The Swiss Federal Pension Fund Publica confirmed on October 8, 2026 that a cyberattack on an external software supplier — identified in Swiss press as PK Softech AG — led to a data leak involving Publica information. The supplier detected the attack at the end of September 2026, filed a criminal complaint, and informed federal authorities, Publica, and its other customers. Switzerland’s Office of the Attorney General has opened an investigation. Publica’s own notice is short and careful; Swiss broadcasters that reviewed member communications filled in the data-type picture members are actually reading in their inboxes.
This is a verified Publica data breach under the fund’s public confirmation — not a leak-site rumor. Scope is still being measured with federal authorities. Publica has on the order of 66,000–70,000 active insured members and roughly 40,000–41,600 pensioners, depending on the year-end snapshot cited; Swiss media stress that it is not confirmed whether all of them are in the leaked set. Pension fund assets and benefit payments are described as secure and continuing. Canonical BreachHistory record: https://breachhistory.com/publica/publica-pk-softech2026 (/publica/publica-pk-softech2026).
What this is not: a confirmed theft of the CHF tens of billions under management, a shutdown of pension payments, or proof that every federal office that ever touched Swiss IT was hit. Publica’s English notice states that no other federal entities have a business relationship with the compromised supplier. The parallel Swiss readers will hear is the 2023 Xplain vendor breach — another path into sensitive public-sector data through a software contractor — not a direct assault on Bern’s core networks.
Who Publica is — and why AHV-linked pension data matters
Publica is one of Switzerland’s largest pension funds. It insures employees of the Federal Administration and institutions in the ETH Domain, among others. At year-end 2025, SWI swissinfo reported about 70,000 active members, 41,600 pensioners, and just under CHF 45 billion in assets. RSI’s Italian-language reporting uses the slightly lower round numbers of about 66,000 active insured and 40,000 pensioners when discussing possible exposure — treat those as the same population ballpark, not competing censuses of confirmed victims.
Swiss occupational pensions sit on top of the first-pillar AHV/AVS social-security number. When a pension administrator’s personal data leaks, the dangerous combination is not a drained investment account — Publica says the funds are safe — but a durable identity package: legal name, date of birth, AHV/AVS number, address, salary, pension balance, marital status, and partner data. That package is enough for convincing impersonation against banks, insurers, tax offices, and other pension funds for years.
Publica spokesperson Beatrice Rychen, quoted in RSI’s coverage adapted from SRF, called the situation “the worst thing that could happen” for the institution after the case became public on Thursday, October 8. That is the tone of a pension fund that knows its members’ trust is the product.
What happened in the Publica breach 2026
According to Publica’s English news release and corroborating Swiss press:
- An external software supplier used by Publica identified a cyberattack at the end of September 2026.
- Swiss media name the supplier as PK Softech AG, a company that develops applications for pension funds.
- The supplier filed a criminal complaint and informed relevant federal authorities, Publica, and other customers.
- A data leak involving Publica data is confirmed.
- The Office of the Attorney General launched an investigation.
- Publica is working with federal authorities to determine the scope of affected data.
- Publica has informed its members about the leak, implications, and actions taken (newsletter plus letters to pensioners, per Swiss reporting).
- No other federal entities have a business relationship with this supplier, per Publica.
Attackers did not need to crack Publica’s own perimeter if PK Softech held production or near-production member data for software support. RSI notes specialists are analyzing what was taken and that it is not yet known whether other pension funds that also use PK Softech lost data in the same incident. That open question matters for the Swiss second-pillar industry beyond Publica alone.
Timeline
- Late September 2026 — PK Softech AG (external software supplier) detects a cyberattack; criminal complaint filed; Publica and authorities informed.
- Late September – early October 2026 — Joint work with federal authorities to map which Publica datasets were affected; forensic analysis of stolen data underway.
- October 8, 2026 — Publica publishes confirmation of the data leak; SWI, RSI/SRF, and other Swiss outlets report; Office of the Attorney General investigation already active.
- Ongoing — Scope determination; member support and caution guidance; criminal investigation by federal prosecutors.
What remains unknown publicly
- Exact headcount of affected individuals — not confirmed as the full active + pensioner population.
- Technical intrusion details — ransomware vs. silent exfiltration, initial access path, and whether backups or test environments were involved are not in Publica’s short English notice.
- Whether other PK Softech customers lost data in the same attack.
- Whether stolen data has appeared on criminal forums or been used in confirmed fraud against named members.
- Full remediation timeline for the supplier and for Publica’s contractual controls.
