Skip to main content

Hot topics 2022

3 January 2023

Weekly review 52 – More than 34,000 reports in 2022

03.01.2023 - In the last weekly review of 2022, the NCSC looks back at the more than 34,000 reports received over the past twelve months. We would like to take this opportunity to thank you for all your reports. They help the NCSC to better assess the situation in cyberspace and warn potential new victims more effectively.

27 December 2022

Week 51: Phishing using classified ads – new variant with fake Swiss Post website

27.12.2022 - The number of reports received by the NCSC declined last week. In the days after Christmas, unwanted gifts are often offered for sale on classified ad platforms. However, even when selling an item, people need to be wary of scammers and phishers, as shown by a case reported to the NCSC.

20 December 2022

Week 50: Attacks on app providers via "SMS traffic pumping"

20.12.2022 - Last week, the NCSC received roughly the same number of reports as in the previous week, with 635 in total. One case in particular stood out: attackers attempted to obtain money from app registrations by using "SMS traffic pumping" and foreign phone numbers.

13 December 2022

Week 49: Targeted attacks using leaked data

13.12.2022 - Last week, the NCSC received more reports than in the previous week, with 641 in total. Data leaked during data breaches can be used for targeted phishing or fraud. Therefore, regularly checking your email address for data leaks will help to protect you from unpleasant surprises.

6 December 2022

Week 48: Phone calls from your credit card provider – apparently

06.12.2022 - Last week, the NCSC once again received fewer reports than in the previous week, with 561 in total. Particularly striking were phone calls in which fraudsters attempted to obtain confidential information. In some cases, the caller claims to be an employee of a credit card provider and tries to obtain one-time passwords.

NCSC to become federal office in DDPS

02.12.2022 - Based on the growing significance of cybersecurity and the good work done in recent years to establish the National Cybersecurity Centre (NCSC) in the Federal Department of Finance (FDF), the NCSC is to become a federal office. During its meeting on 2 December 2022, the Federal Council decided that the new federal office will be located in the Federal Department of Defence, Civil Protection and Sport (DDPS). It instructed the DDPS, in collaboration with the FDF, to define the structures of the new federal office by end-March 2023.

2 December 2022

Federal Council submits dispatch on mandatory reporting of cyberattacks on critical infrastructures to Parliament

02.12.2022 - The Federal Council wants to introduce a reporting duty for cyberattacks on critical infrastructures. To this end, during its meeting on 2 December 2022, it adopted the dispatch on amending the Information Security Act and submitted it to Parliament. The proposal creates the legal basis for the reporting obligation for the operators of critical infrastructures and defines the tasks of the National Cybersecurity Centre (NCSC), which is intended to be the central reporting office for cyberattacks.

1 December 2022

Update: Still over 2,000 unsecured Microsoft Exchange servers in Switzerland

01.12.2022 - Just over a fortnight ago, the NCSC called for the security patches provided by Microsoft to be installed in order to fix the ProxyNotShell vulnerability. Despite the urgency, there are still some operators that have failed to heed this call to date. Therefore, the NCSC has sent more than 2,000 registered letters to those concerned, urging them to act now.

29 November 2022

Week 47: Targeted Office 365 phishing with additional function

29.11.2022 - Last week, the NCSC received 647 reports, fewer than in the previous week. A Microsoft Office 365 phishing scam drew particular interest. In the targeted attempt, the phishers not only chose an internet address that looked very similar to the company's actual address, but also used a trick to try to obtain other valuable information in addition to the password.

24 November 2022

Black Friday and Cyber Monday: Don't trust every bargain!

24.11.2022 - Online retailers and online shops advertise fantastic discounts for Black Friday and Cyber Monday at the end of November. But these promotion days are of interest not only to trustworthy merchants. Cybercriminals also exploit them by creating fake shops or sending fake parcel notifications via text message and email.

22 November 2022

Week 46: Unsolicited parcels from fraudsters – as gifts and sometimes also with an invoice

22.11.2022 - Last week, the NCSC received its 30,000th report for this year. Among them was a report concerning several unsolicited parcels that were delivered in what turned out to be an attempted brushing scam. The fraudsters typically pay for the parcels, but the victim in this case did not receive the parcels as a gift, and is now supposed to pay the outstanding invoices.

