Full Report
An external software supplier used by the Swiss Federal Pension Fund Publica identified a cyber attack at the end of September. The company immediately filed a criminal complaint and informed the relevant federal authorities, the Swiss Federal Pension Fund Publica and its other customers. The Office of the Attorney General has launched an investigation. No other federal entities have a business relationship with the company. The company is currently working together with various federal authorities to determine the scope of Publica data affected. Publica has informed its members about the data leak, its implications and the action taken.
Analysis Summary
# Incident Report: Supply Chain Cyber Attack on Publica Software Vendor
## Executive Summary
An external software supplier for the Swiss Federal Pension Fund (Publica) suffered a cyber attack in late September, resulting in a confirmed data leak. While the supplier does not serve other federal entities, Publica data was compromised, leading to a criminal investigation by the Office of the Attorney General. The incident highlights the risks associated with third-party software providers in the public sector.
## Incident Details
- **Discovery Date:** Late September (Year not specified, presumed 2023/2024 based on source)
- **Incident Date:** Late September
- **Affected Organization:** Swiss Federal Pension Fund (Publica) via an unnamed External Software Supplier
- **Sector:** Public Sector / Pension Funds / Financial Services
- **Geography:** Switzerland
## Timeline of Events
### Initial Access
- **Date/Time:** Late September
- **Vector:** Unknown (Third-party supplier breach)
- **Details:** The attack originated within the infrastructure of a specialized software vendor used by Publica.
### Lateral Movement
- **Details:** Not disclosed; however, the attackers successfully accessed environments containing data related to Publica members.
### Data Exfiltration/Impact
- **Details:** A data leak was confirmed. The exact volume and specific sensitivity of the data are currently under investigation by federal authorities and the supplier.
### Detection & Response
- **Detection:** Identified by the software supplier in late September.
- **Response:** The supplier filed a criminal complaint, notified Publica, and alerted federal authorities. Publica subsequently notified its members regarding the potential implications.
## Attack Methodology
*Note: Specific technical details (TTPs) were not disclosed in the provided article.*
- **Initial Access:** Software Supply Chain Compromise.
- **Persistence:** Unknown.
- **Privilege Escalation:** Unknown.
- **Defense Evasion:** Unknown.
- **Credential Access:** Unknown.
- **Discovery:** Unknown.
- **Lateral Movement:** Unknown.
- **Collection:** Access to Publica client/member data.
- **Exfiltration:** Confirmed data outflow/leak.
- **Impact:** Data breach and reputational damage to the pension fund.
## Impact Assessment
- **Financial:** Costs associated with forensic investigations, legal fees, and potential regulatory fines are pending.
- **Data Breach:** Confirmed leak of Publica member data; scope currently being determined.
- **Operational:** No reported disruption to pension payments, but significant administrative overhead for incident response.
- **Reputational:** High; requires communication with all pension fund members and federal stakeholders.
## Indicators of Compromise
- **Network indicators:** None disclosed.
- **File indicators:** None disclosed.
- **Behavioral indicators:** Unauthorized access to database environments and unusual data egress patterns at the supplier level.
## Response Actions
- **Containment:** The supplier initiated internal containment protocols (specifics not disclosed).
- **Eradication:** Investigation launched by the Office of the Attorney General of Switzerland.
- **Recovery:** Publica notified all members; federal authorities are assisting in determining the data scope.
## Lessons Learned
- **Supply Chain Vulnerability:** Third-party vendors remain a critical weak point for government-adjacent organizations.
- **Transparency:** The supplier’s immediate notification and filing of a criminal complaint allowed for a faster coordinated response between Publica and the government.
- **Isolation:** The fact that no other federal entities used this supplier limited the blast radius of the incident.
## Recommendations
- **Third-Party Risk Management (TPRM):** Conduct more frequent security audits and penetration testing of external software suppliers.
- **Data Encryption:** Ensure that sensitive member data is encrypted at rest and in transit within vendor environments.
- **Least Privilege:** Enforce strict access controls so that vendors only have access to the specific data sets required for their software to function.
- **Incident Response Planning:** Review and update joint incident response playbooks with all critical third-party service providers.