Swiss Bitcoin Pay has taken its server operations fully offline after confirming suspected unauthorized access to internal systems that may have exposed customer contact, financial and transaction information. Potentially compromised data includes email addresses, Bitcoin addresses, IBANs, transaction histories and hashed passwords, though the company has not determined whether data was exfiltrated or whether other information was accessed. It has not disclosed the number of affected accounts, the timing of the intrusion or its access vector. The company said its non-custodial payment model keeps customer funds outside its custody and that no unauthorized Bitcoin transfers or breach-related losses have been confirmed. Swiss Bitcoin Pay said it will fully refund amounts owed to users after completing infrastructure security measures, without setting a service-restoration date. The data combination could increase the risk of targeted phishing, particularly for users whose email, payment and banking details were exposed.