18 November 2022

Over 2,800 vulnerable Microsoft Exchange servers in Switzerland once again (ProxyNotShell)

18.11.2022 - The NCSC is aware of over 2,800 Microsoft Exchange servers in Switzerland that have a ProxyNotShell critical vulnerability. As these Exchange servers are connected to the internet and accessible from everywhere, it is possible for attackers to exploit the vulnerability remotely and execute code (Remote Code Execution Vulnerability – RCE). Therefore, attackers can exploit the vulnerability to compromise Microsoft Exchange Server.

15 November 2022

Week 45: Phishing emails containing malware and other dubious emails to the NCSC

15.11.2022 - The number of reports received by the NCSC rose sharply compared to the previous week. Once again, threatening emails in the name of the police were the reason. An email sent to the NCSC in Cyrillic script also attempted to distribute the Xloader/Formbook malware.

8 November 2022

Week 44: Increase in hacking with stolen data

08.11.2022 - The number of reports received by the NCSC was once again up slightly on the previous week. In recent weeks, there has been a considerable jump in the number of reports submitted to the NCSC about hacked accounts for a wide range of online services. The damage caused by stolen login credentials can be greatly reduced by using different passwords and a password manager.

3 November 2022

NCSC semi-annual report with focus on cyberspace and armed conflicts

03.11.2022 - The latest semi-annual report of the National Cybersecurity Centre NCSC deals with the most important cyberincidents of the first half of 2022 both in Switzerland and internationally. The focus topic concerns cyberspace and armed conflicts.

3 November 2022

Federal Cybersecurity Delegate represented Switzerland at International Counter Ransomware Initiative Summit in Washington

02.11.2022 - On 31 October and 1 November 2022, the White House brought together 36 countries and the EU for the Second International Counter Ransomware Initiative Summit in Washington. Florian Schütz, the Federal Cybersecurity Delegate, put forward Switzerland's position in the five working groups. He also met with Chris Inglis, the US National Cyber Director, for a bilateral exchange.

1 November 2022

Week 43: One size fits all for fake bank websites too

01.11.2022 - The number of reports received by the NCSC was up on the previous week. Last week, there were reports of an internet address under which several well-known financial institutions were imitated on dynamically generated websites. Such fake bank websites are mainly used for advance-fee fraud, but also for romance scams, like in this case. Also in the case of a phishing website that targeted web administrators, the fraudsters had designed the website dynamically.

27 October 2022

Unprotected .git folders on the internet pose a security risk

27.10.2022 - Git open-source software is often used by software developers for the management and version control of software source code. These version control tools make work easier and are very practical, but too careless and negligent use can pose a security risk and endanger the confidentiality of sensitive data. A look at Swiss websites shows that insufficiently protected .git folders constitute a real risk in Switzerland.

25 October 2022

Week 42: Fake German financial market supervisory authority promises to retrieve funds lost to fraud

25.10.2022 - The number of reports received by the NCSC remained unchanged compared to the previous week. Last week saw an increase in reports of phishing and fraud related to financial services offered by Revolut. Fraudsters also posed as the German financial market supervisory authority and contacted victims of investment fraud, claiming to be able to retrieve their lost assets – for a fee, obviously.

18 October 2022

Bug bounty programme carried out for the Confederation's eIAM central access system

18.10.2022 - Since August 2022, a central bug bounty programme has been available to the entire Federation Administration. This has now been used on productive systems for the first time. The National Cybersecurity Centre (NCSC), the Federal Chancellery's Digital Transformation and ICT Steering (DTI) Sector and the Federal Office of Information Technology, Systems and Telecommunication (FOITT), working together with Bug Bounty Switzerland AG, arranged for the Federal Administration's central access system, eIAM, to be tested for potential vulnerabilities by ethical hackers.

17 October 2022

Week 41: Office 365 and SBB phishing – variations on a theme

17.10.2022 - The number of reports received by the NCSC was higher last week. Several interesting phishing attempts to obtain Office 365 access credentials were reported to the NCSC last week. In one case, an HTML file was attached to the phishing email instead of a phishing link. In another, the fraudulent link was embedded in a QR code. Furthermore, the NCSC also received reports of phishing attempts targeting SBB, in which the phishers tried to steal the SwissPass or SwissID access credentials.

13 October 2022

Include your security contact on your website

13.10.2022 - In case of cybersecurity problems in a company or organisation, it is very important to quickly inform the relevant security contact. Often, however, these contacts are not easy to find on websites, or are not even listed. The "security.txt" standard provides a way to publish the security contact of an organisation or company in a uniform way, thus making it quicker to find.

