Pocket Bitcoin said a security breach in its customer support system exposed personal data belonging to 5,411 customers of the Swiss-licensed non-custodial Bitcoin purchasing service. The firm first disclosed the August incident on August 21 and issued initial findings on August 31, then confirmed on September 3 that the scope was larger than first estimated. Affected users fall into two groups: 291 customers whose communication data with partner banks for identity verification and proof-of-funds—including names, mailing addresses, Bitcoin addresses, identification-document copies and proof-of-funds records—was compromised; and 5,120 customers whose partner-bank transaction lists were exposed, including names, addresses, transfer amounts and dates, and in some cases originating-account IBANs. Pocket Bitcoin detected the attack and blocked access on August 16 and by August 19 confirmed that email addresses and consultation records had been duplicated. It said its customer and transaction-history databases were not breached, no Bitcoin or private keys were exposed, and purchased Bitcoin is sent directly to users’ wallets under a non-custodial model that never holds customer assets. The company patched the vulnerability, applied further security measures, completed a forensic investigation, notified affected people by individual email, and reported the incident to the Swiss Federal Data Protection Authority. As of the September 3 update, no evidence showed the leaked data had been misused, though users were urged to watch for more credible phishing that could exploit exposed names, addresses and transfer details.