← Blog

Pocket Bitcoin Breach: 5,411 Customers Hit via Support

Share on X

August 2026: Swiss non-custodial Bitcoin buy/sell service Pocket Bitcoin confirmed a sustained cyberattack that reached an internal support-system database holding emails, support chats, and — for two narrower cohorts — partner-bank correspondence and transaction lists. Roughly 5,411 customers sit in those higher-sensitivity buckets; core customer, KYC, and transaction databases were not compromised, and funds were never at risk. Canonical: pocket-bitcoin-support2026. Primary sources: Pocket Bitcoin notice (21 Aug), update (31 Aug), Crypto Briefing.

This is not a hot-wallet drain story. Pocket Bitcoin is regulated in Switzerland and does not custody coins. Private keys never leave the customer's device. What leaked was the messy middle of a regulated on-ramp: support tickets, attachments, and bank compliance paperwork that lived beside the helpdesk instead of inside the hardened customer vault.

If you used Pocket Bitcoin and got a personal email after the August 31 update, read that message carefully — it tells you which group you are in and which fields apply to you. If you did not get a personal email, the company says only the broader August 21 picture (email plus support correspondence) applies.

What happened: Pocket Bitcoin data breach timeline

Pocket Bitcoin says it was hit by a sustained cyberattack lasting about a week in mid-August 2026. Operators responded as the intrusion unfolded, hardening systems and applying updates while the attacker still had a foothold.

By Sunday, August 16, 2026, the company cut off the attacker's access. That containment date matters: everything that follows is forensic discovery, not ongoing live access.

On Wednesday, August 19, investigators found that an internal database containing email addresses and customer support communications had been accessed and copied during the attack window. That database sat in the support stack — not the systems that hold customer profiles, KYC dossiers, or transactional ledgers.

On Friday, August 21, Pocket Bitcoin published its first public notice. The early post was deliberately narrow: emails and support conversations (including attachments) were in scope; bitcoin addresses, the customer database with KYC data, and transaction history were listed as not affected — meaning those dedicated systems were not breached. The company also said anyone with additional sensitive material in support threads would get a personal email within about a week.

The first notice answered the questions customers ask first. Are my bitcoin safe? Yes — private keys were never stored. Is it safe to keep buying and selling? Yes — the service stayed up. Do I need to change my Pocket email? No. Could attackers see purchase amounts from the transaction database? No, unless a customer had pasted those details into a support reply. That early clarity helped, but it also left a gap: compliance paperwork sitting in the same support backup had not yet been fully inventoried for the public.

On Monday, August 31 (with a later refresh through early September), Pocket Bitcoin published a detailed update. The forensic work was complete. Two concrete cohorts emerged from how compliance paperwork had been stored in the same support system backup that was copied. Combined, those cohorts total about 5,411 customers: 291 in Group 1 and 5,120 in Group 2. Crypto Briefing and other trade coverage rounded the same census.

Pocket Bitcoin reported the incident to the Swiss Federal Data Protection and Information Commissioner (FDPIC), to Liechtenstein's data protection office under GDPR where applicable, and to police. Buying and selling remained operational throughout.

What was exposed — and for whom

Think of the Pocket Bitcoin breach 2026 disclosure as three layers, not one undifferentiated dump.

Baseline exposure (support correspondence)

Across the incident, attackers obtained access to material in the support system: emails tied to customer support, chat threads (email with [email protected], Telegram, WhatsApp), and attachments people had sent while troubleshooting. Telegram handles and WhatsApp numbers that appeared in those channels should be treated as exposed for anyone who used them.

That baseline is why phishing risk spiked even for people outside the two named groups. Real support language, ticket context, and contact channels make spoofed outreach more believable. A fake "we need one more ID photo" message lands harder when the attacker already knows how you talk to support.

Group 1 — 291 customers: bank correspondence in support

As a regulated firm, Pocket Bitcoin must verify identity and, for some transactions, source of funds before a purchase or sale clears. That process includes correspondence with the partner bank that processes payments. Portions of that correspondence were stored in the support system and were part of the copied backup.

Across Group 1, fields appear in varying combinations — most people do not have every item:

  • Names
  • Postal addresses
  • Bitcoin addresses used for transactions
  • Copies of identity documents
  • Source-of-funds documentation

This is the sharper privacy hit. A bitcoin address on its own is public blockchain data. Linking that address to a legal name, home address, and ID scan is a different problem. Anyone who can read the chain can then associate on-chain history with a real person. Amounts can also appear inside Group 1 correspondence and proof-of-origin documents even though the main transaction database was untouched.

