Publica data breach: attack and federal investigation

Attack at the end of September against an external supplier of Publica Data leak and immediate criminal complaint Investigation by the Office of the Attorney General of Switzerland
Context
TL;DR
- Attack in late September against an external supplier to Publica
- Data breach and immediate criminal complaint
- Investigation by the Office of the Attorney General of Switzerland
- Publica: 70'000 active insured persons and 41'600 pension recipients
Key facts
- What → cyberattack on an external software provider for Publica
- When → late September; radio report of October 8, 2026
- Consequence → data leak
- Criminal proceedings → immediate criminal complaint and investigation by the Office of the Attorney General of Switzerland
- Scale → approximately 70'000 active insured persons, 41'600 pension beneficiaries and a balance sheet just under 45 billion francs
On October 8, 2026, the 12.30 radio news broadcast reported on the cyberattack involving Publica, in a report by Anna Valenti. At the end of September, an external software provider for the Confederation's pension fund was hit by a cyberattack that resulted in a data leak.
In the statement released on Thursday, the company reports that it immediately filed a criminal complaint. The Office of the Attorney General of Switzerland has launched an investigation. Together with the various federal services, the provider is now assessing the extent to which Publica's data were affected.
In the meantime, the pension fund informed insured persons about the data leak, its effects and the measures taken. The statement thus places the incident on two levels: the criminal action already initiated and the technical assessment of the extent of the leak. The latter is not presented as completed.
Publica's scope
These figures describe the size of the institution involved, while the extent of any impact on the data remains tied to the provider's assessment together with the federal services. The statement also specifies that the company hit by hackers has no business relations with any other federal service. The assessment therefore concerns Publica's data in its relationship with that provider, while the criminal investigation is proceeding at the Office of the Attorney General of Switzerland.
For those monitoring their own position in previdenza e nelle rendite, the concrete reference remains the communication received from Publica, which provides information about the data leak, its consequences and the measures taken.
Operational details
For those who live or work in Switzerland, the Publica case should be read by distinguishing between the affected supplier, the potentially affected data, and the consequences communicated to the insured. The source identifies an external software company as the target of the attack and links the extent to which the fund's data are affected to the review with the Confederation's services. This distinction avoids automatically attributing elements from other incidents to Publica.
Comparison with recent incidents
| Case | Reported elements |
|---|---|
| CHUV | At the beginning of September, a personal-data breach involving eleven patients after a cyberattack against an external laboratory specializing in cancer diagnosis. |
| UFIT | In August, an attack against SharePoint servers, a file-sharing platform; approximately 200 accounts compromised, with no indications of a data breach at that time. |
| RUAG | The US subsidiary was hacked in October 2025 and data were stolen; last June, RUAG acknowledged paying a ransom. |
| Stadler Rail | In July, technical data were stolen from a supplier; a demand for 10 million francs was rejected and Stadler systems were not affected. |
The incidents have different scopes: patients and laboratory in the CHUV case, accounts and sharing platform for UFIT, a US subsidiary for RUAG, and a supplier for Stadler Rail. In the Publica case, by contrast, the report brings together an external supplier, a federal pension fund, and a review of the Confederation's data.
The responses are not comparable either. For RUAG, in August, the Federal Department of Defence concluded that the ransom payment did not constitute a violation of the law, while criticizing shortcomings in incident management. Stadler Rail had refused the requested payment and its systems had not been affected. For Publica, the statement reports a criminal complaint, an investigation and information provided to the insured, without linking the case to any of the remedies described for the other companies.
The size of the fund, with active insured persons and pension recipients, explains the national interest in the case; it does not, however, allow figures or consequences from the other incidents to be attributed to Publica. To keep the data-breach issue separate from pension management, the tools at previdenza e rendite can be consulted.
Useful tools to protect your net income
To reduce FX leakage, compare CHF-EUR exchange options and banks for cross-border workers.
Useful planning tools
To estimate your pension strategy, use the pension planner and the pillar 3 simulator.
Key points
For an insured person, handling the matter involves Publica's communication and the announced investigations. The procedure can be organized into a few steps, without attributing to the case measures that the source does not mention.
Operational steps
1. Recognize the relationship with Publica. The communication concerns insured persons; within the fund, the text distinguishes between active insured persons and pension beneficiaries. This distinction serves to correctly interpret the information received. 2. Read the section dedicated to the data breach. Publica informed insured persons about this event, its consequences and the measures taken. Therefore, start with the fund's communication, not the details of other attacks. 3. Separate consequences and measures. These are two distinct elements of Publica's information. The consequence describes what results from the breach; the measure indicates the action taken by the fund, according to the communication received. 4. Follow the measures communicated by Publica. The text does not apply to this case the procedures relating to CHUV, UFIT, RUAG or Stadler Rail: the incidents remain separate and have different scopes. 5. Follow the verification that is still ongoing. The provider is working with the various services of the Confederation to determine the extent to which Publica's data are affected. Any update on the scope of the incident depends on this investigation.
What to monitor next
For those working in the Federal Administration or in the federal institutes of technology sector, Publica identifies the insurance relationship as the reference. The statement also specifies that the company targeted by the hackers has no business relationships with any other federal service. If the professional relationship is with another service, the source alone does not authorize extending any possible involvement of the data to that service.
The available timeline places the attack in late September and the radio report on October 8, 2026. The operational step indicated by the source remains reading Publica's communication and the measures taken, together with the results of the technical verification.
To learn more about pension matters related to the fund, consult sezione previdenza e rendite.
Compare LAMal health insurance premiums: up to CHF 200 monthly difference between providers for the same canton and deductible.
Source: rsi.ch
Plan your cross-border pension: calculate AVS, second pillar and INPS coordination to avoid retirement surprises.
Frequently Asked Questions
- What happened to the Publica pension fund?
- At the end of September, an external software provider of Publica, the Swiss Confederation's pension fund, suffered a cyberattack in which a data breach occurred. The company immediately filed a criminal complaint, and the Office of the Attorney General of the Swiss Confederation launched an investigation to establish the facts and determine to what extent Publica's data were affected.
- What are the size and scope of Publica?
- Publica is one of Switzerland's largest pension funds and insures employees of the Federal Administration and the sector of the federal institutes of technology. At the end of 2025, it had approximately 70'000 active insured persons and 41'600 pension recipients, with total assets amounting to just under 45 billion francs.
- What should the insured persons involved do?
- The insured persons have received a communication from the pension fund informing them about the data breach, its consequences, and the measures taken. Practical handling for the insured person is carried out through this specific communication and the technical investigations still underway between the provider and the Confederation’s services.
Related articles
- All articles: Safety and crime
- Attacco informatico al fornitore software di Publica
- Nomi, numeri AVS e stipendi: ecco i dati rubati a Publica
- Indagine reddito di cittadinanza e capitali in Svizzera
- Svizzeri in fuga all'estero: l'impatto del costo della casa
- Attacco informatico IWB Basilea: 40'000 clienti coinvolti