Key Takeaways
- Swiss Bitcoin Pay disclosed Sept. 14 that info like emails, bitcoin addresses and IBANs may have fallen into the wrong hands.
- The company joins at least 5 crypto firms hit by data breaches in 2026, giving scammers more ammo.
- Swiss Bitcoin Pay says funds are safe, but its servers remain offline while the Sept. 14 breach gets sorted out.
Malicious User Gains Access to Swiss Bitcoin Pay Systems
2026 has not seen a shortage of data breaches, and on Sept. 14, Swiss Bitcoin Pay explained that its systems may have been accessed by a “malicious user.” The company, founded in late 2022, is basically a non-custodial BTC payment processor that merchants can use to accept bitcoin.
The firm’s website claims the application is leveraged by more than 1,000 merchants in 21 countries. On Monday, the official X account disclosed the information concerning the breach. “A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems. As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure,” Swiss Bitcoin Pay wrote.
The team then explained that they think the user may have “accessed customer email addresses, Bitcoin addresses and IBANs, transaction history, and hashed passwords.”
Crypto Industry Faces a Wave of Data Breaches
The news comes as 2026 has seen a tidal wave of data breaches in the crypto industry, and this week’s Revolut incident. According to the reports, Revolut responded to a government-agency email domain that was operated by a malicious operator.
Revolut reportedly revealed home address info, emails, phone numbers, passport or driver’s license copies, verification selfies, and IBANs. Alongside this, data breaches struck Trezor, Pocket Bitcoin, Bits of Gold, and Safepal. Swiss Bitcoin Pay said that user funds were “safe” and that “any amounts owed to users will be fully returned.” The team added that they did not know when they would reopen again, but were working on it.
Customers and users of any of these companies that have suffered data breaches should assume that their personal information, emails, phone numbers, and home addresses are likely known. Going forward, the best thing affected customers can do is watch and stay alert for phishing attempts, fake support, phony letters, and unidentified callers.







