It's good to know that Swiss Bitcoin Pay discovered this breach on time and took necessary precautions. Another good piece of news is that people's funds are safe. However, these criminals now have access to some important personal information. Users' identities have been exposed and could be sold on the dark web market. Those who use the services of this non-custodial payment processor and gateway company would have to be ready for all forms of phishing messages.
Phishing messages are not that big of an issue in my opinion, but there is one more thing that the users need to be worried about, it is the attackers cross-checking the hashed passwords and emails they have stolen at every possible platform and service in the hope that they might find a match and get access to user accounts where they can possibly do some stealing. For example, if a merchant who was using Swiss Bitcoin Pay also has a Binance account with the same email address, and it is a fact that a lot of people usually use the same password for most of the accounts they hold so that they don't forget the password easily, which means that if they try, they might be able to log in.
I used Binance only as an example, and I know that Binance has good security because they ask for 2FA, and they also sometimes asks for facial verification when a new device tries to log into an account, which is a great thing, but I'm just generally talking about possibilities. So I think that every single user should immediately change the passwords of any other platform and service they use where they are using the same email addresses which they have used for Swiss Bitcoin Pay accounts so that the attackers or malicious users don't get to have any possibility of stealing any of their funds.