Hackers steal data from the federal pension fund. The attack came through a software supplier
Salaries, AHV numbers and pension amounts of federal employees may be affected. How many insured members are hit, Publica does not yet know. The Office of the Attorney General is investigating.
Publica, the federal pension fund, confirmed a data leak on Thursday. The target was not the fund itself but its software supplier, PK Softech AG, which develops applications for pension funds; Publica confirmed the name to the news agency AWP. According to Publica, the attack took place at the end of September. Through the supplier, the attackers apparently gained access to data held by the fund. Details on salaries, pension assets and pension amounts, as well as contact details, may be affected. SRF also reports names, AHV numbers and details on life partners; RSI reports similarly. The Tages-Anzeiger writes that the salaries of thousands of federal employees could become public. The software company says it detected the attack itself and filed a criminal complaint. The Office of the Attorney General has opened proceedings. According to Publica, it is unclear how many insured members and pensioners are affected. At the end of 2025 the fund had about 70,000 active insured members and 41,600 pensioners; that is the total membership, not the number of people affected. Publica is one of the largest pension funds in Switzerland. It insures not only employees of the federal administration but also staff of organizations close to the federal government. The circle of people who wondered on Thursday whether their data is among those affected is correspondingly wide. The fund could not yet give them an answer. It announced that it will inform those affected once the analysis is complete.
Publica has informed its insured members. Pension assets are safe, it said, and pensions will be paid out as usual. The fund advises caution with unusual e-mails, calls and messages, because leaked personal data could be misused for fraud. It is open whether data from other pension funds that work with the same supplier is also affected. Several outlets recall the Xplain case: in 2023, hackers stole data from the Bern software firm that also concerned federal offices, and later published it on the dark web. At the time it became clear how vulnerable the federal government is through its suppliers. The Publica case raises the same question: how closely does an authority check what its suppliers do with its data, and how much real personal data sits with firms that develop and test software? For those affected, the danger is concrete. Anyone who knows a person’s name, AHV number and salary can launch convincing fraud attempts, such as fake calls in the name of the fund or the bank. The NZZ describes a cyberattack on the software supplier, not on Publica itself. What exactly was leaked is for the investigation to show; until then the details remain provisional. Politically, the case is likely to raise questions, for instance whether the lessons of Xplain were also applied at an independent federal institution such as Publica. There were no answers to that on Thursday.