Hacker attack on SRF: data stolen from about 340 employees

SSR reports an attack on SRF: contact and organizational data of approximately 340 employees were stolen. Passwords and banking details do not appear to be involved.
Context
In brief
- A cyberattack hit SRF.
- Data belonging to about 340 staff members was stolen.
- The information dates back to 2020.
- Passwords and bank details do not appear to be involved.
Key facts
- Who → SRF, German-speaking Swiss public broadcaster of SSR
- People involved → about 340 former and current staff members
- Data → contact and organizational information dating back to 2020
- Scope → primarily SRF's Information division
- Excluded → personal passwords, financial and banking data
- Measures → people notified, access disabled and security strengthened
- Status → internal and external investigation into the cause
- Publication → no evidence that data was published or misused
About 340 former and current SRF staff members are involved in the data theft following a cyberattack. SSR announced this on Monday, specifying that it had filed a complaint. The number concerns people who work or have worked for the German-speaking Swiss public broadcaster; the source does not extend the figure to the organization as a whole.
The intrusion and countermeasures
After discovering the intrusion, the broadcasting company immediately initiated the countermeasures indicated in a statement. The people involved were notified, access was disabled and additional security measures were adopted. The communication does not indicate a deadline for these activities or provide a date for the attack.
According to SSR, the hackers did not gain access to personal passwords, financial or banking data. The same assurance applies to journalistic sources, research data and communications content. The stolen material would instead consist of contact and organizational data of about 340 former and current staff members.
The information dates back to 2020. It includes names and roles, as well as work contact details and, in some cases, private contact details. The breach mainly concerns SRF's Information division. Other corporate and regional units were spared, according to the statement.
SSR is trying to determine the cause of the attack with internal and external experts. At present, there is no evidence that the stolen data were published or used improperly. The statement therefore distinguishes what was stolen from the categories that, according to the information provided, do not appear to have been compromised.
The information provided is limited to these elements. SSR reports the scope of the data, the measures taken and the status of the checks, but adds no details about the cause of the intrusion. For now, the only reported outcome is the absence of evidence of the publication or misuse of the data. No further information is reported on how access was gained. The statement is limited to the categories listed and the measures already taken.
Operational details
The practical understanding of the incident hinges on distinguishing between types of data. A name, a role or contact detail belongs to the contact and organizational information referred to by SSR. According to the same communication, they are not equivalent to a personal password or financial or banking data. This distinction is the most concrete point for those who were informed: the report describes a limited theft, not the compromise of all company information.
A scope not to broaden
| Area | Source indication |
|---|---|
| Data period | 2020 |
| People | former and current collaborators |
| Most affected division | Information |
| Other units | corporate and regional units spared |
| Data status | no evidence of publication or misuse |
The reference to 2020 calls for caution when interpreting the contact details: the source places them in that year, but does not say whether they are still current. Likewise, the fact that the attack mainly concerns the Information division does not justify automatically extending it to every SSR unit. The note mentions other corporate and regional units as having been spared.
For a former collaborator, the communication matters just as much as it does for a current collaborator, because the scope includes both categories. SSR states that the people involved were notified; no different procedure is described for those who no longer work at the company. No deadlines, document requests or additional individual instructions beyond the measures already communicated are indicated either.
The practical consequence is to limit conclusions to what is known. There is nothing in the source to suggest that passwords were stolen, banking data exposed or journalistic content published. The investigation with internal and external experts serves to determine the cause; the reported status remains that of the filed report and the absence of evidence of publication or misuse. calcolatore stipendio, on the other hand, concerns a separate service and cannot verify this incident.
Useful tools to protect your net income
To reduce FX leakage, compare CHF-EUR exchange options and banks for cross-border workers.
Key points
Based on the available data, the individual procedure remains limited to what SSR has communicated.
What to check
1. Identify the notice received from SSR, if you are among the current or former collaborators involved. 2. Compare the categories indicated: names, functions, work contact details and, in some cases, private contact details. 3. Keep contact and organizational data separate from the categories that SSR says were not compromised. 4. Bear in mind that access has already been disabled as a communicated company measure. 5. Follow only the updates concerning the investigation and any possible publication of the data.
For current and former collaborators, the first point of reference remains the communication received, because SSR states that it notified the people involved. The source does not indicate a portal, form or office to which documents should be sent; therefore, an unannounced individual procedure cannot be added.
Access management is also described as a measure already taken by the company. SSR assures that the hackers did not gain access to personal passwords, financial or banking data, journalistic sources, research data or communication content. The text does not indicate a deadline for any further requirements.
The only development indicated is the investigation conducted with internal and external experts to determine the cause. There is no confirmation that the data has been published or misused. Readers can therefore distinguish between stolen data, company measures already adopted and checks still in progress, without extending the scope beyond what was communicated.
If you are looking for a separate salary calculation, calcolatore stipendio is the site’s tool. To explore this topic further, use calcolatore stipendio.
Source: rsi.ch
Frequently Asked Questions
- How many people are involved in the attack on SRF?
- The source refers to data concerning approximately 340 former and current SRF employees. The group mainly concerns the Information division; other corporate and regional units were spared. The information dates back to 2020 and includes names, roles, and work contact details and, in some cases, private contact details.
- What data was stolen?
- According to SSR, these are contact and organizational data. They include names and roles, as well as work and, in some cases, private contact details. The communication specifies that the information dates back to 2020. Personal passwords, financial or bank data, journalistic sources, research data, and communication content, on the other hand, were not affected.
- Have personal passwords been compromised?
- SSR assures that the hackers did not gain access to personal passwords. The same assurance applies to financial and bank data, as well as journalistic sources, research data, and communication content. The source instead reports the theft of contact and organizational data relating to approximately 340 former and current employees.
- What did the SSR do after the attack?
- After discovering the intrusion, SSR initiated countermeasures, notified the people involved, deactivated access, and adopted additional security measures. It also filed a complaint. The attack is being examined by internal and external experts to determine its cause. For now, there is no evidence that the data have been published or misused.