Full Report
Die SRG hat einen Cyberangriff festgestellt, bei dem Unberechtigte auf Daten von SRF-Mitarbeitenden zugegriffen haben. Die SRG reagierte umgehend, indem die betroffenen Zugänge deaktiviert und zusätzliche Sicherheitsmassnahmen umgesetzt worden sind. Gemeinsam mit internen und externen Fachleuten untersucht die SRG nun den Vorfall. Die SRG hat die zuständigen Behörden informiert, steht mit ihnen in engem Austausch und hat Anzeige erstattet. Die betroffenen Personen wurden direkt über den Vorfall informiert. Die SRG nimmt den Schutz der Mitarbeitenden und ihrer Daten ernst und unterstützt Betroffene aktiv.
Analysis Summary
# Incident Report: Unauthorized Access to SRF Employee Data
## Executive Summary
The Swiss Broadcasting Corporation (SRG) identified a cyberattack resulting in the theft of contact and organizational data belonging to approximately 340 current and former employees of Swiss Radio and Television (SRF). The breach primarily impacted the "Information" unit of SRF, leaking data originating from 2020. SRG has since contained the incident, deactivated compromised accounts, and initiated a forensic investigation with authorities.
## Incident Details
- **Discovery Date:** Reported September 28, 2026
- **Incident Date:** Not explicitly stated (Data involved dates back to 2020)
- **Affected Organization:** SRG SSR (specifically the SRF regional unit)
- **Sector:** Media & Broadcasting
- **Geography:** Switzerland
## Timeline of Events
### Initial Access
- **Date/Time:** Unknown/Not disclosed
- **Vector:** Unauthorized access to specific accounts/access points.
- **Details:** Attackers exploited vulnerabilities or credentials to gain access to legacy data archives or internal systems.
### Lateral Movement
- **Details:** The investigation is ongoing to determine how attackers navigated the environment, though current findings suggest the breach was limited primarily to the SRF "Information" unit's records.
### Data Exfiltration/Impact
- **Data Stolen:** Contact and organizational data of ~340 employees.
- **Specifics:** Names, professional functions, business contact details, and some private contact information.
### Detection & Response
- **Discovery:** Internal security monitoring (Date not specified).
- **Response actions:** Immediate deactivation of affected access credentials, implementation of additional security hardening, and direct notification to all impacted individuals.
## Attack Methodology
*Note: Specific technical details were not disclosed in the public statement.*
- **Initial Access:** Unauthorized access via compromised accounts.
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Likely involved, leading to the deactivation of "affected accesses."
- **Discovery:** Targeted organizational and contact data.
- **Lateral Movement:** Not disclosed.
- **Collection:** Gathering of legacy (2020) employee datasets.
- **Exfiltration:** Confirmed data outflow ("Datenabfluss").
- **Impact:** Data breach and potential privacy violation for staff.
## Impact Assessment
- **Financial:** Not disclosed; costs likely associated with forensic investigation and legal compliance.
- **Data Breach:** ~340 records containing PII (Personally Identifiable Information). No passwords, financial data, or journalistic sources were compromised.
- **Operational:** Low; no reports of broadcasting or service disruption.
- **Reputational:** Moderate; requires management of employee trust and public perception regarding data handling.
## Indicators of Compromise
- **Network indicators:** Not disclosed.
- **File indicators:** Not disclosed.
- **Behavioral indicators:** Unauthorized login attempts or unusual data access patterns leading to account deactivation.
## Response Actions
- **Containment measures:** Deactivation of compromised accounts and access points.
- **Eradication steps:** Deployment of "additional security measures" to block the attack path.
- **Recovery actions:** Forensic analysis by internal and external specialists; filing of criminal charges (Anzeige erstattet).
## Lessons Learned
- **Legacy Data Exposure:** The breach involved data from 2020, highlighting the risk of retaining or under-protecting historical employee records.
- **Unit Isolation:** The impact was largely contained to one unit (SRF Information), suggesting some level of internal segmentation or targeted interest by the attacker.
## Recommendations
- **Data Minimization:** Review retention policies for employee data to ensure old records (e.g., from 2020) are purged or encrypted if no longer needed.
- **Identity Security:** Implement or enforce Multi-Factor Authentication (MFA) across all entry points to prevent unauthorized access via compromised credentials.
- **Monitoring:** Enhance logging for access to sensitive HR and organizational directories.