Data belonging to Publica, the Swiss federal government's pension fund, has been leaked following a cyberattack on one of its external software suppliers. Publica announced this on Thursday, 8 October 2026, according to the Keystone-SDA news agency, as reported by SWI swissinfo.ch. At this stage, it is not known exactly which data is affected. The Office of the Attorney General of Switzerland has opened an investigation.
What we know
The sequence of events as communicated is as follows. The software supplier detected the attack at the end of September. It then filed a criminal complaint and informed the relevant federal authorities, Publica and its other clients. The attack therefore did not directly target the pension fund's systems, but those of a service provider that processed data on its behalf.
The extent to which Publica's data has been compromised is currently being analysed together with several federal authorities. The fund says it has informed its insured members of the leak, its possible consequences and the measures taken.
Publica also states that no other federal office has a business relationship with the supplier in question. This is a statement by the institution, which the published information does not allow to be verified independently.
What remains unknown
Several questions remain open. Publica has not named the affected supplier or specified the nature of the leaked data. It is therefore unclear whether it involves contact details, salary data, information on pension benefits or other categories. Nor is it known how many people are affected, who carried out the attack or how they went about it.
The time between the detection of the attack, at the end of September, and the public announcement, on 8 October, is known in broad terms. However, the date on which Publica itself was alerted by its supplier has not been disclosed.
Who Publica is
Publica is one of the largest pension funds in Switzerland. Among others, it insures the staff of the federal administration and of the ETH Domain (the Swiss Federal Institutes of Technology). At the end of 2025, it had around 70,000 active insured members and 41,600 pension recipients, with total assets of just under 45 billion francs.
These figures give an idea of the size of the group of people potentially affected, but do not say how many of them are actually affected by the leak: that will depend on the results of the ongoing analysis.
Analysis: the subcontractor link
The case illustrates a well-known mechanism in IT security: an organisation can protect its own systems and still see its data exposed through a service provider. As soon as a supplier hosts, processes or receives data on behalf of an institution, the security of that data also depends on the supplier's own protective measures.
For public institutions and pension funds, which often rely on specialised software supplied by third parties, this kind of dependency is hard to avoid. What is at stake then comes down to concrete questions: which data is actually transmitted to the service provider, how it is protected, and how quickly the institution is alerted in the event of an incident. In Publica's case, the information available does not yet make it possible to say how these points were handled.
One element does emerge from the announcement, however: the supplier itself alerted its clients and the authorities, and criminal proceedings are under way. The rest of the investigation and the expected details on the nature of the data will show whether the incident calls for broader adjustments in how the Swiss Confederation manages its IT subcontractors.



