BERN. Publica, the pension fund for employees of the federal administration, disclosed on Thursday that data has leaked following a cyberattack on one of its external software suppliers. The Office of the Attorney General has opened an investigation, and the fund said it is still establishing exactly which data was affected.

The supplier detected the attack at the end of September and filed a criminal complaint. It informed the relevant federal authorities, Publica and its other customers at the time. Publica said it is investigating the extent of the leak in collaboration with several federal offices, and has since written to policyholders about the breach, its potential consequences and the measures taken.

The fund declined to name the supplier or to describe the nature of the data involved. It stressed that, according to its own information, no other federal agency has a business relationship with the company in question, which limits the potential spread of the incident across the administration.

It is not yet clear exactly which data has been affected.

What policyholders have been told

In its letter to insured members, Publica set out the standard precautions for a data leak of this kind: caution with unexpected emails, letters or phone calls that quote personal details, and particular care with any message that asks for passwords or payment information. Pension funds hold exactly the data that makes such approaches convincing, including names, addresses, dates of birth, salary histories and bank details.

Whether any of that information has in fact been copied remains open. The investigation now under way must establish what the attackers reached, how long they had access and whether the data has been offered or published anywhere. Experience with comparable incidents suggests that answer will take weeks rather than days.

One of the largest pension funds in the country

Publica is among the biggest pension funds in Switzerland. It insures the staff of the federal administration and of the federal institutes of technology, among others, and closed 2025 with around 70,000 active members and 41,600 pensioners. Its assets total just under CHF 45 billion.

The breach lands in a year of repeated warnings from the Federal Office for Cybersecurity about attacks on suppliers rather than on institutions directly. The office has long argued that the weakest point of an otherwise well defended organisation is often a contractor with quieter systems, a pattern seen this summer when fraudsters manipulated a food delivery website rather than attacking a bank.

For the federal administration, the political question will follow quickly: how a supplier with access to pension fund data was vetted, and what duties to report attacks it was under. Parliament has tightened reporting obligations for critical infrastructure in stages since 2023, and each new incident tests whether those obligations reach far enough down the supply chain.

Publica said it would inform policyholders again as soon as the investigation produces firm findings. Until then, the advice to the more than 110,000 people whose pensions it manages is the advice that follows every such incident: be suspicious of messages that know too much about you.