Customer data exposed: a warning for trustees

The hacking of a Vaud-based trust company serves as a stark reminder of a reality that many companies would rather ignore: accounting, tax and payroll data are prime targets. According to Le Temps, a trust firm based in Yverdon-les-Bains has had client data published on the dark web, including more than 100,000 files totalling some 220 GB. The data is said to include information relating to individuals, businesses, institutions, local authorities and even the file of a member of the Cantonal Council.

For SME managers, the self-employed and fiduciary firms, this goes beyond a mere IT incident. It strikes at the heart of the relationship of trust: tax returns, annual accounts, payslips, identity documents, bank details and correspondence with the authorities. When such a wealth of information leaves the confines of the business, the issue is no longer merely technical. It becomes an accounting, legal, organisational and commercial matter.

A trust firm, a tax safe haven turned into a target

According to Le Temps, the digital extortion group BravoX, linked to ransomware attacks, claimed responsibility in early July for the hack of the Vaud-based fiduciary firm. On 18 July, the data was reportedly posted online on an underground website. By the start of this week, the site had already recorded nearly 250 downloads, according to a dark web specialist quoted by the newspaper.

The dark web refers to a part of the internet that is not accessible via standard search engines and requires specific tools to access. It can be used for legitimate purposes, but it is also used to distribute or sell stolen information. For an SME whose documents end up in this type of environment, the damage is not limited to a breach of confidentiality: the information can be reused for attempts at scams, identity theft, CEO fraud, targeted phishing or to put pressure on business partners.

The affected trust company told *Le Temps* that it took action following a connection issue with its server. According to its director, the IT service provider isolated the affected systems, revoked compromised access rights and restored the data from an external backup. The company also states that no communication took place with the perpetrators of the attack and that no ransom was paid.

This account highlights a crucial point for all businesses: backups are not merely an operational detail, but a guarantee of survival. An external backup – tested and isolated from the main system – can make the difference between a controlled recovery and prolonged paralysis. However, it is still necessary to know who triggers the contingency plan, who communicates with customers, who assesses the incident, and which documents must be retained to trace the decisions taken.

The FADP turns data breaches into a matter for senior management

In Switzerland, data protection is no longer merely a matter of best practice. The research report highlights that the Data Protection Act, revised in 2023, requires companies to report serious breaches of personal data. For a trust company, the concept of personal data is particularly broad: a client file may contain a combination of tax information, family circumstances, remuneration, assets, debts, contact details, employment contracts and correspondence with public authorities.

The first instinct should therefore not be to downplay the incident, but to classify it correctly. What data is involved? Does it concern individuals, sole traders, employees of client companies or beneficial owners? Is the data simply inaccessible, or has it been copied and published? The answers determine the reporting obligations, the need to inform those affected and the risk mitigation measures.

An additional framework applies to certain organisations. Since 1 April 2025, operators of critical infrastructure must report cyber-attacks to the Federal Office for Cyber Security within 24 hours of their detection, according to information from the FOCS regarding the Information Security Act and the Cyber Security Ordinance. Not all SMEs are automatically subject to this specific obligation. Whether an organisation qualifies as critical infrastructure must be assessed on a case-by-case basis, taking into account factors such as its business activity, its role in a supply chain or the services it provides to third parties.

For a trust company, even where the obligation to report to the OFCS does not apply directly, the principle remains the same: document quickly, decide quickly, and communicate consistently. In a cyber crisis, the first few hours are crucial not only for limiting the spread of the attack, but also for avoiding communication errors. A letter that is too vague causes concern amongst clients; a letter that is too definitive can become problematic if forensic analysis subsequently reveals a wider scope.

Invoices, salaries, VAT: the domino effect in client files

The distinctive feature of an accountancy firm is that it holds data which, economically and operationally, belongs to others. An SME may have outsourced its accounts, payroll, VAT returns or tax affairs, but it remains vulnerable when the information required for these services is leaked. The risk therefore extends beyond the attacked fiduciary firm itself: it spreads to its clients, their staff, and sometimes to their suppliers and end customers.

