Swiss pension fund Publica confirms data leak after supplier cyberattack
Swiss prosecutors have opened an investigation after an attack detected in late September. The supplier remains unnamed, and the extent of Publica’s data exposure is still being assessed.
Publica, the Swiss federal pension fund, disclosed in Switzerland on 8 October that its data had leaked following a cyberattack on an external software supplier detected in late September. The fund serves federal employees and affiliated organisations, but authorities are still determining which records were affected and how extensive the exposure was.
The Swiss Office of the Attorney General has opened an investigation, according to the federal announcement and Reuters. The supplier has not been named. Neither the announcement nor the current reports establish how many people’s information was compromised, leaving the scale of the incident unresolved.
What Publica has confirmed about the supplier attack
The supplier discovered the attack at the end of September and immediately filed a criminal complaint, according to the announcement published by the Swiss Federal Department of Finance. It also notified the relevant federal authorities, Publica and other customers. The announcement gives no exact detection date.
The company and federal authorities are jointly examining the extent to which Publica’s data were affected. Publica said it had informed insured people about the leak, its consequences and measures taken. The public notice does not describe those measures or reproduce the individual notification sent to members.
The announcement also says no other federal entities maintain business relationships with the supplier. That statement concerns federal customers: it does not establish whether other, non-federal customers suffered data exposure. Although the company notified other customers, the notice does not identify them or describe any impact on their records.
Publica’s membership figures do not establish the breach count
Publica is one of Switzerland’s largest pension funds, according to SRF’s SDA-credited report. Its insured population includes employees of the federal administration and the ETH domain. At the end of 2025, it had approximately 70,000 active insured members and 41,600 pension recipients, SRF reported.
Those figures describe the fund’s membership, rather than a verified count of people affected by the leak. SRF also reported an end-2025 balance-sheet total of just under 45 billion Swiss francs. That financial figure describes Publica’s size; it is not a measure of money lost in this incident.
The current reports do not identify the categories of exposed data, the attacker or the method used. They also do not establish whether there has been financial loss, misuse of information or an interruption to pension payments. Those questions remain unanswered publicly; the lack of reported findings does not establish that no such effects occurred.
The separate Capita breach provides pension-provider context
A previous UK case shows how a service-provider breach can expose pension-related information. On 15 October 2025, the UK Information Commissioner’s Office announced combined fines of £14 million against Capita plc and Capita Pension Solutions Limited over a March 2023 cyberattack. This was a separate incident, with no established connection to Publica’s supplier.
The regulator said information belonging to 6.6 million people was stolen across pension records, employee records and customer information held for organisations Capita supported. That was not solely a count of pension members. Capita Pension Solutions processed information for more than 600 organisations providing pension schemes, of which 325 were affected.
The ICO found inadequate safeguards and incident response. Capita admitted liability and agreed to pay the £14 million penalty without appealing, the regulator said. Those findings concern Capita; they do not establish negligence, an identical attack mechanism or comparable damage in the Publica incident.
What the Publica investigation still needs to establish
The announced work now consists of the criminal investigation and the assessment of affected Publica data. The federal notice sets no deadline for findings or further disclosure. The central outstanding questions for members are what information was exposed and how many people were affected; neither has yet been answered in the public accounts.
Sources and context
- Swiss pension fund hit by data leak after cyber attack on software providerReuters via CNA
- Cyberangriff auf Softwarelieferant von Publica: Datenabfluss bestätigtSwiss Federal Department of Finance website / federal official announcement
- Cyberangriff – Bundespensionskasse Publica meldet abgeflossene DatenSRF, credited sda/mcep;hosb
- Capita fined £14m for data breach affecting over 6m peopleUK Information Commissioner’s Office
AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.
About NewsJaws Desk
AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.