11 October 2022

Week 40: Web administrators targeted by would-be hackers

11.10.2022 - The number of reports received by the NCSC declined further. In recent weeks, the NCSC has received reports of blackmail messages sent to web administrators. These are fake extortion messages that are similar in style to the well-known fake sextortion emails with empty threats and repeatedly used cryptocurrency addresses.

4 October 2022

Week 39: "Best customer service" maximises damage

04.10.2022 - The number of reports received by the NCSC declined last week. Investment fraud is one of the crimes that causes the greatest losses. There has recently been an increase in reports of fraudsters posing as client advisers and using remote access software to "help" victims to "invest" their money. By allowing this remote access, victims expose themselves to additional risks aside from financial loss.

3 October 2022

S-U-P-E-R.ch - Malware

03.10.2022 - Be wary of an email urging you to open an attachment. It could be a fraudulent message used by criminals to try to install malware on your computer.

27 September 2022

Week 38: Purported security researchers press for rewards

27.09.2022 - The number of reports received by the NCSC declined last week. Phishing emails offering an alleged tax refund began to circulate again. In addition, several reports were received about emails from purported security researchers who claimed to have found vulnerabilities on company websites.

26 September 2022

S-U-P-E-R.ch – Investment Fraud

26.09.2022 - Invest in cryptocurrencies and make a lot of money quickly with little effort. Wouldn't it be nice! Criminals try to get their hands on your money with offers of fake or bad investment opportunities. Not only will you not make any money, but you will also lose the money you invest.

20 September 2022

Week 37: Resurgence of phone calls about apparent parcel deliveries

20.09.2022 - The number of reports received by the NCSC declined last week. Fake threat emails claiming to be from the police still make up the majority of reports. Last week, the name of the NCSC itself was misappropriated as the sender of these emails. There was also a resurgence in phone calls purporting to be from parcel delivery services, which attempted to fool the victims into downloading software in the guise of a parcel delivery notification.

19 September 2022

S-U-P-E-R.ch - Fake-Sextortion

19.09.2022 - «We have pornographic images of you and will publish them unless you pay EUR 1,200.» Do not comply with such requests under any circumstances, as this is a nasty scam called fake sextortion. The blackmailers send such messages on the off-chance of reaching recipients who have visited pornographic websites. In most cases, the recipients are also put under pressure to pay the ransom quickly.

13 September 2022

Week 36: Record number of reports received by the NCSC and fraudsters discover the payment app TWINT

13.09.2022 - Last week, the NCSC received 954 reports, which was the highest number received in a single week since the NCSC was created. This was caused by a large-scale wave of fake extortion attempts launched by fraudsters on Thursday afternoon. By the end of the week, more than 400 reports concerning fake threatening emails supposedly from the police had been processed. In addition, there were many reports about the payment app TWINT. This popular app was not on fraudsters' radars for a long time. In recent weeks, however, the NCSC has received a growing number of reports regarding scams carried out via TWINT. One particularly brazen attempt involves a fake webshop with the sole aim of triggering fraudulent TWINT payments.

12 September 2022

S-U-P-E-R.ch - Phishing

12.09.2022 - «Your financial institution» notifies you that your account is blocked and that you should update your credit card details using the link in the message. Or that you supposedly paid an invoice twice and are now entitled to a refund. All you have to do is click on the link in the message. Do not do this under any circumstances!

8 September 2022

S-U-P-E-R.ch - Fake fees

08.09.2022 - «Your parcel is on its way and will be delivered to you as soon as possible. However, we are still awaiting your payment». This is what your alleged parcel delivery service or the customs authority purportedly tells you by email or text message. You are supposed to confirm your delivery by clicking on the link. Don't!

6 September 2022

Week 35: Phishing risks when using multifunction devices

06.09.2022 - The number of reports received by the NCSC fell slightly again last week. Reports regarding threatening emails allegedly from the police remained the predominant type. Two cases reported to the NCSC last week show how attackers exploit the fact that practically every office today has a multifunction printer with a scan-to-email function.

5 September 2022

Launch of the national cybersecurity awareness campaign

05.09.2022 - Cyberattacks via email and messenger services are on the rise. They can be detected by critically examining messages, thereby making it possible to avoid major financial losses and personal suffering. To promote public awareness, the NCSC and Swiss Crime Prevention SCP, together with the cantonal and city police forces, are launching the S-U-P-E-R.ch national cybersecurity awareness campaign on 5 September 2022.

