Swiss Bitcoin Pay has temporarily taken its servers offline after discovering that a malicious user may have gained access to the company’s internal systems.
The non-custodial merchant payment processor said on Monday that the incident could have exposed customer email addresses, Bitcoin addresses, IBANs, transaction histories and hashed passwords.
Swiss Bitcoin Pay, which was founded in late 2022, enables merchants to accept bitcoin. Its website says the application is used by more than 1,000 merchants across 21 countries.
In a statement posted on its official X account, the company said: “A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems. As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure.”
The firm said it was still investigating the extent of the possible access and did not know when its services would be available again.
“Our team has reasons to believe that the user may have accessed customer email addresses, Bitcoin addresses and IBANs, transaction history, and hashed passwords,” it added.
Swiss Bitcoin Pay said customer funds were “safe” and promised that “any amounts owed to users will be fully returned”.
The incident comes during a year in which the cryptocurrency industry has faced a series of data breaches. The source article also refers to an incident involving Revolut this week, after the company reportedly responded to an email from a government-agency domain operated by a malicious actor.
Revolut reportedly disclosed home address information, email addresses, phone numbers, copies of passports or driving licences, verification selfies and IBANs.
Other companies named in connection with data breaches in 2026 include Trezor, Pocket Bitcoin, Bits of Gold and Safepal.
Customers affected by breaches at any of these companies should assume that personal details, including email addresses, phone numbers and home addresses, may be known to criminals, according to the advice in the source article.
They have been urged to remain alert for phishing attempts, fake customer-support messages, fraudulent letters and calls from unidentified numbers.
The source article also contains a repeated, incomplete reference to an institution sharing personally identifiable information belonging to an unknown number of users after receiving a request from an unauthorised government source. It does not identify the institution or provide further details.
