Swiss pension funds are investigating whether members’ sensitive personal data were compromised in a cyber attack on data management software provider PK Software at the end of September.

PK Software provides data management systems to Publica, the pension fund for employees of the Swiss federal government, Pensionskasse Post, Migros Pensionskasse and Bernische Pensionskasse.

Publica told IPE that members’ data, including salaries, pension assets and benefit amounts, as well as contact details, could have been affected by the attack.

“It is currently impossible to determine which member, or how many of them, may have had their data compromised. The analysis is ongoing,” a spokesperson for the pension fund said, adding that pension assets remain “secure”.

Publica is investigating the incident with IT experts from federal agencies and the software supplier.

Pensionskasse Post told IPE it was investigating whether, and to what extent, members’ data might have been affected.

Data held by PK Softech on behalf of Pensionskasse Post is anonymised, while personal data requiring special protection, such as information on disability insurance, is not stored by the software provider, the scheme added.

Migros Pensionskasse is working with PK Softech to establish whether data were stolen.

Bernische Pensionskasse is in contact with the software supplier and cantonal authorities. “At present, there is no indication that data has been stolen. However, this cannot be entirely ruled out,” the pension fund said in a statement.

PK Software told IPE it had yet to establish with certainty which data had been compromised in the cyber attack.

“Consequently, at this stage, we can neither confirm nor rule out that other pension funds – in addition to Publica – have been affected. Investigations are currently underway,” the company added in the statement.

PK Software said “unknown parties” had gained access to part of its IT infrastructure using malware.

The company said it had “immediately disconnected the affected environment from the network, engaged external specialists, informed the relevant authorities, and filed a criminal complaint”.

The Swiss Federal Office of the Attorney General has launched an investigation.