have each of the above types of information exposed. Pocket Bitcoin contacted each affected customer and gave him information about his case. Another type of information could be exposed to customers during the initial breach – email addresses or support communications.

Bitcoin Core Assets Were Unaffected

Pocket Bitcoin extended its statement regarding the August security incident following a forensic investigation into exposed information about 5,411 users. This compromised information comprised names, addresses, transaction history, and some IBANs, while for 291 users, there was a risk of compromising identity documents and funding information. Bitcoin Pocket stated that its core systems, user Bitcoins, and keys were unaffected by this security compromise. There were no indications of any misuse, but the risk of physical fraud was indicated.

Customers Notified About Physical Fraud

Pocket Bitcoin said that there is currently no reason to believe that any of the data was used by attackers for any malicious actions. However, the names, addresses, and transfer information can be used to conduct a more convincing social engineering attack against the targeted customers through physical communication channels.

The threat of fake letters and other physical communication was explicitly raised by Pocket Bitcoin. The company noted that the newly found databases do not have any information regarding email addresses and passwords, which makes it unlikely that targeted email phishing attacks can be conducted with their use.

Pocket Bitcoin informed the Swiss Federal Data Protection and Information Commissioner and the Liechtenstein Data Protection Authority about the breach. They also filed a police report after the investigation of the incident. The vulnerability has been closed, and new security measures have been implemented.

Highlighted Crypto News:

CFTC Seeks Dismissal of CME’s Kalshi Bitcoin Futures Lawsuit

I specialize in Web3 and crypto writing, producing clear, research-driven content on blockchain, cryptocurrencies, and market trends.