Politics · Switzerland · 1 day ago
Possible Publica data leak raises questions about software provider access
Publica, a large Swiss pension fund, says a cyberattack may have exposed sensitive information about its members.
The attack targeted its software supplier, PK Softtech AG, rather than Publica directly.
The data may include names, addresses, Swiss social security numbers, salaries and pension balances.
It is not yet clear how much data was exposed or who was affected.
A cybersecurity expert says software suppliers may access client data to run systems or carry out tests and repairs.
Using real personal data for testing can increase the harm if a supplier is attacked, although anonymising data takes time and can be error-prone.
Exposed details could help criminals create convincing scam messages or misuse people’s identities.
Publica has urged members to be cautious about unusual calls or messages, and the investigation into the possible leak’s scale is ongoing.
A suspected data leak at Swiss pension fund Publica may have exposed sensitive information about insured people.
The cyberattack targeted Publica’s software provider, PK Softtech AG, rather than Publica directly.
Potentially affected information includes names, addresses, AHV numbers, salaries and pension balances.
The size of the leak and which insured people may be affected are not yet known.
Cybersecurity expert Marc Ruef outlined possible routes for data access and warned that security can be overlooked when selecting software providers.
- Who
- Publica’s insured people may be affected; the attack targeted software provider PK Softtech AG.
- What
- A cyberattack may have resulted in sensitive insured-person data being leaked.
- When
- The report was published on 10 October 2026; the attack date is not stated.
- Where
- The affected organization is Publica, Switzerland’s federal pension fund; the attack targeted PK Softtech AG.
- Why
- Not stated. The article describes possible ways the provider could access data, including hosting software or conducting tests and maintenance.
This story does not have two clearly opposing sides.
Daten zu anonymisieren und zu pseudonymisieren, ist sehr aufwändig und auch fehleranfällig
Manchmal entscheidet man sich für die Wirtschaftlichkeit anstatt für die Sicherheit.
Erfahrungsgemäss steht das Thema Cybersecurity oft nicht sehr weit oben auf der Liste.
SRF’s Rendez-vous broadcast included a report about the possible Publica data leak.
SRF published its article on how sensitive data may have reached an external software company.
- Targeted company
- PK Softtech AG
- Potentially exposed data
- Names, addresses, AHV numbers, salaries and pension balances
- Affected fund
- Publica, Switzerland’s federal pension fund
- Cybersecurity expert
- Marc Ruef
- Unknown details
- The leak’s size and which insured people may be affected







