CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

PK Softech cyberattack and Publica data outflow (September 2026)

incident · incident:pk-softech-publica-cyberattack-2026-09

Malware-enabled intrusion at PK Softech AG (Reinach BL), supplier of the pension-administration application of the Swiss Federal Pension Fund Publica, detected at the end of September 2026; PK Softech says it must be assumed that data left its systems, the Confederation says Publica informed its insured persons about the data outflow, the scope of Publica data is still being established and the Federal Prosecutor's Office is investigating (Swiss Federal Administration and PK Softech, 2026-10-08).

Aliases: Publica supplier cyberattack

Coverage
1
first 2026-10-09 → last 2026-10-09
Latest activity
2026-10-09
Publica's software supplier was breached; the Confederation reports a data outflow, scope and actor not public
Peak priority
routine
1 routine
Targets
public-sector
sectors: public-sector · regions: switzerland
Sources cited
4
4 hosts

Action items (2)

Do-now tasks recorded on the entries about PK Softech cyberattack and Publica data outflow (September 2026), newest first. Check the date before acting on an older one.

  • Tell the helpdesk, HR and payroll teams of every body whose staff are insured with Publica (including the federal administration and the ETH domain) that AHV number, date of birth, address and salary may now be known to criminals and must not count as proof of identity, and route requests that quote them to a call-back on a known number.
    2026-10-09Publica's software supplier was breached; the…
  • If your organisation's pension administration, HR or payroll runs on PK Softech software, ask the supplier in writing whether your data was in the affected environment and what it holds.
    2026-10-09Publica's software supplier was breached; the…

Defender insights

What each entry about PK Softech cyberattack and Publica data outflow (September 2026) tells a defender to do, newest first.

2026-10-09ROUTINEPublica's software supplier was breached; the Confederation reports a data outflow, scope and actor not public

Detection

Story timeline

  1. 2026-10-09Publica, the Confederation's pension fund: malware at its administration-software supplier PK Softech and a data outflow the Confederation reports, with the Federal Prosecutor's Office investigating
    active-threatsPublica's software supplier was breached; the Confederation reports a data outflow, scope and actor not public

Hunting pivots

ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessTrusted Relationship

Initial Access TA0001

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-10-09/publica-pk-softech-supplier-malware-intrusion-data-outflow · ATT&CK page ↗

Entries about PK Softech cyberattack and Publica data outflow (September 2026) (1)

2026-10-09 · view entry permalink →

ROUTINENATOA2

Publica, the Confederation's pension fund: malware at its administration-software supplier PK Softech and a data outflow the Confederation reports, with the Federal Prosecutor's Office investigating

The Confederation, in a release headlined "data outflow confirmed" (translated from German), says an external software supplier of the federal pension fund Publica detected a cyberattack at the end of September, informed its other customers, whom the sources do not name, and that the Federal Prosecutor's Office has opened an investigation; no other federal office has a business relationship with the supplier (Swiss Federal Administration, 2026-10-08); the supplier, PK Softech AG of Reinach (BL), says unknown persons used malware to reach part of its IT infrastructure and that it must be assumed data left its systems, with type and scope still under investigation (PK Softech, 2026-10-08). Publica insures, among others, staff of the federal administration and the ETH domain, about 70,000 active members and 41,600 pensioners at the end of 2025, and its member letter lists name, date of birth, AHV number, address, contact details, salary and pension data and partner details as data that could have been stolen (watson.ch, 2026-10-08). Netzwoche reports it is still unclear whether data of the pension fund actually left (Netzwoche, 2026-10-08); no access vector or actor is public, and Publica declined to say whether a ransom was demanded (watson.ch, 2026-10-08); the supplier is a software supplier of a federal institution, and Publica data may be affected (Swiss Federal Administration, 2026-10-08).

At the end of September an external software supplier of the federal pension fund Publica detected a cyberattack. (translated from German)

Swiss Federal Administration (admin.ch) 2026-10-08

According to current knowledge it must be assumed that data left our systems. (translated from German)

PK Softech AG 2026-10-08

Whether and which data actually left in the incident is, however, still unclear. (translated from German)

watson.ch 2026-10-08
incident09 Oct 03:41Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • admin.ch1 (25%)
  • netzwoche.ch1 (25%)
  • pksoftech.ch1 (25%)
  • watson.ch1 (25%)