HomeNewsBreachesAbout
Account
bitbox-2025

Bitbox Breach

Jul 26, 2025

20,849 rows

Added on Aug 10, 2025

Search the Leak

Email

What happened in the Bitbox Breach?

DataBreach.com Team · August 9th 2025, 8:00 pm EDT

Understanding the BitBox Breach 

1. What is BitBox, and what happened in recent news? 

BitBox - also known as Bitbox.swiss - is a Swiss-based provider of cryptocurrency hardware wallets (e.g., BitBox02, BitBox02 Nova) and BitBoxApp software, developed by Shift Crypto AG.  
In late July 2025, the company was targeted in a ransomware-style breach by the group Everest, which claimed to have stolen internal documents and customer order information, according to public disclosures

2. When did the breach occur and when was it discovered? 

The intrusion reportedly happened around July 26, 2025, but it was first publicly discovered and disclosed on July 30, 2025, as noted in security bulletins.  
Some reporting even gives the exact timestamp of 14:47:48 UTC on the day of discovery, based on incident tracking logs

3. Who is behind the breach? 

The attack has been linked to the Everest ransomware group, a known Russian-affiliated criminal outfit. This group is notorious for naming victims publicly and releasing partial data to apply pressure during ransom negotiations, as documented in threat intelligence reports.  
Since 2023, Everest has been connected to over 240 victims, with nearly 90 attacks in the past year, including high-profile incidents in the Middle East. 

4. What kind of data was compromised? 

Leaked samples appear to include recent hardware wallet orders containing identifiable purchaser information, according to cybersecurity researchers.  
Analysts noted that these records seem to come from “recently fulfilled orders,” raising privacy concerns for affected customers. 

5. What risks does this breach pose? 

  • Risk to customer privacy, since order details could contain names or contact information. 
  • Potential for linking hardware wallets to specific individuals, which could raise physical or targeted security threats. 
  • Damage to the brand reputation of BitBox, a company whose appeal relies heavily on trust and security. 

6. What can affected users or stakeholders do? 

  • Stay vigilant against phishing and impersonation attempts, as breaches of personal data often trigger such activity. 
  • Maintain wallet security: BitBox hardware wallets are built with strong safeguards, and no compromise of private keys has been reported (full security overview here).  
  • Watch for official updates from Shift Crypto regarding any further impacted data or mitigation steps. The company has published details on past security incidents, which may indicate how they will handle this one. 
For media inquiries, contact us at contact@databreach.com