SRG breach exposes staff data, but not yet the whole mess

The broadcaster says the attack is contained, though the leak of employee contact and organisational data is hardly a triumph for digital hygiene.

SRG breach exposes staff data, but not yet the whole mess

A media group that spends much of its time explaining the world to others has now had to explain a breach of its own. SRG says it detected a cyber incident in which unauthorised parties gained access to data from SRF employees, then moved quickly to shut down the affected accounts and tighten security. So far, the organisation says the attack is under control. That is reassuring, up to the point where one remembers that the data were accessible in the first place.

The compromised material concerns contact and organisational information from 2020, affecting roughly 340 current and former SRF employees. Most of the records belong to staff in the current Information unit of SRF’s regional division. Employees from other business and regional units are, for now, not affected. The data include names, functions and work-related contact details, and in some cases private contact information as well.

SRG says there is no indication at present that passwords, financial or bank data, journalistic sources, research material or communication content were touched. Nor, according to the broadcaster, is there any sign that the data have been published or used for malicious purposes. Those are the facts on the table; the rest is the familiar fog that follows any breach, where organisations speak of vigilance and investigations while hoping the public will move on.

That is not quite how it works, of course. SRG has informed the people concerned directly, reported the incident and filed a complaint. It is also working with the competent authorities and with internal and external specialists to establish how the attack happened and how far the damage extends. Existing protective measures are being reviewed and, if necessary, strengthened further.

The episode is a reminder that even institutions with public responsibilities can be caught out by the most ordinary weakness of the digital age: access that should not have been there. For SRG, the immediate task is containment and clarification. For everyone else, the lesson is less elegant but more useful: data security is not a slogan, and the bill usually arrives after the breach, not before it.

Written by Sandy van Dongen sandy.vandongen@alpineweekly.com