30 August 2022

Week 34: Beware of invoices from supposed company registers and business directories

30.08.2022 - The number of reports received by the NCSC fell slightly again last week. However, the number of reports received so far this year already exceeds the total number of reports received last year. A case reported to the NCSC in recent weeks is a good example of how important it is to carefully check invoices for company registers, listings and business directories, and also to read the small print.

25 August 2022

Cybermyth: Cybersecurity is complicated

25.08.2022 - Cybersecurity concerns us all. Yet, many are put off by the idea of looking more deeply into hacking, phishing, spam and Trojans, etc., because they think that everything to do with cybersecurity is complicated and time-consuming. This is a long-standing myth: just a few simple security measures and rules of good conduct can prevent many cyber-risks.

23 August 2022

Week 33: How phishers try to bypass spam filters

23.08.2022 - The number of reports received by the NCSC rose sharply last week. As has often been the case recently, this increase was driven by threatening emails sent in the name of the police. Further reports were received about phishing attacks in which the attackers tried to trick the spam filters by inserting irrelevant text content in their emails.

16 August 2022

Week 32: Email bombing disguises hacker attack

16.08.2022 - The number of reports received by the NCSC rose slightly. In a hacker attack against an online shop user's account details, an attempt was made to disguise the attack by email bombing. The new type of phishing attack using QR code bills described in the last weekly review is already being used by phishers on a large scale and in different forms.

11 August 2022

The email avalanche at the end of the holidays and those forgotten passwords

11.08.2022 - After your relaxing summer holiday, it's time to go back to work. There are various login credentials and passwords to be entered, and there is a large backlog of emails in your mailbox. The NCSC provides tips on how to avoid stressing over multiple passwords, plus a warning about being careful when dealing with a full mailbox, as it could also contain fraudulent emails.

9 August 2022

Week 31: New phishing scheme with QR code bill

09.08.2022 - The number of reports received by the NCSC remained unchanged last week. Two new phishing schemes stood out. In the first phishing variant, a link allegedly leads to a personalised online sharing service, where people have to enter the password for their webmail. In the second new variant, a fake QR code bill in the name of Sunrise is sent via email.

3 August 2022

Federal Administration procures platform for bug bounty programmes

03.08.2022 - In order to increase the cybersecurity of the IT infrastructure and reduce cyber-risks effectively and cost-efficiently, the Confederation is procuring up a centralised platform for bug bounty programmes. Under the auspices of the National Cybersecurity Centre (NCSC) and in collaboration with Bug Bounty Switzerland, ethical hackers will search the Federal Administration's IT systems for vulnerabilities.

2 August 2022

Week 30: Smartphone bank targeted by phishers

02.08.2022 - The number of reports submitted to the NCSC rose slightly once again. Users of the smartphone bank WISE were targeted by phishing attempts. There were also more reports of the quality, quantity or type of goods ordered online not being delivered as expected. The NCSC gives tips on how to identify such webshops.

28 July 2022

Recommendations on cybersecurity in the healthcare sector

28.07.2022 - Digitalisation rapidly gained momentum during the COVID-19 pandemic. However, growing digitalisation also means greater cyber-risks, including in the healthcare sector. In response to this, the Swiss Conference of the Cantonal Ministers of Public Health has developed recommendations on data protection and information security, referring to the recommendations on cybersecurity in the healthcare sector defined by the NCSC.

26 July 2022

Week 29: Hacker attacks with stolen login credentials

26.07.2022 - With the summer holidays in full swing, the number of reports received by the NCSC was again low last week. The NCSC received an increased number of reports of attempts to hack into systems using stolen login data; this form of attack is known as "credential stuffing". This can lead to interruptions because legitimate users are also locked out if too many attempts fail.

19 July 2022

Week 28: How cybercriminals cleverly exploit holiday absences

19.07.2022 - In week 28, the number of reports received by the NCSC remained low. Several reports on so-called CEO fraud cases stood out. The attackers have adapted their approach so that only a small number of fake email addresses are used in order to attract less attention. It is likely that the timing of the current wave was chosen because of the upcoming summer holidays. Many tasks are carried out by deputies due to holiday absences and attackers know how to exploit this.

12 July 2022

Retbleed – critical vulnerability discovered in microprocessors

12.07.2022 - Security researchers from the ETH Zürich have discovered a serious security vulnerability in Intel and AMD microprocessors. The vulnerability, called Retbleed, potentially allows an attacker to access any memory area. Initial countermeasures have already been defined. The NCSC has assigned the internationally valid CVE identifiers for the vulnerability of both manufacturers.