In payroll, for example, a file may reveal salaries, personal details or sensitive administrative information. In accounting, invoices and statements can reveal a company’s commercial relationships, its prices, margins, payment difficulties or future plans. In tax matters, annexes and supporting documents can provide a detailed picture of the financial situation of a self-employed person or a company director.

For SMEs that are clients of a fiduciary firm, the practical issue is knowing what data has been entrusted to them, where it is stored and who has access to it. Many companies have a clear service agreement setting out the services provided, but far fewer have a precise understanding of the tools used, access rights, record retention or IT subcontractors. Yet a cyberattack reveals that the chain of trust encompasses accounting software, hosting, remote access, email accounts, backups and internal procedures.

The consequences can also affect cash flow and day-to-day operations. A company that has to replace access credentials, inform staff, respond to concerned customers, verify bank details or urgently strengthen its internal controls ends up spending time and money on these tasks. For a small organisation, these indirect costs can quickly eat into profit margins. They are not always visible in the initial IT invoice, but they manifest themselves in lost hours, administrative delays and a deterioration in customer relations.

The litmus test: access, backups and IT service providers

The available figures show that the situation in Vaud is part of a wider picture. The research report indicates that Switzerland recorded around 65,000 cyber incidents in 2025, of which some 25,000 are thought to have affected SMEs, according to BDO. The same source notes that only 42 per cent of Swiss SMEs consider themselves sufficiently prepared to deal with cyberattacks. PME Magazine, for its part, cites the Cisco Cybersecurity Readiness Index, which states that nearly one in two companies fell victim to a cyberattack in 2024.

These figures should be seen as a management warning. Cybersecurity is no longer a one-off purchase, but an internal control process. For a trust company, it should be treated with the same seriousness as a financial close or a VAT return: clearly defined responsibilities, retained evidence, regular checks and disaster recovery capabilities. For a fiduciary’s client, it is becoming a key criterion when selecting a service provider, on a par with tax expertise or responsiveness.

Without turning every manager into a technical expert, a few simple questions can already help test the robustness of the system:

  • Is access to client files restricted to those who genuinely need it?
  • Is strong authentication enabled for accounting software, emails and remote access?
  • Are backups outsourced, protected against deletion and regularly tested?
  • Does a contingency plan specify who is to contact the IT service provider, clients, the authorities and the insurer?
  • Are staff trained to recognise fraudulent emails and suspicious payment requests?

Treuhand Suisse provides guides and checklists on cyber security for fiduciaries. Tools of this kind are useful as they translate a technical subject into organisational measures: access governance, data classification, backups, awareness-raising and incident management. The expert recommendations mentioned in the research report point in the same direction: contingency plans, regular backups, ongoing training and security audits.

For an SME, the most prudent approach is to map out critical data before a crisis strikes. What information would be most damaging if it were made public? Who holds it? How long is it retained? Which documents are sent by email when a secure portal would be more appropriate? This analysis is no substitute for a specialist audit, but it helps to prioritise and avoid treating all data as if it were equally sensitive.

Trust in a fiduciary is now also demonstrated through cybersecurity

The cyberattack on the Vaud-based trust firm illustrates a shift in standards. Clients no longer simply expect a fiduciary to correctly file a tax return, finalise accounts or prepare payroll. They want to know whether their information is protected, whether an incident would be detected quickly and whether a clear procedure is in place in the event of a data breach.

This expectation also applies to SMEs in their role as employers and business partners. When a company entrusts its payroll or accounts to a service provider, it should incorporate data security into the terms of the engagement: confidentiality clauses, access management, data retention, subcontracting, incident notification and, where applicable, cyber insurance. Measures must be tailored to the size and risk profile of the business, and reviewed by specialists where exposure is significant.

The incident in Vaud is no cause for panic, but rather a call for greater professionalism. Cybersecurity is not merely an IT budget line item: it is a prerequisite for business continuity, compliance and trust. For fiduciaries and their clients alike, the right time to clarify responsibilities, test backups and prepare communications is never the day the files appear on the dark web.