Cyberattack on Swiss Software Provider Raises Concerns for Thousands of Pension Fund Members
Two major pension funds serving workers in Switzerland’s canton of Bern are investigating whether members’ personal information was exposed after a cyberattack on an external software provider. Although authorities have reported no evidence that data belonging to the two funds was stolen, they have not ruled out the possibility as investigations continue.
The incident, which occurred at the end of September 2026, has also affected the Swiss federal pension fund Publica, where a data leak has been confirmed. The Office of the Attorney General of Switzerland is investigating the incident, while the affected pension institutions and government departments work with the software company to establish what information may have been compromised.
The Bernische Pensionskasse (BPK), which covers employees of the canton and other participating employers, and the Bern Teachers’ Insurance Fund (BLVK) are both affected because they use services provided by the external supplier. The company has not been named in the initial English-language report by Swissinfo, but subsequent reporting identified it as PK Softech AG.
For members, the immediate concern is whether information held by the provider could have reached unauthorized parties. Officials have emphasized that the investigation remains ongoing and that the security of pension assets is separate from the question of whether personal records were exposed.
What authorities know about the incident
The cyberattack was detected at the software provider at the end of September. The company subsequently filed a criminal complaint and notified relevant authorities, Publica and other customers. Switzerland’s Office of the Attorney General has opened an investigation into the incident.
The investigation is examining the scope of the data exposure and whether information held for different pension funds was affected. Publica confirmed that data had leaked from the supplier, but the precise nature and extent of the affected information remained under investigation in reports published on October 8 and 9.
The situation at the two Bern funds is not identical to the confirmed leak affecting the supplier’s systems. Bern’s cantonal authorities said there was no evidence at that stage that data belonging to BPK or BLVK had been stolen. They also cautioned that theft could not be completely excluded.
That distinction is important. A cyberattack on a shared service provider does not automatically establish that every customer’s records were accessed or taken. Investigators must determine which systems were compromised, what information was accessible and whether any exposed files contained personal data belonging to specific customers.
The authorities have not publicly established the full extent of the incident or identified all potentially affected records.
Why the incident matters to pension members
BPK and BLVK provide occupational pension coverage to a substantial population in the canton of Bern. According to figures published by the canton, BPK had 42,145 actively insured people and 18,321 pension recipients at the end of 2025. BLVK had 21,417 active members and 10,259 pension recipients. Together, the funds served more than 63,000 active members and approximately 28,600 pension recipients.
The scale of the membership explains why the investigation matters beyond the immediate technical problem. Pension administration involves sensitive records that can include identifying information, employment details and financial data used to calculate retirement benefits.
In its separate response to the supplier incident, Publica warned that potentially affected information could include names, addresses, dates of birth, Swiss social security numbers, contact details, salaries and pension savings information. These are examples of data that may be at risk in the broader incident; they do not establish that the same information belonging to BPK or BLVK members was stolen.
If personal records were exposed, they could potentially be used in targeted fraud attempts. Criminals who know a person’s employment or pension details may be able to make emails, phone calls or text messages appear more credible. However, there is no confirmed evidence in the cited reports that the Bern pension funds’ members have been targeted using stolen information.
Pension payments and retirement assets remain secure
The Bern pension funds have indicated that the incident has not disrupted their ability to pay benefits. BPK Director André Matthey and BLVK Director Thomas Keller told the Keystone-SDA news agency that pension assets were secure and that retirement payments and lump-sum benefits could continue as usual.
This distinction is central to understanding the potential consequences. A breach of an information system can expose personal records without necessarily affecting the financial assets held by a pension institution. Pension savings are not the same as the administrative data used to manage accounts, calculate benefits or communicate with members.
Nevertheless, the possibility of personal information being exposed remains serious even if payments continue normally. Information about identity, employment and retirement arrangements can be sensitive, and affected individuals may need to take precautions if investigators confirm that their records were compromised.
BPK has said it plans to inform its members in writing about the situation. The two funds are maintaining contact with the software supplier and the relevant cantonal departments while the investigation proceeds.
The risks of relying on external software providers
The incident highlights a broader cybersecurity challenge for financial and pension institutions: sensitive information may be processed or stored by external technology companies rather than exclusively within the institutions themselves.
Such arrangements can support specialized administration and data management, but they also create dependencies. If a provider’s systems are compromised, investigators may need to determine whether information belonging to multiple customers was exposed through the same incident.
The available reporting does not establish the exact technical method used in the attack against PK Softech AG, nor does it identify a confirmed route by which pension members’ data might have been taken. It would therefore be premature to attribute the incident to a particular vulnerability or security failure.
The investigation will need to clarify which systems were accessed, what information left the provider’s environment and whether any affected data can be linked to individual pension funds. Those findings will help determine what additional safeguards or notifications may be required.
What members should do now
Until the investigation provides greater clarity, members of the affected pension funds should be alert to unexpected messages or calls claiming to concern their pensions, employment records or retirement benefits.
They should avoid opening suspicious links or attachments, sharing passwords or providing sensitive information in response to unsolicited contact. Anyone receiving a message that appears to come from a pension fund should verify it through the institution’s established communication channels.
These precautions do not mean that members’ records have been confirmed stolen. They are sensible measures while the extent of a potential exposure remains uncertain.
The next major development will be the outcome of the investigation into the software provider’s systems and the identification of any affected customer records. Until those findings are available, the Bern funds’ position remains that there is no evidence of stolen member data, although the possibility has not been ruled out.
The incident demonstrates why protecting pension information requires attention not only to the funds themselves but also to the technology providers that handle their records. For thousands of workers and retirees in Bern, the immediate priority is establishing whether their personal information was affected while ensuring that pension payments continue without interruption.
