CTIPilot

Swiss Bitcoin Pay internal-systems breach (September 2026)

incident · incident:swiss-bitcoin-pay-internal-systems-breach-2026-09 single-source-victim

Neuchâtel-based non-custodial Bitcoin payment processor Swiss Bitcoin Pay disclosed on 2026-09-14 that a malicious user likely gained access to its internal systems, and that customer email addresses, Bitcoin wallet addresses, IBANs, transaction history and hashed passwords may have been accessed; customer funds were unaffected under the platform's non-custodial design (Swiss Bitcoin Pay's own statement, via Bitcoin Magazine and Bitcoin.com News, 2026-09-14).

Coverage timeline
1
first 2026-09-15 → last 2026-09-15
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-09-15/swiss-bitcoin-pay-neuchatel-internal-systems-breach · ATT&CK page ↗

Story timeline

  1. 2026-09-15Swiss Bitcoin Pay (Neuchâtel) shuts down its servers after a suspected intrusion, saying IBANs, wallet addresses and hashed passwords may have been accessed
    active-threatsA Swiss Bitcoin payment processor takes itself offline over a suspected breach, but says customer funds stay safe under its non-custodial design

Where this entity is cited

  • active-threats1

Source distribution

  • bitcoinmagazine.com1 (33%)
  • news.bitcoin.com1 (33%)
  • x.com1 (33%)

explore in graph

Entries about Swiss Bitcoin Pay internal-systems breach (September 2026) (1)

2026-09-15 · view entry permalink →

NOTABLENATOB2

Swiss Bitcoin Pay (Neuchâtel) shuts down its servers after a suspected intrusion, saying IBANs, wallet addresses and hashed passwords may have been accessed

Swiss Bitcoin Pay, a Neuchâtel-based non-custodial Bitcoin payment processor whose website claims more than 1,000 merchants across 21 countries (Bitcoin.com News, 2026-09-14), disclosed on its official account on 2026-09-14 that "a malicious user has likely gained access to Swiss Bitcoin Pay's internal systems" and that, "as a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure" (Swiss Bitcoin Pay, 2026-09-14). The company says "at this stage, we believe they may have accessed customer email addresses, Bitcoin addresses and IBANs, transaction history, and hashed passwords," adding that "it is not yet clear whether any other information was accessed" (Swiss Bitcoin Pay, 2026-09-14). No attacker has been named, no access vector or mechanism has been disclosed, and the company has not said when service will resume.

Customer funds themselves are unaffected: Swiss Bitcoin Pay's non-custodial model routes Bitcoin and Lightning Network payments directly to merchant wallets rather than holding them, so the company states "user funds are safe, and any amounts owed to users will be fully returned" (Swiss Bitcoin Pay, 2026-09-14). The exposure risk instead falls on affected customers: the combination of email addresses, IBANs, Bitcoin wallet addresses and transaction history is enough to support targeted phishing, SIM-swap attempts, and social-engineering against payment-recovery or account-verification pretexts, even though the hashed passwords and non-custodial design limit direct account or fund takeover.

A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems. As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure.

At this stage, we believe they may have accessed customer email addresses, Bitcoin addresses and IBANs, transaction history, and hashed passwords. It is not yet clear whether any other information was accessed.

User funds are safe, and any amounts owed to users will be fully returned.

Swiss Bitcoin Pay (victim's own statement) 2026-09-14
incident15 Sep 05:20Zsingle-source · victim disclosureOpen finding ↗