Publica Leak Confirmed
Swiss Federal Pension Fund Publica says its unnamed software supplier identified a cyber attack at the end of September. Its 8 October notice confirms that data leaked and says Publica notified members while the supplier and federal authorities determine which data were affected.
The supplier filed a criminal complaint and notified Publica, federal authorities and other customers; the Office of the Attorney General is investigating. The notice gives no exact event or publication time, supplier identity, affected population, data fields, method or CVE.
Verify contact before acting
A confirmed leak with an unknown data inventory calls for careful verification, not a guessed breach scenario.
BlackTree recommends verifying any incident message through a Publica channel found independently. Do not use links or contact details inside an unexpected message. Save the notice and later updates so you can compare verified findings with any request made of you. This is a verification step, not evidence that fraud is occurring.
Ask for an evidence map
BlackTree recommends that Publica and connected organisations ask the supplier for an evidence map covering the affected service, Publica data flows, access identities, integrations, preserved logs, and the earliest and latest suspicious activity. It should distinguish data viewed, queried, exported and confirmed lost.
Preserving authentication, administrator, export, API and support-access logs would help investigators test that map before anyone makes exposure-specific claims. This is an evidence question set, not proof that a control failed.
Keep the boundary precise
Publica says no other federal entity has a business relationship with the supplier. This does not exclude unrelated incidents.
An omitted data field is not proof that it was safe. Equally, a confirmed leak does not establish credential theft, payment fraud or pension account compromise.
The responsible sequence is to verify contact, preserve evidence, publish a field-level inventory when supported, then give members actions tied to confirmed exposure.
Source: Publica press release, hosted by the Swiss State Secretariat for International Finance.