11 July 2022

Week 27: Fake email senders and hacked email accounts

12.07.2022 - Beim NCSC war letzte Woche der Meldeeingang nochmals tiefer. Aktuell erwecken Fake-Sextortion-E-Mails den Anschein, vom eignen E-Mail-Account abgesendet worden zu sein. Zugleich verwenden die Betrüger Login-Daten aus einem Datenabfluss und hacken E-Mail- und Social-Media-Konten, um ihrer Forderung Nachdruck zu verleihen. Auch erhielt das NCSC letzten Dienstag die Meldung, dass die Domäne ncscs.ch für eine betrügerische E-Mail missbraucht wurde.

6 July 2022

Fraudulent emails in the name of the NCSC

06.07.2022 - Currently, cybercriminals are sending fraudulent emails in the name of the NCSC. The unknown perpetrators are using a domain name (ncscS.ch) that looks deceptively similar to that of the NCSC (ncsc.ch). Do not reply to these emails!

5 July 2022

Week 26: New phishing variants via telephone and personalised text messages

05.07.2022 - At the NCSC, the number of reports received last week was significantly lower, which is mainly due to the decrease in fake extortion emails. Noticeable were phishing attempts in which no link was sent, but in which a callback was requested, as well as phishing text messages containing a personalised link that can be deactivated after use. The two different approaches show that attackers are willing to invest more time and effort in their phishing campaigns.

1 July 2022

Be mindful of cybersecurity even during your holidays

01.07.2022 -In July, the summer holiday season is just around the corner for many of us. But especially during these weeks, there are many things to bear in mind when it comes to cybersecurity, be it when making bookings, surfing when you are out and about or correct social media conduct. One thing is clear: cybercriminals do not take holidays.

28 June 2022

Week 25: Increase in reports of incidents involving encryption Trojans (ransomware)

28.06.2022 - The NCSC again received a large number of reports last week. Eight reports on encryption Trojans, also known as ransomware, remind us how important it is to take precautions to protect ourselves from such attacks.

23 June 2022

Cybermyth: If I click on a link, it will really take me to the specified website.

23.06.2022 - The internet lives on the use of links. As they enable you to surf from one website to the next, the internet would never have become so successful without them. But not every link leads to the page you expect. This is because any link whatsoever can be placed behind any text on a website.

21 June 2022

Week 24: Personal devices when working from home pose high risks

21.06.2022 - The number of reports received by the NCSC remained at the same high level last week. An incident involving a data leak and ensuing blackmail shows that using private devices to access company networks entails considerable risks.

16 June 2022

Nine practical tips for secure mobile phone use

16.06.2022 - Mobile phones have become our permanent companions. These small, compact devices also contain more and more personal data, such as photos, contacts, emails and text messages. Therefore, the loss or theft of data can quickly result in serious consequences. In general, the same security rules apply as for a PC or notebook, except that a mobile phone's size makes it is easier to steal or lose. The NCSC has compiled nine practical tips to make your mobile phone more secure. The focus is on public WLAN use.

14 June 2022

Week 23: Supposed SBB competition and the importance of quickly applying patches

14.06.2022 - The number of reports received by the NCSC was high again last week. A supposed SBB competition spread very quickly thanks to the snowball system. And one report provided a perfect example of how important it is to apply patches swiftly.

8 June 2022

Week 22: Fake telephone numbers and fake invoices

08.06.2022 - DThe number of reports received by the NCSC was high last week. Aside from the threatening emails supposedly from the police, the NCSC mainly received reports concerning fake telephone numbers. In addition, the NCSC received a tip-off about an invoice manipulation scam that targeted a company's customers.

31 May 2022

Week 21: Cases of investment fraud with large losses

31.05.2022 - The number of reports received by the NCSC remained high last week. This was once again due to threatening emails allegedly from the police. Italian versions of these were also reported at the weekend. In addition, the NCSC received reports concerning various cases of investment fraud, some of which involved substantial losses. In most cases, a little research would have quickly revealed the fraud.

24 May 2022

Week 20: Warning from Microsoft turns out to be a phishing attempt

24.05.2022 - The number of reports received by the NCSC was high last week. The main reason was apparent threat emails from the police. A user of Microsoft Outlook was also «warned», in an email purporting to come from Microsoft, about unusual sign-in activity from Moscow. Closer investigation by the NCSC revealed this to be a phishing attempt. Thanks to the use of a Sender Policy Framework, this message was identified as a phishing email and automatically moved to the spam folder.

