Government

Swiss Fear Government Data Stolen in Cyberattack

Switzerland said government operational data might have been stolen in a ransomware attack on a technology firm that provides software for several departments.

Switzerland said government operational data might have been stolen in a ransomware attack on a technology firm that provides software for several departments.

Switzerland said Thursday that government operational data might have been stolen in a cyberattack on the technology firm that provides software for several departments.

“Xplain, a Swiss provider of government software, has been the victim of a ransomware attack. After the stolen data had been encrypted and the company blackmailed, the attackers posted some of the stolen data on the darknet,” the government said in a statement.

“Contrary to the initial findings and following recent in-depth clarifications… it appears that operational data of the federal administration could also be affected.

“In-depth analyses are still ongoing.”

The Swiss army and the customs department are among the clients of Xplain, which supplies software to authorities specialising in homeland security.

The government said it did not believe that the Xplain systems have direct access to the federal administration systems.

Advertisement. Scroll to continue reading.

Xplain accused a ransomware group called Play of being behind the attack.

“We have not made any contact with the Play group and we will not pay a ransom,” Xplain’s director Andreas Loewinger told AFP on Saturday.

Xplain has notified Switzerland’s National Cybersecurity Centre and the Bern police.

As in other countries, cyberattacks targeting companies, governments and even universities are on the increase in Switzerland.

Recently, two media outlets, CH Media and NZZ, were targeted by Play.

Related: Ransomware Group Used MOVEit Exploit to Steal Data From Dozens of Organizations

Related: SaaS Ransomware Attack Hit Sharepoint Online Without Using a Compromised Endpoint

Related: Pharmaceutical Giant Eisai Takes Systems Offline Following Ransomware Attack

Related Content

Malware & Threats

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

Cybercrime

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims.

Artificial Intelligence

The accord opened the door to future regulation but focused on four voluntary steps for the companies to take.

Data Breaches

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

Government

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. 

Cybercrime

Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version