Device infected
If a device is infected with malware, the consequences can be serious: files may be stolen or encrypted, and attackers may be able to operate unnoticed in the background. If you can recognise the signs of malware and know how to respond, you can take targeted steps to limit the damage and protect your data.
Computers, smartphones and tablets are constantly connected to the internet and can therefore be exposed to a wide range of threats. Malware commonly reaches devices through security vulnerabilities, infected email or messaging attachments, and unsafe downloads. Once installed, it can download additional components and give attackers a wide range of ways to compromise the device. Malware can be difficult to detect and may go unnoticed at first. Often, the first sign that something is wrong is unusual behaviour from the device or a warning from security software.
Possible warning signs include a noticeable slowdown in performance, frequent crashes, unexpected pop-ups or browser redirects, and security software being disabled. Unusual data usage or suspicious network activity can also indicate that something is wrong.
If you suspect that your device has been compromised by malware, act quickly and methodically.
If you suspect malware
- Have your device checked by a specialist. Remember to back up your personal files first.
- Disconnect the device from the network by turning off Wi-Fi and mobile data and unplugging the network cable. This will help prevent further data leaks and the malware from spreading.
- The changes that malware makes to a system are often irreversible. If a device is infected, the whole system needs to be reinstalled. Remember to back up your personal files first.
- Back up your data regularly (regular backups).
- Do not log in to online banking, email or other sensitive services if you suspect your device is infected.
- Only change important passwords, such as those for email, online banking and social media, from a device that you know to be uninfected. Enable two-factor authentication wherever possible.
- Install all available security updates for your operating system and applications.
If you suspect ransomware
Ransomware is a type of malware that encrypts files on a computer and on connected network drives, making them unusable. The attackers then demand a ransom to decrypt the files. Common entry points include poorly secured systems and emails with malicious attachments. Do not give in to the attackers' demands. Stay calm and avoid taking any rash action.
- Secure your backups and disconnect them from the network immediately.
- Disconnect all internet connections, including web, email, remote access and VPN connections.
- Report the matter to the police. You can find a police station near you on Suisse ePolice.
- If you lack the necessary expertise, consult an external security service provider.
- Report the incident to the NCSC using the reporting form.
What should you do if data may have been leaked?
If personal or business data has been compromised as a result of the infection, additional steps are necessary:
- Check which data has been affected, such as login details, bank information, and copies of identity documents.
- Inform the relevant organisations immediately, such as your bank or credit card provider.
- Monitor bank transactions and online accounts for suspicious activity
- Report the incident to the police.
- If necessary, report the data breach to the Federal Data Protection and Information Commissioner (FDPIC).
- In the following weeks, be especially cautious of phishing attempts or any signs that your personal details are being misused.
Smartphones and tablets
Smartphones and tablets are just as vulnerable to malware as laptops and desktop computers. Malware can reach these devices through unsafe apps, manipulated links or compromised Wi-Fi connections, for example.
- Uninstall any unknown or suspicious apps.
- Change all important passwords, such as those for your email account, Apple ID, Google account and social media accounts. Only do this from a device that you are sure isn't infected. Enable two-factor authentication wherever possible.
- Update your operating system (iOS or Android) and all installed apps to the latest version.
- In the account settings for your Apple ID or Google Account, check all active sessions and linked devices, and remove any unknown entries.
- Check app permissions and remove access to functions that apps do not need, such as to your camera, location, storage or contacts
- Check whether there are any signs of suspicious activity or unknown access on your linked cloud accounts, such as iCloud or Google Drive.
- If a factory reset cannot be performed on the device itself, a full restore can be carried out via iTunes on a computer for iOS devices.
- If the malware cannot be removed with certainty, a full factory reset is recommended. Back up all important data first.
- If you suspect that your SIM has been swapped (also known as SIM hijacking), contact your mobile provider immediately. Warning signs include a sudden loss of reception, or calls made from your number that you did not make.
Further information
Patchday – regular updates keep you safe
No more ransom – Free decryption tools: https://www.nomoreransom.org.
