Switzerland’s federal pension fund Publica said on Thursday that a data leak affected it after one of its external software providers was hit by a cyberattack at the end of September.
The incident has raised fresh concerns about the cybersecurity risks organizations face when they rely on external technology providers to manage digital systems and data.
Publica said the cyberattack on its external software provider resulted in a data leak. The pension fund is now assessing the extent of the incident and the information that may have been affected.
The specific nature and scope of the data leak have not been disclosed.
Publica has not reported any financial losses or any misuse of the leaked data so far. The organization is taking steps to address the incident and reduce further risk.
The breach highlights the risks of interconnected digital infrastructure, where an attack on a third-party service provider can affect organizations that depend on its systems.
Public institutions and other organizations increasingly rely on external technology companies for software and digital services. A security incident involving one of these providers can therefore have consequences beyond the company directly targeted by hackers.
Publica’s announcement comes as organizations across sectors face growing cyber threats and increased scrutiny of third-party providers’ security practices.
The pension fund has not disclosed the identity of the software provider involved in the incident or provided details about how the attackers gained access to its systems.
Also Read: South Korea Bank Hacks: 26-Year-Old in China Suspected
Publica is continuing to assess the consequences of the cyberattack and the potential exposure of data. It has also begun taking steps to address the breach and reduce the risk of similar incidents in the future.
At this stage, the pension fund has not indicated that the leaked information has been misused or that the incident has resulted in financial losses.
The case underscores a broader cybersecurity challenge for organizations: protecting sensitive information increasingly depends not only on their own systems but also on the security measures implemented by the external providers they rely on.