Nick Salzmann

· Articles

Seven francs for my pension data

A software vendor to Publica, the pension fund for Switzerland’s federal employees, was hacked in late September. Data got out. Which data, and where it went, is under investigation.

Possibly my data. I’m insured with Publica.

A pension fund doesn’t hold just any data. Publica wrote to me yesterday to tell me exactly what: first and last name, AHV number (that’s the Swiss social security number), address, phone numbers (work and private), email addresses (work and private), pension details (salary, insured earnings, retirement savings), marital status, and information about my spouse or partner.

That’s the dataset you need to rebuild a person’s identity.

I’m pissed.


Publica doesn’t name the vendor. It doesn’t have to, because the company outed itself the same morning: PK Softech AG, Reinach BL, a specialist in pension fund software. The rest is on simap.ch, the Swiss public procurement portal, where every government contract is published with price and term. In 2017, PK Softech won the tender for Publica’s core system against six competitors. Contract value: 12.6 million francs. Term: up to 16 years, which takes us to 2033.

Let’s do the math. 12.6 million, divided by 16 years, divided by 110,000 insured members and pensioners: seven francs. For seven francs per person per year, my data sits with a company for which this contract is probably the biggest it has ever had. Whether that’s a lot or a little, I honestly don’t know. But the asymmetry is striking. For Publica, a rounding error on a 45-billion-franc balance sheet. For PK Softech, its existence. That’s a problem for two reasons.

  1. Whoever depends on one customer says yes to everything and doesn’t ask uncomfortable questions—like whether a fixed price also covers security measures nobody ordered.
  2. A company that small can’t run a security team, 24-hour monitoring, or incident response; for them, an attack isn’t an incident, it’s an existential threat. And Publica still can’t just walk away—you don’t swap out a core system in a year. Both are stuck, and neither has real leverage. That’s the kind of arrangement where things get left undone.

Lorem ipsum

I took a look at PK Softech’s website.

The “Team” menu item leads to a 404 page. Taking your own people out of the line of fire after an incident like this is understandable. Obvious, even. Well done.

In the source code, there’s an invisible side panel that was never filled in. Contact address: Cybersteel Inc., 376-293 City Road, San Francisco. Phone: +44 1234 567 890. That’s the demo content of a purchased website theme, shipped with every single page for years. A company with access to Swiss pension data is, according to its own website, headquartered in a lorem-ipsum office in California.

Quellcode-Screenshot von pksoftech.ch (9.10.2026): Beispieldaten, die nie angepasst wurden
Reinach BL or San Francisco?
Source code screenshot from pksoftech.ch dated October 9, 2026: Lorem Ipsum text that has never been removed
Lorem Ipsum


The privacy policy opens like this: „This website and its content are provided by PK Softech AG without commercial interests.” A corporate website with product pages and a contact form. Without commercial interests. The sentence comes from a template for personal websites; nobody read it before it went live.

Further down: the site uses Matomo, “which uses so-called ‘fingerprints’ (not ‘cookies’), i.e., text files stored on your computer.” That’s the definition of a cookie, accidentally glued onto a fingerprint. The site really doesn’t set any cookies, so the claim is true. Only the explanation is wrong. And the cookie banner asks for my consent to cookies that never arrive.

Sure: a website isn’t a pension fund system. None of this proves anything about the security of the software that manages my data. PK Softech surely maintains its core system more carefully than its website. But a website shows how a company handles the things that aren’t its core business. Privacy policy, theme leftovers, cookie banner—all side issues.

Cybersecurity is a side issue for a pension software vendor, too. Until it isn’t.

Questions

What I’d like to know now, as an insured member—and what Publica owes me according to its own privacy policy (“Through the selection of service providers and appropriate contractual agreements, we ensure that data protection is guaranteed [...]”):

  • Why was member data at the vendor in the first place—hosting, test environment, migration, support? And why in plain text? Publica explicitly names pseudonymization as a safeguard.
  • What security requirements were in the 2016 specifications, and has anyone checked them in the nine years since? Swiss data protection law requires the client to “satisfy itself” that the processor can guarantee security.
  • What access did PK Softech have to Publica’s systems? The company offers remote support via TeamViewer on its website. Has that access been shut off since the attack?
  • Which data exactly is gone, and when will I find out?
  • What does a fixed price through 2033 mean for security work nobody ordered in 2016?


Seven francs. For secure data, I’d have paid fourteen. Nobody asked me.


← Blog