Group 2 — 5,120 customers: partner bank transaction lists

During compliance checks, some partner banks sent Pocket Bitcoin time-bounded overviews of bank transfers. Those lists lived in the support system and rode along in the exposed backup. Many people in this group never personally uploaded the documents that named them — the bank did.

Group 2 exposure includes:

  • Names
  • Addresses
  • Individual bank transfers with amounts and dates
  • In some cases, the IBAN of the account that funded a transfer

An IBAN is an account identifier, not a password or remote-access token. Pocket Bitcoin is explicit: nobody can move money from your bank balance with an IBAN alone. Still, names, addresses, amounts, and dates are enough for targeted social engineering — forged letters that cite a real transfer, or phone scripts that sound like your bank.

Pocket Bitcoin says both categories are fully analysed. It does not expect further cohorts. If something new appears contrary to that expectation, the company says it will post on the blog and email those affected.

What was not compromised

This distinction is easy to blur in headlines, so keep it crisp.

Pocket Bitcoin's customer database (profiles and KYC holdings), its dedicated transaction database, and private keys were not compromised. The August 21 post said bitcoin addresses, KYC, and transaction history systems were not affected. The August 31 update clarified the nuance without walking that back: those systems still were not breached, but some of the same data types appeared inside support-held bank correspondence and lists that were copied.

In plain English: attackers did not empty the KYC vault. They got a support backup that sometimes contained KYC-adjacent paperwork because compliance workflows had parked copies there.

Funds were never at risk. Pocket Bitcoin is non-custodial. Private keys never leave the device. The company never held spendable access to customer bitcoin, so this incident could not move coins.

As of the company's early-September refresh, Pocket Bitcoin said it had no indication the disclosed information had been misused — based on what it could see at the time, not a guarantee about the future.

Are funds and wallets safe?

Yes, for the reasons that matter on-chain.

Spending bitcoin requires private keys. Those keys stay on the customer's device. Disclosing a receive address does not grant spend rights. Disclosing an IBAN does not unlock a bank login. Disclosing a support chat does not reset a wallet seed.

What changes for Group 1 is privacy and targeting risk. If your name is newly paired with a bitcoin address, observers can watch that address's balance and history. Moving coins to a fresh address does not erase past chain history, but it separates future activity from the disclosed address. Pocket Bitcoin itself frames that choice as optional privacy hygiene, not an emergency evacuation.

Pocket Bitcoin will never ask for your seed phrase — not by email, not by letter, not by phone. Any message that asks for 12 or 24 recovery words is fraud, full stop. The same rule applies to "recovery portals," QR codes in letters, and Telegram accounts that claim to be Pocket support after a breach.

Who is at risk after the Pocket Bitcoin breach 2026

Risk is uneven. Match yourself to the company's categories.

Group 1 (291): Highest privacy stakes. Identity documents, source-of-funds packs, and especially name-to-bitcoin-address linkage enable doxxing, blackmail narratives, and highly tailored phishing. Treat postal mail and phone calls that reference prior Pocket activity as hostile until you verify through official channels you initiate yourself.

Group 2 (5,120): Banking metadata risk. Names, addresses, transfer amounts/dates, and some IBANs feed convincing bank-impersonation scams. Watch for letters or calls that cite a specific transfer amount or date you recognize from Pocket purchases.

Everyone with support history: Even outside the 5,411, the August 21 notice covers emails and support communications. Expect spoofed Telegram, WhatsApp, or email traffic that quotes prior ticket language.

If you received no personal email: Pocket Bitcoin says nothing beyond the August 21 baseline applies. That still means treat support-channel phishing seriously; it does not mean you were in Group 1 or 2.

Geography matters only insofar as Switzerland and Liechtenstein regulators were notified. Customers elsewhere who used the service still face the same data-type risks if they appear in the cohorts. Was I affected? The operational answer is simpler than most breaches: check whether Pocket sent you a personal email describing your group. Absence of that email is the company's signal that you are outside the bank-doc cohorts.

Why support systems and KYC paperwork keep showing up in crypto breaches

Regulated bitcoin on-ramps sit in an awkward seam. They must collect KYC, talk to partner banks, retain records for years, and still convince users that "non-custodial" means coins stay safe. Support desks become accidental archives: ID scans forwarded during a stuck SEPA transfer, source-of-funds PDFs, bank lists pasted into tickets for compliance staff.

Attackers know this. Core wallets and cold infrastructure often get the security budget. Helpdesk databases, shared mailboxes, and temporary compliance folders get less attention — until a week-long intrusion copies them wholesale.

The Pocket Bitcoin data breach is a textbook version of that pattern. Customer and KYC databases held. The support system backup did not. Compliance correspondence that should have lived in a tightly scoped vault was reachable from the helpdesk plane.

