---
schema: 1
kind: incident
title: "Publica, the Confederation's pension fund: malware at its administration-software supplier PK Softech and a data outflow the Confederation reports, with the Federal Prosecutor's Office investigating"
headline: "Publica's software supplier was breached; the Confederation reports a data outflow, scope and actor not public"
summary: >
  The Confederation, in a release headlined "data outflow confirmed", said on 2026-10-08 that a software supplier of Publica
  detected a cyberattack at the end of September, and the supplier PK Softech AG (Reinach BL) says unknown attackers used malware to reach part of its IT infrastructure and that
  it must be assumed data left its systems; the Federal Prosecutor's Office is investigating. Publica insures, among others, staff of the federal administration and the ETH domain, about
  70,000 active members and 41,600 pensioners at the end of 2025, and says name, date of birth, AHV number, address, contact details, salary and
  pension data and partner details could have been taken; which data left, how the attackers got in and
  who they are is not public.
discovered_at: "2026-10-09T03:41:00Z"
updated_at: null
event_date: "2026-10-08"
run_id: 2026-10-09T0255Z-intel
priority: routine
immediate_action: null
tags: [data-breach, supply-chain]
regions: [switzerland]
sectors: [public-sector]
entities: ["incident:pk-softech-publica-cyberattack-2026-09"]
techniques: [T1199]
affected_products: []
cves: []
sources:
  - url: "https://www.admin.ch/de/newnsb/FjG4XOIms04s"
    publisher: "Swiss Federal Administration (admin.ch)"
    date: "2026-10-08"
    role: primary
  - url: "https://pksoftech.ch/de/newsreader/Cyberangriff-auf-die-PKSoftechAG"
    publisher: "PK Softech AG"
    date: "2026-10-08"
    role: primary
  - url: "https://www.watson.ch/schweiz/digital/228405160-pensionskasse-des-bundes-cyberangriff-auf-publica-softwarefirma"
    publisher: "watson.ch"
    date: "2026-10-08"
    role: corroborating
  - url: "https://www.netzwoche.ch/news/2026-10-08/bundespensionskasse-publica-meldet-datenabfluss"
    publisher: "Netzwoche"
    date: "2026-10-08"
    role: corroborating
closed_sources: []
evidence:
  - quote: "At the end of September an external software supplier of the federal pension fund Publica detected a cyberattack. (translated from German)"
    original: "Ein externer Softwarelieferant der Pensionskasse des Bundes Publica stellte Ende September einen Cyberangriff fest."
    publisher: "Swiss Federal Administration (admin.ch)"
    source_url: "https://www.admin.ch/de/newnsb/FjG4XOIms04s"
  - quote: "According to current knowledge it must be assumed that data left our systems. (translated from German)"
    original: "Nach heutigem Kenntnisstand muss davon ausgegangen werden, dass Daten aus unseren Systemen abgeflossen sind."
    publisher: "PK Softech AG"
    source_url: "https://pksoftech.ch/de/newsreader/Cyberangriff-auf-die-PKSoftechAG"
  - quote: "Whether and which data actually left in the incident is, however, still unclear. (translated from German)"
    original: "Ob und welche Daten bei dem Vorfall tatsächlich abgeflossen sind, ist allerdings noch unklar."
    publisher: "watson.ch"
    source_url: "https://www.watson.ch/schweiz/digital/228405160-pensionskasse-des-bundes-cyberangriff-auf-publica-softwarefirma"
verification: multi-source
sourcing_note: >
  The Confederation's release, headlined data outflow confirmed, and the supplier's own notice agree on the intrusion; the supplier
  says it must be assumed that data left, while Publica's spokesperson says it is still unclear which data is affected, and the
  data classes come from Publica's member letter as watson reports it. No source names an access vector, an actor or a ransom demand, and watson's reading that
  the facts point to a ransomware group is its own and unconfirmed.
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Tell the helpdesk, HR and payroll teams of every body whose staff are insured with Publica (including the federal administration and the ETH domain) that AHV number, date of birth, address and salary may now be known to criminals and must not count as proof of identity, and route requests that quote them to a call-back on a known number."
  - "If your organisation's pension administration, HR or payroll runs on PK Softech software, ask the supplier in writing whether your data was in the affected environment and what it holds."
updates: []
migrated_from: null
---

The Confederation, in a release headlined "data outflow confirmed" (translated from German), says an external software supplier of the federal pension fund Publica detected a cyberattack at the end of September, informed its other customers, whom the sources do not name, and that the Federal Prosecutor's Office has opened an investigation; no other federal office has a business relationship with the supplier ([Swiss Federal Administration, 2026-10-08](https://www.admin.ch/de/newnsb/FjG4XOIms04s)); the supplier, PK Softech AG of Reinach (BL), says unknown persons used malware to reach part of its IT infrastructure and that it must be assumed data left its systems, with type and scope still under investigation ([PK Softech, 2026-10-08](https://pksoftech.ch/de/newsreader/Cyberangriff-auf-die-PKSoftechAG)). Publica insures, among others, staff of the federal administration and the ETH domain, about 70,000 active members and 41,600 pensioners at the end of 2025, and its member letter lists name, date of birth, AHV number, address, contact details, salary and pension data and partner details as data that could have been stolen ([watson.ch, 2026-10-08](https://www.watson.ch/schweiz/digital/228405160-pensionskasse-des-bundes-cyberangriff-auf-publica-softwarefirma)). Netzwoche reports it is still unclear whether data of the pension fund actually left ([Netzwoche, 2026-10-08](https://www.netzwoche.ch/news/2026-10-08/bundespensionskasse-publica-meldet-datenabfluss)); no access vector or actor is public, and Publica declined to say whether a ransom was demanded ([watson.ch, 2026-10-08](https://www.watson.ch/schweiz/digital/228405160-pensionskasse-des-bundes-cyberangriff-auf-publica-softwarefirma)); the supplier is a software supplier of a federal institution, and Publica data may be affected ([Swiss Federal Administration, 2026-10-08](https://www.admin.ch/de/newnsb/FjG4XOIms04s)).

**Detection:** Publica warns that misuse of the data cannot be ruled out and asks members to watch for unusual e-mails, calls or messages ([watson.ch, 2026-10-08](https://www.watson.ch/schweiz/digital/228405160-pensionskasse-des-bundes-cyberangriff-auf-publica-softwarefirma)), so the telemetry to watch is mail-gateway logs and the helpdesk, HR and payroll call and ticket records of affected bodies for contact that cites an AHV number, a salary or a partner's details.

**Defender takeaway:** until Publica reports the scope, AHV number, date of birth, address and salary should not serve as proof of identity, and a request that quotes them deserves a call-back through a known number; an organisation that runs PK Softech software should ask the supplier in writing whether its data was in the environment.
