Ransomware (Play)

Xplain Ransomware Attack

The ransomware attack on Xplain affected over 900 GB of Swiss government data. Analysis of the incident and why cyber insurance would have helped.

Xplain Ransomware Attack

What happened?

In 2023/2024, Xplain AG, a Swiss IT service provider for government agencies, fell victim to a ransomware attack by the “Play” group. Over 900 GB of sensitive data was stolen and published on the darknet.

Who was affected?

  • Xplain AG itself
  • Swiss federal authorities (Fedpol, FOCA, SEM and others)
  • Cantonal authorities and police forces
  • Thousands of citizens whose data was affected

How large was the damage?

  • IT forensics and incident response: Estimated costs of several million CHF
  • Reputational damage: Loss of trust among government clients
  • Regulatory consequences: Investigations by the FDPIC
  • Business interruption: Weeks of restricted operations

Would cyber insurance have helped?

Yes. A comprehensive cyber insurance policy would have covered:

Cost itemEstimated costCovered?
IT forensicsCHF 500,000+Yes
Legal adviceCHF 300,000+Yes
Notification of affected personsCHF 200,000+Yes
Business interruptionCHF 1,000,000+Yes
Crisis management/PRCHF 100,000+Yes

Lessons for Swiss SMEs

  1. Supply chain risk: An attack on a supplier can affect you indirectly.
  2. Data protection obligations: With the nFADP (since 1.9.2023), reporting and information obligations have become stricter.
  3. Insurance for the entire supply chain: Check whether your IT partners are insured.

Have questions about cyber insurance?

Our partners at BTAG are happy to advise you — free and with no obligation.

A service of BTAG Versicherungsbroker AG, Bern — independent advice since 1990.

BTAG Versicherungsbroker AG Mitglied SIBA FINMA Register-Nr. 12229
Contact us →