• Main navigation
  • Main content
Swisspost LogoMediablog

Hacker test passed: no critical vulnerabilities found in Swiss Post’s e-voting system

Ethical hackers have spent almost three weeks intensively testing Swiss Post’s e-voting system. Despite significantly higher participation than in 2025, testers did not find any critical vulnerabilities. Nevertheless, six findings by the hackers provided valuable information to help improve the system even further. Swiss Post rewarded the reported findings with a total of around 38,000 francs.

Reading Time 3 minutes
  • Stefan Dauner|Media Spokesman|27.08.2026Reading Time 3 minutes
© Swiss Post

Share on

Angriffe im Dienst der Sicherheit

Attacks in the interest of security

In the summer of 2026, Swiss Post once again subjected its e-voting system to a public intrusion test (PIT). From 6 to 24 July, ethical hackers were able to attack Swiss Post’s system and put the voting process through its paces. They didn’t test the real voting system, but an identical environment in which they could simulate the entire process.

Significantly higher participation and a reward of around 38,000 francs

Participation was significantly higher than in 2025. 5,479 different IP addresses from 107 countries accessed the infrastructure provided for the test. By way of comparison, the 2025 test saw 2,600 IP addresses from 54 countries. This year, Swiss Post registered a total of more than 403,000 accesses. In 2026, Swiss Post added expanded testing options to the public intrusion test, which enabled 20 selected security testers to examine the system in greater detail. Swiss Post pays rewards (known as “bounties”) for confirmed vulnerabilities (“bugs”). In this year’s test, Swiss Post paid out around 38,000 Swiss francs to reward ethical hackers for their findings.

Result: the digital ballot box remains untouched

Swiss Post received and analysed 85 reports and was able to confirm six findings. The findings in the e-voting bug bounty programme and, in turn, in the intrusion test are assigned one of four levels of severity: low, medium, high or critical. The intrusion test resulted in one finding with a severity level of “high” and one with a severity level of “medium”. The other findings are of low severity. The “high” severity finding could have affected the availability of the voting server, but not the security of the votes cast. None of the ethical hackers found critical vulnerabilities in Swiss Post’s e-voting system. The digital ballot box withstood the attacks despite much higher participation. Swiss Post analyses all reports in detail and uses them to make further improvements to the system. For Swiss Post, one thing is clear: transparency and cooperation with the international security community are helping to make e-voting in Switzerland ever more secure.

So arbeitet die Post an sicherem E-Voting

How Swiss Post is working on secure e-voting


Swiss Post developed the e-voting system in Switzerland and is continuing to enhance it here. The company has set up a Competence Center for e-voting and cryptography in Neuchâtel, where a team of experts works daily on codes and algorithms. Public safety tests are an important way for Swiss Post to continuously improve the system. They are prescribed by law to allow e-voting to be used in trial operations. More information on e-voting can be found at the Federal Chancellery and at swisspost-digital.ch. Swiss Post also enables other digital services besides e-voting: for example, digital letters can be sent and received directly with the Post-App.