Data breaches

Publica: data leak after cyberattack on Swiss pension software supplier

Swiss authorities confirm a late-September cyberattack at a Publica software provider and data leakage whose precise scope remains under investigation.

Conceptual illustration: Publica: data leak after cyberattack on Swiss pension software supplier
Conceptual illustration · SecurCheck

What is confirmed

On October 8, Swiss federal authorities announced that an external software supplier to pension fund Publica had detected a cyberattack in late September.

The supplier filed a criminal complaint and notified authorities, Publica and other clients. The Office of the Attorney General opened an investigation.

Publica informed members about the data leak. The precise categories and volume of affected data were still being assessed at the time of the release.

What it means

Pension funds rely on third-party software and services, underlining the need for access controls and resilient backups across the supply chain.

Pension or family contact details, if exposed, can support targeted fraud attempts.

How the incident unfolded

On October 8, Swiss federal authorities announced that an external software supplier to pension fund Publica had detected a cyberattack in late September.

The supplier filed a criminal complaint and notified authorities, Publica and other clients. The Office of the Attorney General opened an investigation.

What it means for affected people

Pension funds rely on third-party software and services, underlining the need for access controls and resilient backups across the supply chain.

Pension or family contact details, if exposed, can support targeted fraud attempts.

Practical safeguards

Check official Publica notices and be cautious of callers asking to confirm pension information.

Never disclose passwords or one-time login codes after a breach alert.

What to do

Check official Publica notices and be cautious of callers asking to confirm pension information.

Never disclose passwords or one-time login codes after a breach alert.

Organisations should audit permissions and data flows with suppliers.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Confédération suisse — 8 octobre 2026
  2. Confédération suisse — version EN