Crypto Prices

Pocket Bitcoin Faces Data Breach Affecting Over 5,400 Users’ Information

22 hours ago
2 mins read
7 views

Security Incident Overview

On September 3rd, Pocket Bitcoin revealed that a security incident that occurred in August has resulted in the exposure of personal and financial details belonging to 5,411 customers, increasing the number initially reported. Following a thorough forensic examination, the Swiss cryptocurrency service provider identified two separate groups of affected individuals.

Affected Groups

The first group, which involved the largest number of customers, comprised bank transaction data affecting 5,120 individuals. This information includes customer names, addresses, transaction amounts, and dates, and in some cases, even the IBANs associated with transfers, all derived from transaction lists shared by partner banks during compliance checks.

The second group, consisting of 291 customers, dealt with sensitive correspondence exchanged between Pocket Bitcoin and these partner banks. Depending on individual cases, the data involved included names, residential addresses, public Bitcoin addresses, copies of identity documents, and records verifying the source of funds. However, it’s important to clarify that not every affected customer had all types of data exposed. Pocket Bitcoin has reached out to the individuals impacted, providing them specific details regarding their records.

Data Security and Breach Details

In total, 5,411 customers were affected by this breach. Other users may have experienced exposure of their email addresses or support interactions based on prior disclosures, but those not receiving individualized notifications are advised to trust the information already provided in earlier communications.

Pocket Bitcoin emphasized that its primary databases containing customer transactions and account information were not breached. The leaked data stemmed instead from backup copies related to communications and bank-generated documents stored within a compromised support system. This distinction is critical because it explains the exposure of transaction-related and identity records without compromising the security of the core databases.

Noncustodial Service Assurance

As a noncustodial service, Pocket Bitcoin does not maintain users’ private keys, and the company confirmed that the attacker had no access to users’ Bitcoin balances. Transactions can continue to be processed without interruption. It noted that while a public Bitcoin address does not facilitate transaction authorization, it can potentially be linked to an individual’s identity, allowing others to scrutinize its blockchain activities. However, the visibility of past transactions remains intact, even if Bitcoin is transferred to a new address.

Potential Risks and Company Response

Currently, Pocket Bitcoin has no evidence to suggest that the exposed information has been misused, although this assessment is based on findings from its investigation and does not rule out the possibility of future misuse. The company acknowledged that the combination of exposed names and addresses could make individuals susceptible to impersonation attempts, particularly through forged documents referencing actual bank transfers or Bitcoin transactions.

Importantly, email addresses and login details were not intertwined with the newly identified data categories, minimizing risks of targeted phishing campaigns specifically sourced from this incident.

Industry Context and Regulatory Actions

This revelation comes amidst a wave of data leaks within the cryptocurrency sector, where various recent incidents have highlighted serious vulnerabilities. For instance, other breaches have exposed over 253,487 records that may aid phishing scams or further targeting of individuals based on their transaction histories. Another incident involving Bits of Gold in August raised similar privacy concerns, despite customer assets and passwords remaining secure.

In response to this incident, Pocket Bitcoin has reported the matter to both the Federal Data Protection and Information Commissioner in Switzerland and the Data Protection Office in Liechtenstein. They have also filed a police report but withheld information regarding the suspected perpetrator or specific details of the ongoing investigation.

Future Measures and Customer Advisory

The company has since closed the identified security gap and implemented additional protective measures, reviewing how its bank correspondence and compliance records are handled. Pocket Bitcoin plans to share further updates about these improvements in the weeks ahead, although it does not anticipate discovering new categories of exposed information. Customers are advised to remain vigilant with their bank activities and to be cautious of unprompted communication by treating unexpected correspondence, calls, or alerts with skepticism. The company has also reassured that it will never request sensitive information such as seed phrases or initiate unsolicited Bitcoin transfer requests.

Popular