cybersecurity
Cyberattack steals data belonging to hundreds of Swiss broadcaster staff
A cyberattack on the Swiss Broadcasting Corporation exposed contact and organisational data belonging to around 340 current and former SRF employees. The article should explain what information was taken, what was not compromised, how the broadcaster responded and what the incident reveals about cybersecurity risks facing public institutions and media organisations.

Cyberattack Exposes Data on 340 SRF Staff
Around 340 current and former SRF employees have had personal workplace data exposed after a cyberattack on the Swiss Broadcasting Corporation, the parent company of Swiss public media outlets including German language broadcaster SRF.
The stolen records contain names, job titles and professional contact details. Some private contact information was also included. The SBC said the data mainly concerns staff from SRF’s current Information department, with records dating from 2020.
The incident matters because the broadcaster handles sensitive work across newsrooms, production teams and administrative operations. Employee directories can help attackers map an institution, identify targets and craft convincing messages, even when more sensitive systems remain protected.
The SBC reported the breach on September 28, 2026. It said there was no indication that the information had been published or misused. The company also said it had found no evidence that other SRF units were affected.
The disclosure gives the public a limited but important picture of the attack. Investigators still need to establish how the attackers entered the system, how long they had access and whether they copied anything beyond the identified staff records.
The Records Taken, and the Data Left Untouched
Names, roles and contact details were taken, while the most sensitive categories identified by the broadcaster remained untouched.
The compromised information included professional contact details, such as work addresses and other organisational data, alongside some private contact details. These records can reveal reporting structures and working relationships inside a large media organisation. They may also expose former employees who no longer expect their details to sit inside active institutional systems.
The SBC said there was currently no indication that passwords or financial and banking information had been affected. It also reported no evidence that journalistic sources, research data or communications content had been accessed.
That distinction is significant for SRF’s newsroom operations. Source protection and confidential communications are central to public interest reporting, particularly when journalists work on politically sensitive, criminal or security related stories. The available information does not show that those materials were reached in this incident.
The broadcaster has kept its public account focused on confirmed findings. It has not identified the attackers, disclosed the attack method or said whether the records appeared online. Those questions remain part of the investigation involving internal and external specialists.
SBC Cuts Access and Opens a Criminal Case
The SBC moved to contain the incident as soon as it discovered unauthorised access. The broadcaster said it deactivated the affected access points and introduced additional security measures.
It also filed a criminal complaint, placing the case with law enforcement as investigators work to determine the cause and full extent of the intrusion. Internal and external specialists are cooperating in the inquiry. The company has not publicly assigned responsibility for the attack.
The broadcaster said current information showed that no further unauthorised access had taken place and that the incident was under control. It also said staff in other units did not appear to have been affected.
Those measures reduce the immediate risk, but they do not close every issue raised by the breach. Investigators must verify the boundaries of the affected system, check whether the stolen records were copied or transferred, and assess which current and former employees face a heightened risk of targeted phishing or impersonation.
The company’s response also illustrates the practical demands of breach management. Public institutions must secure systems, preserve evidence, inform affected people and maintain essential services at the same time. The SBC’s criminal complaint and continuing investigation mark the incident as a security matter, not simply an internal data protection problem.
Why Ordinary Staff Data Carries Real Risk
A staff directory can provide an attacker with a map of an institution. Names and job titles show who works where, while organisational details can indicate reporting lines, specialist teams and likely points of contact.
For a broadcaster, that information has particular value. News organisations depend on rapid communication among reporters, editors, producers, technical teams and managers. Attackers can use familiar names and plausible roles to send targeted messages, request documents or impersonate colleagues. The source material does not say that such misuse occurred in the SRF case, but the risk follows directly from the type of information exposed.
The breach also shows why former employees remain relevant to data protection. Records created or retained over time can continue to identify people after they leave an organisation. The SBC said the affected information dated from 2020, underlining the importance of reviewing old directories and access permissions.
Swiss public institutions face the same pressure as other large organisations. They hold extensive personal and operational data, rely on interconnected systems and must remain accessible to the public. Security controls therefore need to cover routine administrative records as well as highly confidential material.
Investigation Will Define the Full Exposure
The immediate findings are limited, while the investigation remains open. The SBC has reported no evidence that the stolen data was published or misused, and it has found no indication that passwords, financial information, sources, research data or communications content were compromised.
Those findings provide reassurance to staff and to the wider Swiss public, but they do not answer every question. The investigation must establish the attack’s entry point, the precise records accessed and whether the incident affected any systems beyond those identified so far.
For SRF employees, exposed contact details may justify extra caution around unexpected emails, calls and requests that refer to internal roles or colleagues. The broadcaster’s additional security measures and continuing review will be important in determining whether the risk has been contained.
The case also places a public institution under scrutiny at a time when cyberattacks have become a recurring challenge for Swiss companies and authorities. Media organisations face a dual responsibility: protect personal data held for routine operations and safeguard the confidential work that supports independent journalism.
The next significant update will be the investigation’s account of what happened and whether the breach extended beyond the approximately 340 staff records already disclosed.