An external software supplier to two Bern pension funds has been hit by a cyberattack. According to a Keystone-SDA report published by SWI swissinfo.ch on 9 October 2026, the incident affects the Bern Pension Fund and the Bern Teachers’ Insurance Fund (the names used for them in the English version of the report). The canton of Bern says it has no indication that any data was stolen.
What happened
The attack took place in late September. It was announced on Friday in a joint statement from the cantonal departments of finance and of education and culture. It was not the pension funds themselves that were targeted, but a company that supplies them with software. That company has not been named.
According to the report, the affected company immediately filed a criminal complaint and the Public Prosecutor’s Office is investigating. The two pension funds are in contact with the departments concerned.
Policyholders’ data: what is known and what remains open
The official message comes in two parts. On the one hand, the canton has no evidence pointing to data theft. On the other, it is not possible to rule out completely that data was stolen. Should this “contrary to expectations” prove to be the case, the pension funds will provide further information, the statement quoted by swissinfo.ch says.
Several points are not specified in the source: the name of the provider, the type of software it supplies, the nature of the attack, the categories of data this supplier had access to, and whether other clients of the company are affected.
Who is insured with these two funds
The two institutions insure, among others, cantonal staff, staff of the cantonal universities and teaching staff in the canton of Bern. According to their own figures, at the end of December last year they had more than 63,000 insured persons in total, plus more than 28,000 pension recipients.
Not an isolated case this week
The swissinfo.ch page also links to an article published on 8 October 2026: the federal pension fund Publica is investigating a cyberattack targeting a supplier and a data leak affecting insured persons. The source does not say whether it is the same provider or whether the two incidents are linked.
Analysis: security also depends on suppliers
What follows is analysis rather than reported fact. A pension fund manages information about its policyholders and pensioners, but part of its IT may rely on external companies. The Bern case illustrates this mechanism: the attack did not target the funds directly, and it was the company that was attacked that filed the complaint. For pension institutions, the security of their data therefore also depends on the protections put in place by their suppliers. At this stage, nothing in the source suggests that Bern policyholders should expect concrete consequences; the funds have said they would provide information if data theft were to be established.
Sources
- SWI swissinfo.ch (Keystone-SDA), “Cyberattack on software supplier affects Bern pension funds”, 9 October 2026: https://www.swissinfo.ch/eng/various/cyberattack-on-software-supplier-affects-bern-pension-funds/92192331




