Play ransomware attack on Swiss supplier Xplain reached federal government data

Organization
Xplain
Exploit
Ransomware
Industry
IT Services

Xplain, a Swiss company that supplies software to police, security and justice authorities, was hit by a ransomware attack in May 2023 that became public on 23 May. The Play ransomware group claimed the intrusion.

Because Xplain held operational data belonging to its government customers, the breach reached into the Swiss federal administration. Affected units included the Federal Office of Police, the Federal Office for Customs and Border Security, the State Secretariat for Migration, the Federal Office of Justice, the defence procurement agency armasuisse and several cantonal police forces.

In consultation with prosecuting authorities and the federal government, Xplain did not respond to the ransom demand. On June 14, 2023 Play published the stolen material on the darknet. The package amounted to around 1.3 million files. Later analysis by Switzerland's National Cyber Security Centre found that roughly 65,000 of them, about 5 percent of the total, were relevant to the federal administration. Of those, 47,413 belonged to Xplain itself and 9,040 to the federal administration, and the federal files contained personal data, technical information, classified documents and, in a handful of cases, readable passwords. Fedpol data accounted for under 10 percent of the leak and included records from HOOGAN, a database on people involved in violence at sporting events.

Fedpol and the customs office filed criminal complaints, the Federal Data Protection and Information Commissioner opened an investigation, and on June 28 the Federal Council appointed a cross departmental crisis team and ordered an administrative inquiry into how government data came to reside on Xplain's systems.

Sources