18 May 2022

NCSC to become federal office

18.05.2022 - On 18 May 2022, the Federal Council took note of the report on the effectiveness assessment of the "2018-2022 national strategy for the protection of Switzerland against cyber-risks (NCS)" and decided to create a further 25 positions in the area of protection against cyber-risks. He also decided to turn the NCSC into a federal office, and instructed the Federal Department of Finance FDF to prepare proposals by the end of 2022 regarding how the office should be structured and which department it should be part of.

17 May 2022

Week 19: Social media hacking with the help of celebrities and new fake support variants

17.05.2022 - The NCSC again received about the same number of reports last week as the week before. Once more, text messages that attempted to trick victims into installing FluBot malware on their smartphones were observed. Attackers also used a devious method to try to hack into social media accounts. In addition, various variants for recovering allegedly stolen or blocked funds were observed.

16 May 2022

MS Exchange vulnerabilities still not patched

16.05.2022 - The NCSC has sent registered letters to more than 200 companies to notify and warn them once again about vulnerable Microsoft Exchange servers. The security vulnerability was discovered quite some time ago and is being actively exploited by cybercriminals.

12 May 2022

Broad support among businesses and cantons for cyberattack reporting obligation

12.05.2022 - The consultation on the introduction of a reporting obligation for cyberattacks on critical infrastructures has ended. It showed that a reporting obligation is generally welcomed by businesses, the research sector and the cantons. The NCSC will now examine all of the feedback received and finalise the proposal.

10 May 2022

Week 18: Increase in emails claiming computer is infected

10.05.2022 - The NCSC again received about the same number of reports last week as the week before. There was an increase in reports of emails claiming that computers were infected. Interestingly, after a few clicks, the users actually arrive on the websites of well-known antivirus manufacturers. Resourceful operators are behind all this, exploiting the commission offers of well-known providers of antivirus software.

5 May 2022

NCSC semi-annual report with focus on supply chain attacks

05.05.2022 - The NCSC's latest semi-annual report deals with the most important cyberincidents of the second half of 2021 both in Switzerland and internationally. The focus topic concerns attacks on IT product supply chains.

3 May 2022

Week 17: Complete takeover of smartphone due to leaked login credentials from alternative app store

03.05.2022 - The NCSC received about the same number of reports last week as the week before. The investigation of attempted extortion with data from a hacked smartphone revealed that the cyberincident could be traced back to leaked login credentials. The leak in question occurred two years earlier at an alternative app store.

28 April 2022

When warnings from the Confederation are in vain

28.04.2022 - Time and again, targeted federal warnings about specific, acute cyberthreats unfortunately go unheeded. Consequently, companies as well as private individuals expose themselves to unnecessary dangers in cyberspace – often with devastating consequences, as shown by a recent case.

26 April 2022

Week 16: Fraudsters use information from public registers for bogus invoices

26.04.2022 - Last week, the number of reports received by the NCSC was lower than it has been for a long time. This was probably due in large part to many people who make reports being away over the Easter holidays. Among other things, bogus invoices sent to SMEs stood out. In order to make their scams more authentic, the fraudsters also systematically search publicly accessible registers for information.

20 April 2022

Week 15: New variant of fake sextortion emails, with email accounts and social media accounts hacked at the same time

20.04.2022 - The number of reports received by the NCSC last week remained at a similar level to the previous week. Threatening emails supposedly sent by law enforcement agencies remained dominant. Reports of fake sextortion emails accompanied by a hacked webmail or social media account are also on the rise at the moment. This is a new variant.

13 April 2022

Risky competitions – also at Easter

13.04.2022 - Time and again, fraudsters try to lure internet users into traps with supposed competitions. This is currently happening on WhatsApp, with an alleged Easter competition organised by a well-known chocolate manufacturer. Participants are asked to click on a link, which takes them to a fraudulent website.

12 April 2022

Week 14: Notice of alleged copyright infringement leads to takeover of museum's social media account

12.04.2022 - The number of reports received by the NCSC last week remained at a similar level to the previous week. The media officers of a museum responded immediately to an alleged copyright infringement, but the email contained a hidden phishing link that enabled the attackers to take over the account and blackmail the museum.

5 April 2022

Association founded to increase the cyber-resilience of the Swiss financial centre

05.04.2022 - On 5 April 2022, the Swiss Financial Sector Cybersecurity Centre (Swiss FS-CSC) association was founded in Zurich in the presence of Federal Councillor Ueli Maurer. The association aims to strengthen cooperation between financial institutions and authorities in the fight against cyberthreats, and to increase the resilience of the financial sector. The president of the association is August Benz, Deputy CEO of the Swiss Bankers Association.

