Names, AVS numbers and salaries: here is the data stolen from Publica

Institutional headquarters in Switzerland related to the Publica pension fund

Late September: attack on Publica’s software provider Names, AVS numbers and salaries among the data at risk Publica has 66’000 active insured persons and 40’000

Context

TL;DR

  • Late September: attack on Publica's software provider
  • Names, AHV numbers and salaries among the data at risk
  • Publica has 66’000 active insured persons and 40’000 pension recipients
  • Pension funds were not affected

Key facts

  • Institution → Publica, the Swiss Confederation's pension fund
  • Provider → PK Softech AG
  • Timing → late September
  • Potentially affected → approximately 66’000 active insured persons and 40’000 pension beneficiaries
  • Investigation → Office of the Attorney General of Switzerland
  • Funds → not affected and safe, according to Publica

At the end of September, a cyberattack hit an external software provider of Publica, the Swiss Confederation's pension fund. The incident caused a data breach and, according to current findings, may have involved particularly sensitive personal information.

The case became public on Thursday, after Publica sent a notice to the insured. The document, seen by SRF, indicates that personal data were probably stolen. Beatrice Rychen, spokesperson for the pension institution, described what happened in stark terms: «For us, this is the worst thing that could have happened».

The information that may have been obtained includes first and last names, dates of birth, AHV numbers, addresses, private and business telephone numbers, as well as personal and business email addresses. The list also includes pension data, such as salary and pension assets, marital status and information relating to a spouse or partner.

The route via the external provider

It is not yet clear whether the leak concerns all approximately 66’000 active insured persons and 40’000 pension beneficiaries, or only some of them. Publica does clarify, however, that the pension funds were not affected and are safe.

The cybercriminals did not attack the Swiss Confederation's pension fund directly. The target was PK Softech AG, the external company that develops applications for pension funds. Through this provider, the perpetrators are believed to have gained access to Publica's data.

The Office of the Attorney General of Switzerland is investigating the case. In the meantime, specialists are analyzing the stolen information. It is not known whether the attack also involved data from other pension institutions. For anyone checking their own situation, the AHV number entry is therefore one of the categories to distinguish from investments and funds, which Publica says were not affected. The guide on previdenza AVS may help with navigating pension terminology.

Operational details

Two distinct risks for insured persons

The matter has two distinct dimensions. The first concerns the possible theft of personal data; the second concerns pension funds. Publica says the funds are safe, while warning of a risk to individuals linked to the misuse of the information.

The theft of a name, address, AHV number, salary or pension assets could, according to the institution, be used in an attempt to assume other people's identities or to gain an advantage. The risk mentioned does not, however, mean that unlawful use of the data has already been established. Specialists are still analyzing how much was stolen.

Table 1: Scenario
ScenarioWhat the source indicatesPractical interpretation
Only some of the insured persons are involvedThe scope has not been clarifiedNot everyone affected would necessarily be exposed
All insured persons and beneficiaries are involvedThe possibility has not been ruled outThe scope would be broader, but this has not been confirmed
Pension fundsPublica says they are safeThe news concerns data, not a declared loss of funds

The reference to salary also makes it important to interpret correctly any salary information that may be contained in the stolen data. For this reason, it may be useful to consult busta paga svizzera, without confusing a category of personal data with a movement in the pension account.

The attack bears similarities to the one that involved Xplain in 2023: in that case, cybercriminals had gained access to information from federal offices through an external software company, resulting in the theft of approximately 1,3 million sensitive files. Two years ago, at the end of an administrative investigation, the Federal Council had adopted measures to prevent further thefts at IT providers. Since then, cooperation with external companies has also been subject to additional security requirements.

The precedent does not automatically make it possible to determine the scope of the Publica case. It does, however, show why the software provider, although not the Confederation's pension fund, is the central focus of the investigation.

Useful planning tools

To estimate your pension strategy, use the pension planner and the pillar 3 simulator.

Useful planning tools

To estimate your pension strategy, use the pension planner and the pillar 3 simulator.

Key points

What to do based on the available information

1. Read the communication. Publica sent insured persons a communication about a data breach. It is the reference point for checking the categories indicated and distinguishing personal information from pension assets.

2. Recognize the most sensitive data. The possible theft also concerns the AHV number, salary data, pension assets, address and contact details. This does not mean that every category was stolen for every person: Publica has not yet clarified whether all insured persons and beneficiaries or only some of them are involved.

3. Exercise caution with unusual contacts. The institution urges insured persons to be vigilant in the event of unusual phone calls or messages. This caution is linked to the risk that the stolen information could be misused to assume a person’s identity or obtain an advantage.

4. Separate data and funds. The communication describes a possible information breach, but Publica states that the pension funds were not affected and are safe. This distinction prevents the news from being interpreted as confirmation of losses to pension assets.

The situation remains under review. Specialists are analyzing the stolen data, and the Office of the Attorney General of Switzerland is investigating the incident. It is also not known whether the attack obtained information from other pension institutions: any updates will therefore have to clarify both the extent of the breach and the categories actually involved.

To better understand the salary items mentioned in the communication, you can use calcolatore stipendio.

Source: rsi.ch

Frequently Asked Questions
What personal data might have been stolen in the attack on Publica?
The information that may have been acquired includes first and last name, date of birth, AVS number, address, private and business telephone numbers, as well as personal and business email addresses. The list also includes pension-related data such as salary and pension assets, marital status, and information relating to a spouse or partner.
Are the insured persons' pension funds at risk?
No, Publica specified that the pension funds were not affected and are safe. The matter concerns exclusively the possible theft of personal data and the sensitive information of insured persons, while the investments and funds of the Confederation's pension fund have not suffered any reported losses.
Who was directly affected by the cyberattack?
The attack did not directly target the Confederation’s Publica pension fund, but rather PK Softech AG, the external company that develops applications for pension funds. Through this external provider, the cybercriminals may have gained access to the data, potentially affecting approximately 66.000 active insured persons and 40.000 pension beneficiaries.

Related articles