Publica, the federal pension fund, confirmed a data leak on October 8 following a cyberattack at the end of September on its software supplier, PK Softech AG. Salaries, pension assets, pension amounts and contact details may be affected; according to SRF, also names, AHV numbers and details on life partners. The Office of the Attorney General is investigating, and the company filed a criminal complaint. How many insured members are affected is unclear. At the end of 2025 Publica had about 70,000 active insured members and 41,600 pensioners. Assets and pensions are safe, it said.
After Xplain in 2023, it is the second major case in which federal data leaks through a supplier. Salary data and AHV numbers are valuable to fraudsters.
If you are insured with Publica or draw a pension from it, be especially careful with calls, e-mails and text messages that refer to salary or pension, and when in doubt check directly with Publica.
Publica informed people quickly and brought in the authorities; the assets are not at risk.
After Xplain, the federal government should have monitored its suppliers more strictly. That real personal data sits with a software house is the actual problem.
The decisive figure is still missing: how many records. In the coming days, ask not only about the scale but also about why a software supplier had access to real data at all. Publica and the federal government have to answer that.
Tages-Anzeiger · NZZ · SRF · RSI · cash (AWP) · 20 Minuten · it-markt (all Oct. 8) · Publica (statement, cited) · number of people affected open
Hackers steal data from the federal pension fund. The attack came through a software supplier
Salaries, AHV numbers and pension amounts of federal employees may be affected. How many insured members are hit, Publica does not yet know. The Office of the Attorney General is investigating.
Publica, the federal pension fund, confirmed a data leak on Thursday. The target was not the fund itself but its software supplier, PK Softech AG, which develops applications for pension funds; Publica confirmed the name to the news agency AWP. According to Publica, the attack took place at the end of September. Through the supplier, the attackers apparently gained access to data held by the fund. Details on salaries, pension assets and pension amounts, as well as contact details, may be affected. SRF also reports names, AHV numbers and details on life partners; RSI reports similarly. The Tages-Anzeiger writes that the salaries of thousands of federal employees could become public. The software company says it detected the attack itself and filed a criminal complaint. The Office of the Attorney General has opened proceedings. According to Publica, it is unclear how many insured members and pensioners are affected. At the end of 2025 the fund had about 70,000 active insured members and 41,600 pensioners; that is the total membership, not the number of people affected. Publica is one of the largest pension funds in Switzerland. It insures not only employees of the federal administration but also staff of organizations close to the federal government. The circle of people who wondered on Thursday whether their data is among those affected is correspondingly wide. The fund could not yet give them an answer. It announced that it will inform those affected once the analysis is complete.
Publica has informed its insured members. Pension assets are safe, it said, and pensions will be paid out as usual. The fund advises caution with unusual e-mails, calls and messages, because leaked personal data could be misused for fraud. It is open whether data from other pension funds that work with the same supplier is also affected. Several outlets recall the Xplain case: in 2023, hackers stole data from the Bern software firm that also concerned federal offices, and later published it on the dark web. At the time it became clear how vulnerable the federal government is through its suppliers. The Publica case raises the same question: how closely does an authority check what its suppliers do with its data, and how much real personal data sits with firms that develop and test software? For those affected, the danger is concrete. Anyone who knows a person’s name, AHV number and salary can launch convincing fraud attempts, such as fake calls in the name of the fund or the bank. The NZZ describes a cyberattack on the software supplier, not on Publica itself. What exactly was leaked is for the investigation to show; until then the details remain provisional. Politically, the case is likely to raise questions, for instance whether the lessons of Xplain were also applied at an independent federal institution such as Publica. There were no answers to that on Thursday.