Current Incidents

Update on the SwissNovaChat notice
The NCSC is currently receiving numerous reports regarding invoices related to an alleged service provided by Swissnovachat, which are being collected through a debt collection agency (Letterdata). BACS recommends that individuals who have not used this service dispute the claim in writing and carefully retain all correspondence in case the claim is pursued further.

Increase in compromised websites with fake CAPTCHAs
The NCSC is currently seeing an increase in compromised websites that use fake CAPTCHAs to trick people into running malicious commands and infecting their computers with malware. More than 100,000 websites worldwide are affected. The NCSC is also seeing an increase in the number of Swiss websites being compromised by cybercriminals and used to distribute malware.

Phishing targeting crypto wallets: Letters with a QR code are currently in circulation
The NCSC has received several reports of letters containing a QR code and prompting recipients to download an urgent update for various crypto wallets. However, after scanning the QR code, recipients are redirected to a phishing website where they are asked to enter their recovery phrases. If these are disclosed, attackers can gain complete control over the crypto wallet in question and steal the assets it contains. Never disclose passwords or recovery phrases to third parties.

Warning regarding SwissNovaChat / SwissNovaCare
The NCSC is currently receiving numerous reports regarding the websites swissnovachat.ch and swissnovacare.com. There may be other similar websites. These are operated by entities whose business model involves sending invoices even though no subscription exists. The legal notice lists “Margot Brands Ltd” from Hong Kong. Ignore such messages, do not click on any links they contain, and do not make any payments.

Phishing emails regarding the E-Vignette
The NCSC receives currently reports of emails claiming that the E-Vignette has been deactivated due to a billing issue. The email links to a phishing site. The email lists the general NCSC email address. This email has not been sent by the NCSC. Please ignore it and delete it.

Blackmail emails in circulation
The NCSC is currently receiving reports of emails in which blackmailers claim to be in possession of credit card details, driving licence details, social security numbers and other data. They threaten to sell this information on the dark web. The emails often appear to come from the recipient's own address. However, this is not the case. The sender address is fake. The email is a bluff. Ignore it and do not be intimidated.