Skip to main content

Published on 24 August 2026

Semi-Annual Report 2026/1

In this semi-annual report, the National Cyber Security Centre (NCSC) presents the relevant incidents and developments relating to cyberthreats in Switzerland and internationally. During the first half of 2026, the NCSC received 27,128 voluntary reports and 200 notifications of cyberincidents that were subject to mandatory reporting. Thus, the number of reports has stabilised at a high level. Fraud continues to dominate the statistics as a lucrative mass-market business, with telephone-based scams – such as voice phishing – having become particularly established methods. By using classifieds platforms, search engine listings and even data breaches as points of contact, cybercriminals are luring their victims using personalised, emotionally manipulative and, in some cases, technologically very sophisticated methods. Attackers are now systematically using artificial intelligence (AI) to deliver tailored, personalised and credible content to their victims.

Cyberincidents at Swiss companies

While there were no major CEO fraud campaigns targeting schools, local authorities or churches, the NCSC recorded an increase in reports of Microsoft 365 phishing, in which attackers take over victims’ business email accounts to use them for further phishing or fraudulent activities. Particularly striking were cases where attackers impersonated IT helpdesks or senior managers, deliberately manipulating staff in order to compromise systems or directly initiate financial transactions. During the reporting period, pending security updates were increasingly used as a pretext to distribute malware. Several popular open-source projects were also compromised, enabling widespread distribution of software designed to steal login credentials. Finally, the number of reported and observed Swiss ransomware cases remained stable, with 79 recorded during this reporting period. However, there is evidence that active ransomware families are becoming increasingly diversified and fragmented.

Cyber resilience in an increasingly politicised, international environment

Cybersabotage has emerged as a viable and often overt activity for single states to launch attacks during international conflicts and within broader spheres of political influence. Although there have been no targeted cybersabotage attacks against critical infrastructure in Switzerland to date, the level of risk may change depending on the geopolitical situation. Given Switzerland’s close ties with other Western value communities and its economic and political interdependence, Swiss organisations must prepare to maintain their resilience even in the face of increasingly hostile cyberthreats. This is illustrated through a case study on an incident in Poland.

The dream job playbook

Jobseekers were the focus of attention in various ways during the reporting period. In addition to large-scale campaigns involving typical fraud schemes, attackers also targeted Swiss individuals and companies, stealing cryptocurrency through fake job application processes. Posing as headhunters, attackers contact their victims on LinkedIn and offer them supposed dream jobs or investment opportunities. As well as using advanced social engineering techniques, attackers employ sophisticated methods to compromise devices, gain access to sensitive login details and steal millions in cryptocurrency from victims and their employers.

Your opinion matters to us!

We would like to know your opinion on the content of the current semi-annual report, so that we can better adapt such products to your needs in the future. Therefore, we would be grateful if you could reply to the following questions (about 2 minutes). You can then send us the form by clicking on the “Submit” button.

The questionnaire is anonymous and personal information such as your age or profession are only aimed to understand the needs of each target audience. But you can leave your email address should you have any questions or comments which you would like us to follow up upon. We are looking forward to reading your thoughts and comments.