What is confirmed
On October 8, Swiss federal authorities announced that an external software supplier to pension fund Publica had detected a cyberattack in late September.
The supplier filed a criminal complaint and notified authorities, Publica and other clients. The Office of the Attorney General opened an investigation.
Publica informed members about the data leak. The precise categories and volume of affected data were still being assessed at the time of the release.
What it means
Pension funds rely on third-party software and services, underlining the need for access controls and resilient backups across the supply chain.
Pension or family contact details, if exposed, can support targeted fraud attempts.
How the incident unfolded
On October 8, Swiss federal authorities announced that an external software supplier to pension fund Publica had detected a cyberattack in late September.
The supplier filed a criminal complaint and notified authorities, Publica and other clients. The Office of the Attorney General opened an investigation.
What it means for affected people
Pension funds rely on third-party software and services, underlining the need for access controls and resilient backups across the supply chain.
Pension or family contact details, if exposed, can support targeted fraud attempts.
Practical safeguards
Check official Publica notices and be cautious of callers asking to confirm pension information.
Never disclose passwords or one-time login codes after a breach alert.
What to do
Check official Publica notices and be cautious of callers asking to confirm pension information.
Never disclose passwords or one-time login codes after a breach alert.
Organisations should audit permissions and data flows with suppliers.
Use the related SecurCheck tool, then confirm important decisions with an official source.