Desk live·
ForensicPost
Ransomware/Public sector/File 23-0614

Play Published 65,000 Swiss Federal Documents Taken From Contractor Xplain

Play breached the Swiss software provider Xplain in May 2023 and published about 1.3 million files. Roughly 65,000 belonged to the Federal Administration — mostly to the justice and police units the company served.

Constructed geometry · not a chart of case data
JurisdictionSwitzerlandBernthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetXplain / Swiss Federal Administration
ActorPlay
D. Kennedy11 min readConfidence: high3 sources reviewed

The Play operation breached Xplain, a Swiss provider of software to government departments and the armed forces, on 23 May 2023, and published stolen material on 14 June. Of roughly 1.3 million files released, about 65,000 were subsequently assessed as relevant to the Federal Administration.

Around 95% of those related to units of the Federal Department of Justice and Police — the Federal Office of Justice, the Federal Office of Police, the State Secretariat for Migration and the department’s internal IT service centre — with just over 3% relating to the defence department. Around 5,000 documents were assessed as containing sensitive information including personal data, technical details, classified information and account passwords.

Five Per Cent Was The Government

The federal material was a twentieth of what was published. The other nineteen twentieths belonged to the supplier and its other clients.

That proportion is the argument. A contractor accumulates material from everyone it serves, in one place, under one security programme, and a breach of it distributes across the whole client list at once. We filed that at 26-0713, at 22-1104b, and at 22-0301 — the assessment question is not whether the supplier can be disrupted but what of yours it is holding.

The Clients Determine The Sensitivity

Xplain is a software company. Its client list — justice, police, migration, defence — is what made its file store a national security matter.

A supplier to those functions holds case material, migration records and system documentation because it cannot build the software otherwise. We have recorded the same inheritance at 23-0217 and 23-0808: the data’s danger comes from the institution it describes, and a vendor risk process that scores the vendor rather than the data will miss it every time.

Passwords In The Dump

The assessment that some published documents contained account passwords is the detail with a future. Every one of those is a live credential until somebody finds and rotates it.

We have recorded secrets sitting in stolen material at 22-1101, 22-0412 and 23-0104, where CircleCI told customers to rotate everything it held. A published dump is not a static disclosure; it is a working set of starting points, and it stays useful long after the news coverage ends.

How we reported this

Compiled from contemporaneous reporting and the Swiss federal authorities’ published assessment of the leak, listed below. This desk has not accessed any published material. No individual is named. The proportions describe the published set as assessed, not the totality of what was taken. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Switzerland: Play ransomware leaked 65,000 government documentsBleepingComputer
  2. Play ransomware leaked 65,000 Swiss government documents, investigation findsThe Record
  3. Information on the data leakage at XplainSwiss Federal Office of Justice
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary