Skip to content

Swiss prosecutors investigate data leak at federal pension fund Publica

Swiss prosecutors have launched an investigation into a data leak at Publica, the federal pension fund, after a cyberattack on one of its external software suppliers. The breach was detected in late September, but details about the scope and impact remain unknown. Publica has notified its members, though the number of affected individuals is still unclear.

Editor, Lazyfounder

Published 4 min read
Swiss prosecutors investigate data leak at federal pension fund Publica
Image: Credit: asun Bughdaryan on Unsplash via source

30 SEC SUMMARY

  • Swiss prosecutors have opened an investigation into a data leak at Publica, the federal pension fund, following a cyberattack on an external software supplier.
  • The supplier detected the attack in late September and filed a criminal complaint, but the extent of the breach remains unclear.
  • Publica has informed its members about the incident, though the number of affected individuals and the type of data compromised are unknown.
  • This incident follows other high-profile ransomware attacks in Switzerland, including breaches at Xplain and Concevis in 2023.

KEY HIGHLIGHTS

  • Publica, Switzerland’s federal pension fund, experienced a data leak due to a cyberattack on one of its external software suppliers.
  • The supplier discovered the attack at the end of September and filed a criminal complaint with federal authorities.
  • The Office of the Attorney General of Switzerland has launched an investigation into the incident.
  • The scope of the data breach and the number of affected Publica members remain unclear.
  • Publica had approximately 70,000 active members and 41,600 pensioners at the end of 2025, with assets under 45 billion Swiss francs.

Cyberattack on supplier triggers data leak at Publica

According to The Next Web, Publica, the Swiss federal pension fund, experienced a data leak following a cyberattack on one of its external software suppliers. The supplier discovered the attack at the end of September and subsequently filed a criminal complaint with federal authorities.

Publica has informed its members about the breach and its potential implications, though it has not disclosed the identity of the supplier or the type of data compromised. The fund serves around 70,000 active members and 41,600 pensioners, managing assets just under 45 billion Swiss francs as of the end of 2025.

Prosecutors launch investigation as details remain unclear

The Office of the Attorney General of Switzerland has opened an investigation into the data leak, according to reports. However, key details about the incident remain unknown, including the extent of the breach, the specific data accessed, and the number of affected members.

Publica has stated that no other federal agencies are known to work with the same supplier, limiting the potential fallout beyond its own members.

Switzerland’s history of supplier-linked cyber incidents

The Publica breach follows other high-profile cyberattacks in Switzerland involving third-party suppliers. In 2023, the Play ransomware group leaked approximately 907GB of data stolen from Xplain, an IT company serving multiple federal agencies.

That same year, Concevis, a supplier for the Federal Statistical Office and the Federal Tax Administration, was also hit by a ransomware attack, resulting in the theft of older federal data.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

This incident underscores the growing risk of cyberattacks targeting third-party suppliers—a weak link that can expose even well-protected institutions like pension funds. For founders and operators, it highlights the need for rigorous vendor security assessments, contractual safeguards, and incident response plans that account for third-party breaches. The prolonged uncertainty surrounding the investigation also illustrates the reputational and operational challenges organizations face when critical details remain undisclosed. For public institutions, this case reinforces the importance of proactive communication with stakeholders, even in the absence of full clarity, to maintain trust and manage expectations.

Key takeaways

  • Third-party suppliers are a critical vulnerability for sensitive institutions like pension funds, amplifying risks even when direct security measures are robust.
  • Transparency with stakeholders is essential, but communicating uncertainty—such as undisclosed breach details—can undermine trust and complicate mitigation efforts.
  • Regulatory investigations into cyber incidents can be prolonged, leaving organizations and affected individuals in limbo over the long-term implications.
  • Pension funds and government-linked entities are increasingly targeted, reflecting their high-value data and potential for cascading impacts on public trust.

FAQ

What is Publica?

Publica is the Swiss federal pension fund, providing pension coverage for employees of the Swiss federal government and the ETH Domain. It is one of the largest pension funds in Switzerland, with around 70,000 active members and 41,600 pensioners as of the end of 2025.

How did the data leak at Publica happen?

The data leak occurred due to a cyberattack on one of Publica’s external software suppliers. The supplier detected the attack at the end of September and filed a criminal complaint.

What information is known about the data breach?

Little is currently known about the breach. It is unclear what data was accessed, how many Publica members are affected, or when the investigation will conclude. Publica has not disclosed the identity of the supplier or the type of data compromised.

Has Publica notified its members about the breach?

Yes, Publica has informed its members about the breach and its potential implications, though details about the scope and impact remain limited.

Are other federal agencies affected by this breach?

According to Publica, no other federal agencies are known to work with the same supplier involved in the breach.

Sources

  1. The Next Web · 2026-10-08
    Swiss prosecutors investigate data leak at federal pension fund Publica

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us