4 April 2022

Week 13: Phishing attempts on Office 365 accounts prevented by use of multi-factor authentication

05.04.2022 - The number of reports received by the NCSC was stable last week. What stood out were reports of very targeted phishing attempts on Office 365 login credentials. Only with the use of multi-factor authentication could these attacks be blocked.

1 April 2022

Expansion of the NCSC statistics on cyberincidents – subcategories now also included

01.04.2022 - The NCSC collects and classifies the cyberincident reports it receives and publishes these figures on its website on a weekly basis. Due to the growing need for information, the categories have been expanded and the graphics adapted.

29 March 2022

Week 12: FluBot malware is active again in Switzerland and various web administrators receive a threatening email from purported Ukrainian hackers

29.03.2022 - The number of reports received by the NCSC was slightly higher last week. It received reports of text messages again trying to trick victims into installing FluBot malware on their smartphones. In addition, website owners received emails from purported Ukrainian hackers claiming to have hacked their website and demanding a "donation".

29 March 2022

"It is indeed the case that we are not currently seeing an increase in cyberactivities in connection with the Ukraine conflict"

29.03.2022 - Florian Schütz discussed the following questions with Reto Lipp, Olga Feldmeier and Nicola Staub on the SRF Eco Talk show: What role does cyberwar play in the current conflict? How well is Switzerland protected against attacks? And how well are Swiss businesses prepared for the new challenges?

24 March 2022

Cybermyth: If a telephone call displays a Swiss number, the call is from Switzerland and must be trustworthy.

24.03.2022 - Telephone users have become accustomed to the caller's number being displayed with every call. If the number is stored in the address book, the matching name will also appear. However, many do not know that this number can easily be faked.

22 March 2022

Week 11: An interesting attempt at CEO fraud and malware mails for those renewing their visa

22.03.2022 - The number of reports received by the NCSC remained high last week. A sophisticated attempt at CEO fraud failed because of the targeted firm's use of familiar forms of address, and also highlighted the misuse of parked domains. In addition, malware was distributed under the pretext of a visa renewal.

17 March 2022

Use of IT products in the area of cybersecurity

17.03.2022 - The NCSC is currently receiving many enquiries about the use of foreign IT products. Here is a brief summary of the most important information from the NCSC.

15 March 2022

Week 10: Fraudsters who make mistakes yet persevere, and threatening emails sent to doctors' surgeries

15.03.2022 - The number of reports received by the NCSC was again high last week. Fake extortion emails purporting to be in the name of the police were reported last week, mainly by GP and paediatric practices. In addition, a request for quotation attempt was observed again; the aim was to obtain the access credentials for an email account.

14 March 2022

QakBot malware active again

14.03.2022 - At the moment, cybercriminals are once again making increasing use of stolen email conversations to spread malware. This primarily affects companies, where employees who are contacted directly are used as a gateway for ransomware attacks.

10 March 2022

QR codes – uses and risks

10.03.2022 - The use of QR codes (Quick Response) has become more and more common in recent years. In autumn 2022, the QR-bill has replaced the traditional payment slips. But QR codes can also be used to access the digital menu in restaurants, for example, or to easily surf websites or make TWINT payments. What is the reason for this success? Where are the codes used and what risks are associated with using them?

8 March 2022

Weekly review 9: Events in Ukraine are being abused for fraudulent emails

08.03.2022 - The number of reports received by the NCSC fell last week. Fake extortion emails purportedly sent in the name of prosecution authorities are still the most frequently reported. Moreover, events in Ukraine are increasingly being used for fraudulent emails.

3 March 2022

You can report cyberincidents to us easily using the reporting form

03.03.2022 - Have you been sent an email or text message and are unsure whether you can trust it? Or did you accidentally click on a link in it? If so, the NCSC is the right place to contact. The new video briefly explains how the reporting form works and how you can get recommendations and support in the case of cyberincidents.

1 March 2022

Week 8: How fraudsters falsify internet addresses

01.03.2022 - There was a slight drop in the number of reports received last week. The likely reason for this is the adjustment of the spam policy at the NCSC, which led to a significant reduction in spam reports. Furthermore, the internet address of a payment service was laboriously falsified in a small ad scam. The NCSC shows how to recognise fake internet addresses of this kind.

