CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
ROUTINENATOA2incident

Publica, the Confederation's pension fund: malware at its administration-software supplier PK Softech and a data outflow the Confederation reports, with the Federal Prosecutor's Office investigating

Publica's software supplier was breached; the Confederation reports a data outflow, scope and actor not public

Defender actions

  • Tell the helpdesk, HR and payroll teams of every body whose staff are insured with Publica (including the federal administration and the ETH domain) that AHV number, date of birth, address and salary may now be known to criminals and must not count as proof of identity, and route requests that quote them to a call-back on a known number.
  • If your organisation's pension administration, HR or payroll runs on PK Softech software, ask the supplier in writing whether your data was in the affected environment and what it holds.

Analysis

The Confederation, in a release headlined "data outflow confirmed" (translated from German), says an external software supplier of the federal pension fund Publica detected a cyberattack at the end of September, informed its other customers, whom the sources do not name, and that the Federal Prosecutor's Office has opened an investigation; no other federal office has a business relationship with the supplier (Swiss Federal Administration, 2026-10-08); the supplier, PK Softech AG of Reinach (BL), says unknown persons used malware to reach part of its IT infrastructure and that it must be assumed data left its systems, with type and scope still under investigation (PK Softech, 2026-10-08). Publica insures, among others, staff of the federal administration and the ETH domain, about 70,000 active members and 41,600 pensioners at the end of 2025, and its member letter lists name, date of birth, AHV number, address, contact details, salary and pension data and partner details as data that could have been stolen (watson.ch, 2026-10-08). Netzwoche reports it is still unclear whether data of the pension fund actually left (Netzwoche, 2026-10-08); no access vector or actor is public, and Publica declined to say whether a ransom was demanded (watson.ch, 2026-10-08); the supplier is a software supplier of a federal institution, and Publica data may be affected (Swiss Federal Administration, 2026-10-08).

Cited evidence

At the end of September an external software supplier of the federal pension fund Publica detected a cyberattack. (translated from German)

Swiss Federal Administration (admin.ch) 2026-10-08

According to current knowledge it must be assumed that data left our systems. (translated from German)

PK Softech AG 2026-10-08

Whether and which data actually left in the incident is, however, still unclear. (translated from German)

watson.ch 2026-10-08

Sources4

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.