On September 3, Pocket Bitcoin announced that an incident from August had resulted in the exposure of more personal and financial details concerning 5,411 customers, broadening the scope beyond what was originally reported.

Summary

  • Pocket Bitcoin revealed that two sets of exposed data involved a total of 5,411 customers.
  • Bank transaction disclosures included customer names, addresses, amounts transferred, dates, and sometimes their IBAN account numbers.
  • Additionally, 291 customers were at risk of having their identity documents, Bitcoin addresses, and sensitive financial records exposed.
  • The company confirmed that its customer databases, transaction systems, private keys, and customer Bitcoin were directly unaffected.
  • Reports have been made to authorities in Switzerland and Liechtenstein, and Pocket has also submitted a formal police report.

Following its forensic investigation, the Swiss Bitcoin services provider found two separate groups of exposed data. One group involved bank transaction details of 5,120 customers, while the other included more sensitive correspondence from 291 customers.

Pocket Bitcoin breach revealed two segments of data

The larger segment consisted of transaction information sent to Pocket Bitcoin by partner banks for compliance audits. These records included customer names, home addresses, amounts transferred, and transaction dates, with some containing the IBAN linked to a transfer.

The smaller segment comprised correspondence that Pocket Bitcoin had shared with partner banks. Depending on the case, exposed information included names, physical addresses, public Bitcoin addresses, copies of identity documents, and source-of-funds verifications.

The information was not uniformly exposed for all 291 customers; different combinations of data were compromised. Affected customers have been notified individually with specific details related to their cases.

In total, these two segments affected 5,411 customers. Others might have had their email addresses or support conversations compromised according to Pocket’s initial announcement. Nonetheless, Pocket advised that those without a new personal notification should adhere to the initial advisory.

Main databases and customer Bitcoin remained secure

Pocket Bitcoin reassured users that its core customer and transaction databases were not breached. The compromised records arose from correspondence and lists generated by banks that were securely stored in a backup related to the affected support system.

This distinction clarifies why transaction and identity data were disclosed, despite the core databases remaining intact. The affected support documentation consisted of copies of information generated or received during regulatory compliance efforts.

A noncustodial service, Pocket Bitcoin does not manage customers’ private keys. The company emphasized that attackers could not access Bitcoin balances, and services for buying and selling continue to function normally.

It is important to note that while a public Bitcoin address cannot facilitate a transfer on its own, connecting it to a customer’s identity may allow others to view its blockchain transaction history. Moving Bitcoin does not erase previous transaction details linked to the address.

Exposed data raises phishing threats

Pocket Bitcoin has stated that there is currently no evidence of misuse of the exposed information. However, this conclusion is based on their investigation and does not rule out future misuse.

“As of now, we do not see any indication that the exposed information has been misused,” Pocket Bitcoin stated.

The company highlighted that the inclusion of names and addresses could create risks for physical phishing attempts. Fraudsters might reference legitimate bank transfers or Bitcoin transactions to enhance their impersonation strategies.

According to Pocket Bitcoin, email addresses and login details were not included in the newly identified data groups, so they do not foresee a heightened risk of targeted email phishing stemming from these records.

This incident follows multiple disclosures involving customer data stored outside of core cryptocurrencies systems. As noted by crypto.news, three recent breaches affected 253,487 records, prompting concerns that residential and transaction data could potentially facilitate phishing or physical targeting over time.

A separate incident in August involving Bits of Gold could have exposed customer identity, banking, and wallet information via a third-party system. Similar to Pocket Bitcoin’s case, it was found that customer funds and passwords were unaffected.

Pocket Bitcoin has alerted authorities and law enforcement

Pocket Bitcoin has notified both the Federal Data Protection and Information Commissioner in Switzerland and the Data Protection Office in Liechtenstein. A police report has also been filed, though details regarding the suspected perpetrator have not been disclosed.

The company indicated that they have closed the vulnerability that led to this incident and implemented additional security measures. They are currently reassessing how bank correspondence and associated compliance documentation are managed and shared.

Further information regarding these changes is expected to be released in the coming weeks. While the likelihood of discovering additional exposure categories appears low, the company indicated it would inform customers if any new findings alter that assessment.

Customers are advised to monitor their bank statements closely and remain cautious of unexpected communications. Pocket Bitcoin emphasized that they will never request customers to share a seed phrase or make Bitcoin transfers via unsolicited calls or messages.

Share.