25 February 2022

The NCSC currently records no increase in cyber attacks on Switzerland in conjunction with the Ukraine Conflict

25.02.2021 - Due to the reporting on possible cyber risks in connection with the Ukraine conflict the National Cyber Security Centre publishes an assessment of the cyber situation in Switzerland. Currently, the NCSC does not see any increase of harmful activities in cyberspace that would directly affect Switzerland.

22 February 2022

Week 7: Supposed order confirmation delivers malware and new variants in fake extortion emails

22.02.2022 - Last week, the NCSC received a persistently high number of reports. Hackers are attempting to distribute remote access malware by means of bogus order notifications. In addition, there has been an increase in the spread of fake extortion emails being sent in the name of prosecution authorities, and they are now written in German as well.

16 February 2022

High time to fix the security vulnerabilities in Microsoft Exchange Servers

16.02.2022 - The NCSC strongly urges businesses and communes to install the security patches for Microsoft Exchange Servers. The security vulnerabilities in Microsoft Exchange Servers, which have been known for a long time, are being actively exploited by cybercriminals to install encryption Trojans, for example.

15 February 2022

Week 6: Phone calls about apparent package deliveries, and misuse of hacked Facebook accounts

15.02.2022 - The NCSC received a large number of reports last week. Once again, SMEs are receiving phone calls about apparent package deliveries and are being pressured into opening emails containing malware. Hacked Facebook accounts are also being misused for investment fraud. And the fake extortion emails, apparently sent on behalf of the prosecution authorities, are now cropping up in German too.

9 February 2022

Some rose purchases come with thorns attached

09.02.2022 - Just a few days after the annual international Safer Internet Day on 8 February, lovers will be celebrating Valentine's Day. However, 14 February is also a red letter day for cybercriminals, and their intentions are rather less romantic. It is therefore worth remembering over the next few days that some rose purchases come with thorns attached!

8 February 2022

Week 5: When the first Google hit is not the right one and a freephone number turns into a scam

08.02.2022 - The NCSC received a large number of reports last week. Reports of fake extortion letters purportedly sent in the name of prosecution authorities still dominate. Two reports serve as examples of why it is always advisable to check very carefully whether you are on the right website. In addition, fake support fraudsters tried to make themselves appear serious by using a freephone number.

1 February 2022

Week 4: Security vulnerability in QNAP NAS devices and new phishing variant

01.02.2022 - Despite the decrease in reports of fake extortion emails, the number of reports received by the NCSC last week remained stable at a high level. The NCSC was particularly occupied with the zero-day vulnerability currently being exploited on QNAP NAS devices. Attention was also focused on a phishing email with a special attachment.

25 January 2022

Week 3: Targeted phishing, targeted CEO fraud and NASA giveaway

25.01.2022 - The number of reports received by the NCSC remained high last week. Fake extortion emails supposedly in the name of prosecution authorities dominated again, accounting for almost 35% of the reports. In addition, the NCSC received reports of phishing emails which at first glance appeared to have been sent in a very targeted manner. CEO fraud is increasingly personalised and a giveaway promotion purportedly from NASA promised that amounts paid in would be instantly doubled.

20 January 2022

Emails with malicious Office documents on the rise again

20.01.2022 - The use of emails with malicious Microsoft Office documents to spread malware is on the rise again. Once a computer has been infected, fraudsters have undetected access to the entire network. Help fight such cyberattacks and report suspicious emails to the NCSC at antiphishing.ch.

18 January 2022

Week 2: Ransomware and phishing websites in the online gaming scene

18.01.2022 - With 881 reports, the NCSC recorded the highest number of reports in its history in the second week of 2022. The main reason was fake extortion emails in the name of prosecution authorities, which accounted for almost 40% of the reports. In addition, ransomware attacks continue to be a hot topic and an interesting case led the NCSC to the online gaming scene, where account data is being stolen via a phishing website.

12 January 2022

Initiation of consultation on introduction of cyberattack reporting obligation

12.01.2022 - The Federal Council today initiated the consultation on the proposed introduction of a reporting obligation for cyberattacks on critical infrastructures. The proposal creates the legal basis for the reporting obligation and defines the tasks of the National Cybersecurity Centre (NCSC), which is intended to be the central reporting office for cyberattacks. The consultation will last until 14 April 2022.

11 January 2022

Week 1: Bogus hospital website and proposal of hacking services

11.01.2022 - The NCSC kicked off the first week of 2022 with an increased number of reports. Many cases of fake extortion in the name of police organisations again appeared among the reports. A bogus website for an actual hospital also attracted attention, and hackers offered their services via spam emails.