Report finds mistakes which led to Swiss government data breach
Mistakes were made by both the government and the internet company Xplain in the case of a criminal cyber-attack on the Bern-based IT business, the Federal Data Protection Commissioner (FDPIC) said on Wednesday.
Three reports by the FDPIC said that neither the Federal Office of Police (Fedpol) nor the Federal Office of Customs and Border Security (FOCBS) had clearly agreed with Xplain the conditions under which personal data could be stored on the latter’s servers as part of support services.
In addition, Xplain had not taken any appropriate measures to ensure data security or information protection, the reports said.
+ Read more: how vulnerable is Switzerland to cyber-attacks?
The government meanwhile said on Wednesday that it had decided on various measures to prevent future data outflows from the government to IT suppliers.
In the cyberattack on Xplain, hackers targeted a vulnerability on the IT service provider’s servers with ransomware and stole data from the federal administration, which later appeared on the darknet.
Adapted from German by DeepL/kp
This news story has been written and carefully fact-checked by an external editorial team. At SWI swissinfo.ch we select the most relevant news for an international audience and use automatic translation tools such as DeepL to translate it into English. Providing you with automatically translated news gives us the time to write more in-depth articles.
If you want to know more about how we work, have a look here, and if you have feedback on this news story please write to english@swissinfo.ch.
In compliance with the JTI standards
More: SWI swissinfo.ch certified by the Journalism Trust Initiative
You can find an overview of ongoing debates with our journalists here . Please join us!
If you want to start a conversation about a topic raised in this article or want to report factual errors, email us at english@swissinfo.ch.