2026 PUBLICA (Swiss Federal Pension Fund) — PK Softech supplier cyberattack; data leak confirmed
Data compromised
Per Publica/Swiss press: possible names, addresses, DOB, AHV/AVS numbers, salaries, pension balances/amounts, marital status, partner data, phones, emails. Scope (all vs subset of ~66–70k active + ~40–42k pensioners) not yet confirmed. Pension fund assets stated secure.
Technical writeup
Verified PUBLICA notice (Oct 8, 2026) — External software supplier PK Softech AG identified a cyberattack at the end of September 2026, filed a criminal complaint, and informed federal authorities, PUBLICA, and other customers. The Office of the Attorney General launched an investigation. PUBLICA confirmed a data leak affecting its data held by the supplier; scope still being determined with federal authorities. Swiss press citing PUBLICA lists possible fields including names, addresses, dates of birth, AHV numbers, salaries, pension balances, marital/partner data, and contact details. PUBLICA states pension funds/assets remain secure and benefits continue; members notified (newsletter to active insured; letters to pensioners). Nationwide person census unpublished — recordsAffected 0.
Root cause
Cyberattack on external software supplier PK Softech AG (detected late September 2026) with confirmed Publica data leak; Office of the Attorney General investigating
References
- https://www.publica.ch/en/about-us/news/cyber-attack-publica-software-supplier-data-leak-confirmed
- https://www.swissinfo.ch/eng/swiss-politics/data-breach-following-a-cyberattack-on-the-federal-pension-fund/92184193
- https://www.rsi.ch/info/svizzera/Nomi-numeri-AVS-e-stipendi-ecco-i-dati-rubati-a-Publica--4145954.html