Supply chain β›“ Supply Chain

Swiss Goverment Third-Party Breach (March 2024)

πŸ“… 2024-03-01 🏒 Xplain
Primary Source β†—

Incident Details

Switzerland: Play ransomware leaked 65,000 government documents. The National Cyber Security Centre (NCSC) of Switzerland has released a report on its analysis of a data breach following a ransomware attack on Xplain, disclosing that the incident impacted thousands of sensitive Federal government files. Xplain is a Swiss technology and software solutions provider for various government departments, administrative units, and even the country’s military force. The Play ransomware gang breached the company on May 23, 2023. At the time, the threat actor claimed to have stolen documents containing confidential information, and in early June 2023, it followed through on its threats and published the stolen data on its darknet portal. Third-party company: Xplain.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Xplain
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-03-01 Breach occurred
  2. 2024-03-07 Publicly disclosed