The Swiss government has revealed that a recent ransomware attack on an IT supplier could have implications for its data. Today, it is warning that the country is being targeted by DDoS attacks.
The situation reflects the complex threats affecting organizations and governments as they use third-party services for data hosting and public exposure of online services.

Ransomware attack exposes data
Last Tuesday, the Swiss government revealed that it was affected by a ransomware attack on Xplain, a Swiss technology provider that supplies various government agencies, administrative units, and even the country's military force with software solutions.
The IT company was breached by the Play ransomware gang on May 23, 2023, with the threat actor claiming to have stolen various documents containing private and confidential data, financial and tax details, etc.
On June 1, 2023, the Play ransomware group published the entire dump, apparently after failing to blackmail Xplain into paying a ransom.

The Swiss government now states that, while investigations into the content and validity of the leaked data are still ongoing, it is possible that the attackers published data belonging to the Federal Administration.
"Clarifications are currently underway to identify the specific units and data involved," the press release published on the government portal states.
"Contrary to the initial findings and following recent in-depth clarifications, it must be assumed that functional data could also be affected ."

'NoName' DDoS
A second press release posted today on the Swiss government's website warned of access problems on various Federal Administration websites, as well as electronic services .
The reason for this outage is a DDoS (distributed denial of service) attack launched by NoName, a pro-Russian hacktivist group that has been targeting NATO-aligned countries and entities in Europe, Ukraine , and North America since early 2022.
"Many Federal Administration websites were/are inaccessible on Monday, June 12, 2023, due to a DDoS attack on its systems," the announcement states.
"Federal Administration specialists quickly noticed the attack and are taking steps to restore accessibility to websites and applications as soon as possible.".
According to the same press release, NoName attacked the Parliament website last week when its members discussed whether the country should abandon its neutrality to send aid to Ukraine.
Information source: bleepingcomputer.com
