The Play operation breached Xplain, a Swiss provider of software to government departments and the armed forces, on 23 May 2023, and published stolen material on 14 June. Of roughly 1.3 million files released, about 65,000 were subsequently assessed as relevant to the Federal Administration.
Around 95% of those related to units of the Federal Department of Justice and Police — the Federal Office of Justice, the Federal Office of Police, the State Secretariat for Migration and the department’s internal IT service centre — with just over 3% relating to the defence department. Around 5,000 documents were assessed as containing sensitive information including personal data, technical details, classified information and account passwords.
Five Per Cent Was The Government
The federal material was a twentieth of what was published. The other nineteen twentieths belonged to the supplier and its other clients.
That proportion is the argument. A contractor accumulates material from everyone it serves, in one place, under one security programme, and a breach of it distributes across the whole client list at once. We filed that at 26-0713, at 22-1104b, and at 22-0301 — the assessment question is not whether the supplier can be disrupted but what of yours it is holding.
The Clients Determine The Sensitivity
Xplain is a software company. Its client list — justice, police, migration, defence — is what made its file store a national security matter.
A supplier to those functions holds case material, migration records and system documentation because it cannot build the software otherwise. We have recorded the same inheritance at 23-0217 and 23-0808: the data’s danger comes from the institution it describes, and a vendor risk process that scores the vendor rather than the data will miss it every time.
Passwords In The Dump
The assessment that some published documents contained account passwords is the detail with a future. Every one of those is a live credential until somebody finds and rotates it.
We have recorded secrets sitting in stolen material at 22-1101, 22-0412 and 23-0104, where CircleCI told customers to rotate everything it held. A published dump is not a static disclosure; it is a working set of starting points, and it stays useful long after the news coverage ends.
Compiled from contemporaneous reporting and the Swiss federal authorities’ published assessment of the leak, listed below. This desk has not accessed any published material. No individual is named. The proportions describe the published set as assessed, not the totality of what was taken. Graded high. Corrections: corrections@forensicpost.com.
- Switzerland: Play ransomware leaked 65,000 government documentsBleepingComputer
- Play ransomware leaked 65,000 Swiss government documents, investigation findsThe Record
- Information on the data leakage at XplainSwiss Federal Office of Justice