Publica, the pension fund that provides pensions for staff of the Swiss federal government, has confirmed today that a data leak occurred as a result of a cyberattack on one of its external software suppliers.
The Swiss government stated that the supplier discovered the attack at the end of September and then filed a criminal complaint while informing the federal authorities, Publica, and its other customers.
Consequently, the Office of the Attorney General has launched an investigation.
Until now, it has not yet been made clear what data was taken, but the supplier is currently working with several federal authorities to determine how much Publica data was affected.
The statement they gave provided no information on how many members might be affected or when the investigation would be completed.
Publica has not identified the supplier or specified the type of data that was leaked, but it has informed its members of the breach, its possible implications for them, and the measures taken in response.
As the statement makes clear, no other federal agencies carry on any business with the supplier.
Publica is one of the largest pension funds in Switzerland and provides pension coverage for individuals who work for the federal government and for those in the ETH Domain, which consists of a number of federal universities and research organisations.
Swissinfo stated that by the end of 2025, the fund had around 70,000 active members and 41,600 pensioners, with assets just under 45 billion Swiss francs.
Swiss federal data has already been made public via a supplier. In 2023, the Play ransomware group released files which it had stolen from Xplain, an IT company that provided services to several federal agencies, including the army and the customs service. The group published approximately 907GB of data.
The same year, the software company Concevis was also the victim of a ransomware attack. It had among its customers the Federal Statistical Office and the Federal Tax Administration, and once again older federal data was stolen, SRF reported.
External companies were also the means by which recent breaches occurred at the FBI and Denmark’s CPR register.
Get the TNW newsletter
Get the most important tech news in your inbox each week.