2026-10-09ROUTINEPublica's software supplier was breached; the Confederation reports a data outflow, scope and actor not public
PK Softech cyberattack and Publica data outflow (September 2026)
incident · incident:pk-softech-publica-cyberattack-2026-09
Malware-enabled intrusion at PK Softech AG (Reinach BL), supplier of the pension-administration application of the Swiss Federal Pension Fund Publica, detected at the end of September 2026; PK Softech says it must be assumed that data left its systems, the Confederation says Publica informed its insured persons about the data outflow, the scope of Publica data is still being established and the Federal Prosecutor's Office is investigating (Swiss Federal Administration and PK Softech, 2026-10-08).
Aliases: Publica supplier cyberattack
Coverage
1
first 2026-10-09 → last 2026-10-09
Latest activity
2026-10-09
Publica's software supplier was breached; the Confederation reports a data outflow, scope and actor not public
Peak priority
routine
1 routine
Targets
public-sector
sectors: public-sector · regions: switzerland
Sources cited
4
4 hosts
Action items (2)
Do-now tasks recorded on the entries about PK Softech cyberattack and Publica data outflow (September 2026), newest first. Check the date before acting on an older one.
- Tell the helpdesk, HR and payroll teams of every body whose staff are insured with Publica (including the federal administration and the ETH domain) that AHV number, date of birth, address and salary may now be known to criminals and must not count as proof of identity, and route requests that quote them to a call-back on a known number.2026-10-09Publica's software supplier was breached; the…
- If your organisation's pension administration, HR or payroll runs on PK Softech software, ask the supplier in writing whether your data was in the affected environment and what it holds.2026-10-09Publica's software supplier was breached; the…
Defender insights
What each entry about PK Softech cyberattack and Publica data outflow (September 2026) tells a defender to do, newest first.
Detection
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessTrusted Relationship
Initial Access TA0001
T1199Trusted Relationship×1
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Evidence: 2026-10-09/publica-pk-softech-supplier-malware-intrusion-data-outflow · ATT&CK page ↗
Entries about PK Softech cyberattack and Publica data outflow (September 2026) (1)
Where this entity is cited
Source distribution
- admin.ch1 (25%)
- netzwoche.ch1 (25%)
- pksoftech.ch1 (25%)
- watson.ch1 (25%)
All cited sources (4)
- admin.chSwiss Federal Administration (admin.ch)https://www.admin.ch/de/newnsb/FjG4XOIms04s
- netzwoche.chNetzwochehttps://www.netzwoche.ch/news/2026-10-08/bundespensionskasse-publica-meldet-datenabfluss
- pksoftech.chPK Softech AGhttps://pksoftech.ch/de/newsreader/Cyberangriff-auf-die-PKSoftechAG
- watson.chwatson.chhttps://www.watson.ch/schweiz/digital/228405160-pensionskasse-des-bundes-cyberangriff-auf-publica-softwarefirma