Similar pressure shows up across crypto travel, exchange, and brokerage incidents whenever identity documents, wallet addresses, and banking rails share an operational inbox. The lesson is structural: treat support attachments like production PII, not disposable chat debris. Retention rules (Pocket notes a 10-year retention duty for certain records) make deletion requests hard — which raises the cost of every misplaced copy.

Switzerland's regulated on-ramp market sells trust. A support-system failure does not bankrupt that model, but it does remind buyers that "keys never leave your phone" and "your ID never leaves our vault" are two different promises. Only the first held cleanly here. For product and security teams elsewhere, the takeaway is blunt: if partner banks email you CSV-style transfer lists, those files are breach-critical the moment they land — store them accordingly, not next to Telegram transcripts.

What Pocket Bitcoin and regulators said

The company apologized plainly in the August 21 post, described containment on August 16, discovery on August 19, and urged phishing caution while stressing non-custodial safety. It notified Swiss authorities and police early.

The August 31 update did the harder work: named the two groups, gave headcounts, explained why bank correspondence and bank-sent lists were in the support backup, and corrected the public understanding without claiming the customer KYC systems had been cracked. It told readers that disclosed Group 1/2 data is not linked to email addresses or login credentials in the leaked sets — reducing one direct email-phishing vector from those particular fields — while warning that forged letters using real names and addresses remain a concern.

Pocket Bitcoin says everyone in the two groups is receiving a personal email describing exactly which fields apply. Future support traffic, the company states, runs through secured systems after the vulnerability was closed and additional protections were added. Buying and selling continued normally. The firm also said it is reviewing how it handles and transmits this class of compliance data with partner banks — including the awkward Group 2 case where people appear on bank lists without having uploaded the documents themselves.

Crypto Briefing summarized the same arc for a broader audience: Swiss non-custodial service, ~5,411 users in the detailed cohorts, no funds at risk, no confirmed misuse as of early September coverage.

For the BreachHistory catalog record and ongoing citations, use the canonical page at /pocket-bitcoin/pocket-bitcoin-support2026.

What you should do

Concrete steps beat generic advice. Prioritize by group if you know it; if you do not, start with phishing and bank vigilance anyway.

  1. Read your personal email if you got one. It assigns Group 1 or Group 2 and lists your fields. Keep it; do not forward it casually.
  2. Assume support-channel phishing. Urgent messages asking you to "verify," "unlock," or "recover" a Pocket wallet are hostile. Pocket never asks for a seed phrase.
  3. Verify out-of-band. If a letter, SMS, Telegram, WhatsApp, or email cites a prior transfer or support ticket, open the official Pocket site yourself and contact support from there. Do not use links or phone numbers inside the suspect message.
  4. Bank vigilance for Group 2 (and anyone with an exposed IBAN). Turn on transaction alerts. An IBAN alone cannot empty your account, but social engineers will try. Never approve unexpected bank callback requests that cite your Pocket activity.
  5. Identity-theft hygiene for Group 1. If ID copies and source-of-funds docs were involved, watch for secondary fraud — fake tax letters, fake bank KYC refreshers, or crypto compliance portals asking you to re-upload documents.
  6. Optional coin move if a bitcoin address was linked to your name. Moving funds does not erase chain history, but it separates future activity from the disclosed address. Do it only through your own wallet software; never via a third-party migration link in email.
  7. Do not panic-rotate your Pocket email. The company says accounts are not compromised by this incident and you do not need to change the linked email solely because of the breach.
  8. Limit what you paste into future support tickets. Prefer secure upload paths the company designates; avoid dropping full ID packs into casual chat if a narrower proof will do.

If you are unsure whether you were affected: no personal email after the August 31 wave generally means you are outside Groups 1 and 2, per Pocket Bitcoin. You may still want phishing caution if you ever emailed or chatted with support. What to do after a notice like this is mostly patience plus skepticism — not a race to abandon a non-custodial wallet.

Canonical record and sources

BreachHistory indexes this incident as a company-confirmed support-system exposure with a published two-group census totaling about 5,411 higher-sensitivity customers, plus broader support-correspondence risk described in the August 21 notice. Full write-up: https://breachhistory.com/pocket-bitcoin/pocket-bitcoin-support2026.

Primary sources:

The Pocket Bitcoin data breach will keep mattering as a case study in regulated crypto operations: coins can stay non-custodial and still leave a trail of bank lists, ID scans, and helpdesk attachments that deserve the same protection as the wallet itself. For readers tracking Switzerland on-ramp risk through 2026, this is the incident to cite when someone asks what a support-system breach looks like when the coins themselves never moved.