Cyberattack on Publica’s software provider

Server rack in a Swiss technical room symbolising the cyberattack on a Publica software provider

## TL;DR - Cyberattack at the end of September - An external Publica provider was affected - The Public Prosecutor's Office has launched an investigation - Publica has

Context

TL;DR

  • Cyberattack in late September
  • An external provider of Publica was affected
  • The Office of the Attorney General of the Swiss Confederation launched an investigation
  • Publica informed the insured persons

Key facts

  • Event → cyberattack at the end of September
  • Affected party → external software provider of Publica
  • Investigation → Office of the Attorney General of Switzerland
  • Data affected → verification ongoing
  • Information → persons insured with Publica

The facts and sequence

In Bern, on October 8, 2026, a press release announced that, at the end of September, an external company providing software to Publica, the Swiss Confederation's pension fund, had been hit by a cyberattack. The text places the incident at the pension fund's external provider.

The company immediately filed a criminal complaint. It also informed the relevant Confederation services, Publica and other customers. The communication therefore places the incident at an external provider that has dealings with multiple customers; the press release specifies, however, that no other federal service has a business relationship with that same company.

The Office of the Attorney General of Switzerland launched an investigation. At the same time, the company and the various Confederation services are checking which data are affected and to what extent Publica's data are involved. The review was still ongoing at the time of publication.

The source also reports that Publica informed the persons insured with it of the data leak, its consequences and the measures taken. These are the elements indicated by the source for those insured with the pension fund.

The press release thus presents two parallel activities. On the one hand, the Office of the Attorney General of Switzerland is pursuing the investigation. On the other, the provider and the various Confederation services are working to establish which data are affected and to what extent Publica's data are affected. The review is not described as concluded.

For the persons insured, the information already communicated by Publica concerns the data leak, the consequences and the measures taken. The text is dated Bern and published on October 8, 2026: the available reporting ends with this state of the findings.

Operational details

What it means today for insured persons

The scope of the news

For people who live or work in Switzerland, the practical point is to distinguish the attack that has already been confirmed from its scope, which is still under review. The statement establishes that the victim is an external provider of Publica, the Swiss Confederation's pension fund, and that Publica's data are being examined together with the company and the relevant services. It does not, however, allow the attack to be automatically associated with every piece of Publica data, because it refers to investigations into which data are affected and to what extent.

The second practical element concerns the recipients of the information. The company informed Publica, the relevant Confederation services and other customers; Publica informed the insured persons. However, the source does not present a single overview for all customers. The reference to federal services is also limited: no other federal service has business dealings with the company. This sentence defines the federal business relationship indicated in the statement, not a broader group.

The central point, therefore, is not a figure but the sequence of the investigations. The criminal investigation was launched by the Office of the Attorney General of the Swiss Confederation, while the technical review must clarify which data are affected and the extent of the involvement. These are two distinct aspects, which the reader should not conflate.

Table 1: Practical question
Practical questionStatement's answer
What is certain?The attack on the external provider and the investigation by the Office of the Attorney General.
What is under review?The data affected and the extent of Publica's involvement.
What information has already been provided?Publica has informed the insured persons about the leak, consequences and measures.
What is the federal scope indicated?No other federal service has business dealings with the company.

Three interpretations to avoid

For someone insured with Publica, it is not correct to replace the information received with assumptions about the content of the data. For someone who works in another federal service, the source does not extend the incident to that service. For the provider's other customers, the text confirms that they have been informed, but does not describe each one's situation.

To get an overview of pensione, the guide on the website can be consulted separately. It does not replace Publica's information or alter the ongoing review.

Useful planning tools

To estimate your pension strategy, use the pension planner and the pillar 3 simulator.

Useful planning tools

To estimate your pension strategy, use the pension planner and the pillar 3 simulator.

Key points

How to use the information received

Sequence for insured persons

For insured persons, the operational procedure emerging from the press release starts with the information from Publica. The communication concerns three distinct elements: the data breach, the resulting consequences, and the measures taken. Separating these three aspects makes it possible to read the case without confusing what Publica has already communicated with the outcome of the investigations still under way.

1. Retrieve the information released by Publica. 2. Identify the section concerning the data breach. 3. Read the consequences indicated for insured persons. 4. Check which measures have been taken according to the communication. 5. Keep the content of the notice separate from the joint review of Publica's data.

The fifth step reflects the status of the matter: the company and the Confederation's services are checking which data are affected and to what extent. For this reason, Publica's communication is the concrete reference already provided by the source, while the investigation by the Office of the Attorney General of Switzerland concerns the criminal-law aspect.

What not to add to the case

The press release does not indicate forms, individual deadlines, technical channels or documents to be submitted. It is therefore not possible to construct an additional procedure without going beyond the available facts. At the institutional level, the source reports that the company has already filed a criminal complaint and that the Office of the Attorney General of Switzerland has opened an investigation.

The same criterion applies to the company's other clients. The text indicates that they have been informed, without describing any further individual situations. For separate further information, consult the guides on busta paga svizzera and pensions. To complete the review of your own financial situation, use calcolatore stipendio.

Source: admin.ch

Frequently Asked Questions
When did the attack on Publica's supplier occur?
The attack took place at the end of September, according to the statement published on October 8, 2026 and dated Bern. The identified victim is an external software provider of the Swiss Confederation's pension fund Publica. The company immediately filed a criminal complaint and informed the relevant services, Publica and other customers.
What are the relevant services verifying?
The company is investigating, together with the Confederation's services, which data are affected and to what extent Publica's data are involved. The investigation was still ongoing at the time the statement was published. Publica informed the insured persons about the data leak, its consequences and the measures taken.
Who is conducting the investigation into the cyberattack?
The Office of the Attorney General of Switzerland has launched an investigation. At the same time, the company and the relevant Confederation services are reviewing the data. The company has also filed a criminal complaint and informed Publica, the relevant services and other customers of the provider.

Related articles