What data may have been exposed
Publica’s English homepage notice does not list field-by-field inventory. Swiss public broadcasters that reviewed the communication sent to insured persons do. Per RSI (citing Publica’s member communication as reviewed via SRF), the following may have been among data taken:
- First and last name
- Date of birth
- AHV/AVS number (Swiss social security number)
- Address
- Telephone numbers (private and professional)
- Email addresses (private and professional)
- Pension-related data such as salary and pension balance / retirement assets (avere previdenziale)
- Marital status
- Spouse or partner data
Present these as possible categories from Publica’s member-facing description as reported by Swiss press — not as a finalized forensic exhibit for every member. Until Publica or prosecutors publish a definitive inventory, assume the worst fields in that list if you are an active insured person or pensioner who received the notice, and adjust only when your personal letter narrows the set.
SWI’s English piece, published the same day, correctly notes that Publica did not detail the supplier identity or leaked data types in the short public statement SWI summarized — the richer field list comes from the member communications Swiss outlets obtained. Both layers are useful: the English notice for official confirmation and investigation posture; RSI/SRF for what members were actually told about personal data.
What was not exposed — or remains secure
Publica’s messaging, as relayed by RSI, draws a bright line around money:
- Pension funds / invested assets are secure
- Benefits continue — payments are not described as interrupted
- The incident is framed as a personal-data leak via a supplier, not as thieves moving Publica’s CHF 45 billion
That distinction is critical for members who hear “pension fund hacked” and assume their retirement capital vanished. Occupational pension assets are segregated and custody-controlled; a software vendor breach that copies membership files is still a serious privacy and fraud event, but it is a different failure mode from a compromised payment instruction system that redirects pensions.
Also not claimed in indexed sources: exposure of every federal ministry’s systems, compromise of the AHV central register itself, or a confirmed dark-web sale listing of the full Publica corpus. Stay inside what Publica and Swiss prosecutors have actually said.
How the attack worked — what is known vs. inferred
What is attested: criminals hit the external software supplier, and Publica data was among what leaked. RSI’s framing is blunt — attackers did not strike Publica directly; they went through PK Softech and thereby apparently reached Publica data.
What is not attested in the English notice: VPN credentials, a zero-day in a pension-admin product, insider access, or ransomware encryption of PK Softech. Do not invent a kill chain. For defenders at other Swiss pension funds, the actionable inference is simpler: if a vendor hosts or processes AHV numbers, salaries, and partner data for your members, that vendor is part of your attack surface even when your own SOC never sees the alert.
PK Softech’s customer base beyond Publica is the next question Swiss administrators will ask quietly. Publica says other federal entities do not use this supplier; private and cantonal pension funds are a separate question RSI already flagged as unknown.
Who is at risk
Active insured members
Federal employees and ETH Domain staff currently contributing to Publica should assume their identity and compensation package may be in criminal hands until scope is narrowed. Salary plus AHV number plus employer context is a gift for spear-phishing that pretends to be HR, a tax authority, or a “pension portal security reset.”
Pensioners
Retirees receiving Publica benefits are in the population Publica is writing to by letter. Older victims are disproportionately targeted with phone fraud. A caller who already knows your pension balance, partner’s name, and AHV number will sound more legitimate than a generic “your package is held” scam.
Spouses and partners
If partner data was among the fields, people who never worked for the Confederation can still be exposed because they appear on a member’s file. They should get the same caution briefing even if they never logged into a Publica portal.
Other PK Softech customers
Until the supplier and prosecutors clarify, other pension funds using the same software should verify whether their tenants or databases were touched. Silence is not a clearance.
Industry and campaign context — the Xplain echo
Swiss reporting immediately compared the Publica supplier breach to the 2023 Xplain case, in which attackers reached sensitive federal-related information through an external Swiss software firm, with reporting at the time describing on the order of 1.3 million sensitive files. An administrative investigation later led the Federal Council to tighten security requirements for collaboration with external IT providers.
That history is why this story lands with political weight in Bern, not only with cybersecurity blogs. Switzerland spent two years telling itself that vendor assurance for public-sector data had improved. A late-September 2026 hit on another software supplier that holds federal pension data tests whether those measures worked in practice for second-pillar systems.
Internationally, the pattern matches a broader 2020s theme: pension administrators, payroll processors, and benefits platforms are concentrated targets because they combine immutable national ID numbers with income and family structure. U.S. readers comparing this to MOVEit-era pension vendor waves should note the difference in confirmation style — Publica’s notice is a clean government-adjacent disclosure with a prosecutor already on the case — while recognizing the same supply-chain lesson.
