External review leaves Swiss espionage and data questions unresolved
Monday 21st September 2026 on 16:15 in
Switzerland
Key questions about suspected espionage and deleted data at Switzerland’s intelligence service remain unanswered, SRF reports, despite an external investigation concluding that the events were “sufficiently clarified”.
The investigation examined events involving the cyber team of the Swiss intelligence service, known as the NDB, over more than a year. Defence Minister Martin Pfister and NDB chief Serge Bavaud presented its findings on Monday.
The investigation found that organisational weaknesses affecting the NDB for years had largely been resolved. The service has established an internal contact point and reorganised itself. The oversight authority for the intelligence service, AB-ND, had already reported more than a year ago that the reorganisation had addressed several problems.
However, the investigation does not make clear whether the most serious allegations were fully examined. The Federal Department of Defence said the events had now been “sufficiently clarified”. Pfister said there were no indications of a Russia affair and that the matter had been properly investigated.
Warnings about possible data transfers
The espionage allegations centre on warnings from foreign intelligence services. According to a classified NDB report from 2021, partner services repeatedly warned Switzerland about “illegal data transfers” and said the former cyber chief had behaved in a compromising manner.
One partner service explicitly warned that classified information could have reached Russian intelligence services through the Russian IT company Kaspersky. The NDB had received these warnings by at least 2020 and included them in its classified report.
It remains unclear whether the new administrative investigation examined the warnings in detail. The report says only that “certain uncertainties” remain concerning the transfer of data.
The Office of the Attorney General of Switzerland is still investigating suspected espionage offences. Bavaud said the NDB no longer works with Kaspersky because the risk had been judged too high. He gave no further details.
Questions over deleted data
The investigation also found no evidence that data had been deleted “on a large scale” in the cyber division, as internal warnings in the NDB’s classified report had suggested.
However, the AB-ND found indications of a possible transfer of information. In a review covering the period from 2022 onwards, the oversight authority said it had found a small number of indications that could point to information having been passed on. It said a detailed and conclusive clarification had not been possible even after analysing the data.
The AB-ND also noted that, as recently as 2024, the cyber division alone was responsible for deleting data. There was no two-person approval principle or regular monitoring, according to the report.
The NDB’s classified report states that data was deleted. Pfister also confirmed on Monday that data had been deleted. But the authorities have not said what data was deleted or who ordered the deletions.