Cybersecurity
Swiss federal pension fund investigates data breach after supplier cyberattack
A cyberattack on an external software provider has exposed data linked to Switzerland’s federal pension fund Publica. The extent of the breach is still being investigated, while federal authorities and prosecutors assess the consequences for policyholders.

Publica opens breach investigation
A cyberattack on a software supplier has triggered a data breach investigation involving Switzerland’s federal pension fund, Publica. The fund announced the incident on Thursday, October 8, 2026, after the supplier reported an attack discovered in late September.
The available information remains limited. Publica said data had been leaked, but investigators have not established exactly which records were affected or whether all of the exposed information belonged to the pension fund. The supplier has notified the relevant federal authorities, Publica and other customers, and has filed a criminal complaint.
The incident matters because Publica serves a large section of Switzerland’s public sector. Its policyholders include employees of the Federal Administration and the Swiss Federal Institutes of Technology domain. At the end of 2025, the fund counted around 70,000 active members and 41,600 pensioners. It managed almost CHF 45 billion in assets.
Publica has informed policyholders about the breach, its possible consequences and the measures taken so far. The fund has not named the software provider or described the data involved. That leaves policyholders waiting for a clearer account of the exposure while the investigation proceeds.
Investigators trace the supplier attack
The breach began outside Publica’s own systems, at an unidentified software provider used by the pension fund. The supplier detected the attack at the end of September and then reported it to authorities and affected customers. Publica has said the investigation is being conducted with several federal authorities.
This structure makes the inquiry dependent on technical evidence held by the supplier, including the systems accessed, the duration of the intrusion and the files removed. Publica has not said whether the incident involved names, contact details, pension records, financial information or other personal data. Those categories remain unconfirmed.
The Office of the Attorney General has opened a criminal investigation. The federal prosecutor’s involvement adds a formal legal track to the technical review and will help determine what happened, who may be responsible and whether Swiss criminal law was breached. Publica is also assessing the consequences for its policyholders.
The fund said other federal agencies do not have business relationships with the supplier in question. That statement narrows the known institutional exposure, although it does not clarify the scope of the data held by the supplier or whether other customers were affected by the same attack.
Publica’s scale shows the potential reach
More than 111,000 people are connected to Publica as active members or pensioners. The fund reported around 70,000 active members and 41,600 pensioners at the end of 2025, illustrating the potential reach of any incident involving policyholder information. The figures do not show how many people, if any, are affected by the breach.
Publica insures employees of the Federal Administration and the Swiss Federal Institutes of Technology domain, placing the fund within the country’s public sector pension system. Its total assets stood at just under CHF 45 billion at the end of 2025. That financial scale explains why a supplier incident has drawn attention from federal authorities, even though the available announcement concerns data exposure rather than a loss of pension assets.
The distinction is important for policyholders. Publica has described a data breach and said it is examining the potential consequences. The source does not report stolen funds, disrupted pension payments or changes to members’ retirement balances. It also does not identify the type of leaked data.
Until investigators establish which files were accessed or extracted, the figures describe Publica’s institutional size, not the number of people affected. Further notices from Publica and the authorities will be needed to clarify the practical risks for members and pensioners.
Policyholders await verified answers
Publica has notified policyholders while authorities assess what the supplier attack means for them. The fund said it had explained the data breach, its potential consequences and the measures taken. It did not provide further details about those measures in the announcement, and it has not named the supplier.
That limited disclosure reflects the early stage of the inquiry. Investigators must establish whether Publica data was held on the supplier’s affected systems, which records were exposed and whether unauthorised parties obtained them. The Office of the Attorney General is examining the incident alongside the technical work carried out with federal authorities.
For policyholders, the immediate issue is information. Publica’s announcement confirms a leak linked to a supplier attack, but it does not confirm the exposure of any particular personal or pension record. Members and pensioners should rely on direct communications from Publica and remain cautious about unexpected requests for identity, banking or account information that invoke the breach.
The case also puts supplier security under scrutiny across Switzerland’s public institutions. Publica said other federal agencies have no business relationships with the provider. The next substantive update will depend on the forensic investigation and the prosecutors’ assessment of the incident’s consequences.