What Publica, the supplier, and regulators said
Publica’s October 8 English statement is deliberately spare: supplier cyberattack, criminal complaint, authorities informed, Attorney General investigation, scope work ongoing, members informed, no other federal customers of this supplier. That is the official minimum.
Member communications, as summarized by RSI/SRF, go further on risk language. Publica speaks of a “certain risk” to individuals and says misuse of personal data for advantage cannot be excluded. Members are told to be cautious with unusual phone calls or messages — the correct operational advice when AHV numbers and contact details may be in the wild.
The Office of the Attorney General’s involvement signals a federal criminal track, not only a civil privacy complaint. Expect more detail to emerge on timelines, attribution, and possibly other victims if the investigation expands beyond Publica’s dataset.
SWI notes Publica is among Switzerland’s largest pension funds and repeats the membership and asset figures that frame national significance. RSI quotes the institutional shock without claiming that every one of the ~100,000+ people in the active-plus-pensioner population is confirmed affected — an important journalistic hedge BreachHistory keeps.
What you should do
If you are a Publica active member or pensioner — especially if you received the newsletter or letter — take the following steps. Swiss processes differ from U.S. credit freezes; prioritize AHV-aware fraud paths and out-of-band verification.
- Read Publica’s member notice carefully and keep it. Note which data categories your letter or newsletter lists for you.
- Treat unexpected contact as hostile. Anyone calling about “Publica security,” “AHV verification,” or “pension unlock” who asks you to read back your AHV number, IBAN, or codes from an SMS is running a classic follow-on scam. Hang up. Use contact channels published on publica.ch or the phone number in your paper letter.
- Watch bank and tax touchpoints. Enable alerts on new payees and large transfers. Be suspicious of emails that cite your exact salary band or pension balance — details criminals may now know.
- Protect partners and family. Brief spouses or partners whose data may appear on your file so they are not blindsided by a convincing bilingual phishing call.
- Do not reuse Publica-related passwords on other sites; rotate any password you ever used on pension or HR portals if it was shared across accounts.
- Document suspicious contacts — date, number, what was asked — and report clear fraud attempts to police and to Publica through official channels.
- Ignore “compensation signup” pages that appear within hours of Swiss headlines unless they are clearly operated by a lawyer you retained; rush claim sites often phishing-harvest AHV numbers.
- Follow Publica updates for scope clarifications. If the fund later says only a subset of members are affected, that narrows monitoring effort; until then, act as if you are in scope if you received notice.
Phishing examples tied to this incident
- German-, French-, or Italian-language emails claiming “Confirm your Publica data after the PK Softech attack” with a credential-harvest link
- WhatsApp messages pretending to be a federal IT helpdesk that already knows your AHV number and asks for a “verification code”
- Calls offering to “freeze your pension account” that then request IBAN changes
- Fake Attorney General “victim portal” pages asking you to upload an ID card “for the investigation”
Publica and Swiss prosecutors will not ask you to paste your AHV number into a random form because you saw a news headline.
Was I affected?
You should assume elevated risk if you are an active Publica insured person or a Publica pensioner and you received the fund’s October 2026 member communication about the supplier cyberattack. Publica has informed members as a population; that is not the same as publishing a list of confirmed exposed AHV numbers.
It is not confirmed that all ~66,000–70,000 active members and ~40,000–41,600 pensioners had data in the leaked set. If you never received any Publica communication and have no Publica relationship, this incident is not about you — though other PK Softech customers could still issue their own notices later.
Federal employees who changed employers or retired should check whether they still appear in Publica’s records as deferred or pensioner statuses; old affiliations still create exposure if the vendor retained historical extracts.
Canonical record and sources
BreachHistory indexes this as a verified October 2026 incident based on Publica’s public confirmation and contemporaneous Swiss press.
- Publica — Cyber attack on Publica software supplier: data leak confirmed
- SWI swissinfo — Swiss federal pension fund faces data breach after cyberattack (Oct 8, 2026)
- RSI — Names, AVS numbers and salaries: the data stolen from Publica (member-communication field list; PK Softech naming; Xplain parallel)
- Canonical catalog entry: https://breachhistory.com/publica/publica-pk-softech2026
If Publica or the Office of the Attorney General later publish a definitive victim count, a technical post-mortem, or confirmation about other PK Softech customers, update the catalog from those primary statements. As of October 8, 2026, the verified core is enough for members to act on: a late-September supplier cyberattack leaked Publica personal data, prosecutors are investigating, pension money is said to be safe, benefits continue, and anyone with an AHV number in that ecosystem should treat unexpected “Publica” contact as a fraud attempt until proven otherwise through official channels.