
Swiss federal pension fund Publica confirms data leak after software supplier cyberattack
Publica, the pension fund for Swiss federal staff, says personal data may have leaked after attackers hit an external software supplier at the end of September. The Office of the Attorney General has opened an investigation.
What Publica confirmed
Publica, the pension fund for Swiss federal employees and staff of the ETH Domain, confirmed on Thursday that a data leak occurred after a cyberattack on one of its external software suppliers. The supplier detected the attack at the end of September, filed a criminal complaint and informed the relevant federal authorities, Publica and its other customers, while the Office of the Attorney General opened an investigation. Publica has informed its insured members about the breach, its possible consequences and the measures it has taken. How much of Publica's data was affected is still being determined together with federal authorities, and the statement gave no date for when that work will be finished. Publica is one of the largest pension funds in Switzerland, with around 70,000 active members and 41,600 pensioners at the end of 2025 and assets just under CHF45 billion, according to swissinfo.
Speaking to SRF, communications head Beatrice Rychen described the attack in stark terms.
For us, it is the worst that can happen.
Which data may be affected
SRF, citing Publica's information to insured members, reports that the leaked data may include names, first names, dates of birth, AHV numbers, addresses, business and private phone numbers and email addresses, salary, insured earnings and pension savings, marital status, and details of spouses or partners. Publica describes these items as possibly affected based on current knowledge, and the list could change as the analysis continues. According to SRF, it is still open whether all of the roughly 66,000 active insured persons and all of the roughly 40,000 pension recipients are affected, or only some of them. Publica says the pension assets themselves are not affected and are secure.
Publica warned that individuals face a certain risk and urged them to stay alert.
It cannot be ruled out that the personal data will be misused to gain an advantage.
The supplier and the attackers
SRF identifies the affected supplier as PK Softech AG, while Publica's statements did not name it. According to SRF, the attack was not aimed directly at Publica, and the attackers apparently reached Publica data through the software company. Publica says federal experts are analysing the leaked data together with the software firm, and that this work is being carried out under high pressure. According to the statement, no other federal agency has business relations with the supplier.
Fraud warning
The Geneva cantonal police warn that fraud attempts are increasing after the data leak. Blick reports that personalised attempts by email, SMS or phone could rise again. Criminals could use leaked details such as names, addresses and sometimes the link between a person and the affected organisation to gain access to bank data. The police warn that the risk persists for a long time, because stolen data stays in circulation long after an incident. Publica also urges caution with unusual calls or messages.
Earlier breaches in Switzerland
The Next Web recalls that in 2023 the Play ransomware group published about 907GB of files it had stolen from Xplain, an IT company serving several federal agencies, including the army and the customs service. The same year, ransomware hit the software company Concevis, whose customers included the Federal Statistical Office and the Federal Tax Administration. RTS reports that in early September the CHUV flagged a data leak affecting 11 patients after an attack on an external cancer diagnostics laboratory. In August, the Federal Office of Information Technology and Telecommunication (OFIT) reported an attack on its SharePoint servers that compromised about 200 accounts, though no data leak had been found at that stage. RTS also notes that RUAG admitted in June that it had paid a ransom to cybercriminals.

