Skip to main content

Hot topics 2023

3 January 2024

Week 52: More than 50,000 reports in 2023

03.01.2024 - As is tradition, the NCSC looks back at the reports received over the past twelve months in the last weekly review of the year. Fake threatening emails and phone calls claiming to be from the police were the main features of 2023. These two phenomena alone accounted for over a third of the reports received. You can find out which other cyberthreats made an impact over the past twelve months in the last weekly review of the year. We would like to take this opportunity to thank you for all of your input and reports, which help the NCSC to better assess the situation in cyberspace and warn potential new victims at an early stage.

27 December 2023

Week 51: How fraudsters attempt to trick the NCSC and other security service providers

27.12.2023 - The NCSC receives numerous reports concerning fraudulent web content, various phishing schemes and dubious advertising websites every day. However, when it checks the reported websites, perfectly normal, innocuous-looking websites are sometimes displayed. In these cases, it is worth persevering rather than believing that those who submitted the reports made a mistake or that the website has already been taken down by the provider. In many cases, closer analysis reveals that fraudsters use various techniques to avoid detection by security authorities for as long as possible.

19 December 2023

Week 50: Malware instead of a new job

19.12.2023 - Fraudulent job advertisements are all too common – most of them are designed to swindle victims out of money under false pretences. One advertisement in particular stood out because the fraudsters did not follow the usual pattern, and instead attempted to plant malware during a job interview in order to subsequently take over the victim's cryptocurrency wallet.

12 December 2023

Week 49: Use of artificial intelligence in fraud attempts

12.12.2023 - The NCSC is observing an increase in the use of so-called artificial intelligence (AI) in phishing and fraud attempts. Below, we look at three examples of how AI is already being used in this way.

5 December 2023

Week 48: motorway tax e-sticker with a service fee

05.12.2023 - Over the past few days, the NCSC has received reports about websites selling motorway tax stickers for more than CHF 40. What at first sight appears to be a fake website is actually using a technique that is already familiar to the NCSC from other contexts. Companies focus mainly on electronic services that can be directly obtained from the relevant government sites. These are then sold on for a fee.

29 November 2023

Federal Council adopts postulate report on increasing ethical hacking

29.11.2023 - During its meeting on 29 November 2023, the Federal Council adopted the report in response to postulate 20.4594 "Institutionalise ethical hacking and increase cybersecurity". The postulate requested the Federal Council to set out how ethical hacking can be institutionalised as a basis for increasing cybersecurity, and how it can be promoted within the Federal Administration and at enterprises affiliated with the Confederation.

28 November 2023

Week 47: Cybercriminals target hotels

28.11.2023 - Cybercriminals are trying new ways to trick hotels and their guests. In the emails currently being sent to hotels, they claim to have been bitten by bedbugs or that they were filmed in the hotel room and are now being blackmailed, among other things. The aim is to trick hotel employees into installing malware.

21 November 2023

Week 46: Phishing involving a purported tax refund and crypto wallet phishing

21.11.2023 - A number of phishing cases were also reported to the NCSC last week. Fraudsters continue to target customers of parcel, telephony and transport service providers very frequently. This weekly review presents two less common phishing scams.

14 November 2023

Federal Administration also impacted by Concevis hack

14.11.2023 - The software company Concevis has fallen victim to a ransomware attack, causing all of its servers to be encrypted. As far as is currently known, the stolen data is believed to include older operational data from the Federal Administration. In-depth analyses are still ongoing.

13 November 2023

Week 45: Don't trust every message you get from a contact

14.11.2023 - The NCSC is once again observing a rise in reports on the following phenomenon: one of your contacts gets in touch via WhatsApp and asks you for help with an urgent problem. All you have to do is forward a code. At first glance, everything seems fine, but unfortunately the forwarding causes your WhatsApp account to be blocked. How does that happen, and what can you do to prevent it?

7 November 2023

Week 44: "Hello, this is your bank's security division"

07.11.2023 - The NCSC has recently been receiving regular reports of telephone calls from supposed bank employees claiming to work in the security division. The callers maintain that they want to stop a fraudulent payment. The telephone number displayed corresponds to the bank's official number. This is faked/spoofed by the fraudsters to appear credible.

2 November 2023

NCSC semi-annual report focuses on hacktivism

02.11.2023 - The National Cyber Security Centre (NCSC) today published its latest semi-annual report. This looks at the main cyberincidents that occurred in Switzerland and abroad in the first half of 2023, with a special focus on hacktivism.

31 October 2023

Week 43: Company-like structures among fake support scammers

31.10.2023 - Threatening calls claiming to be from the authorities have been one of the phenomena most frequently reported to the NCSC since July 2023, and the surge in reports received by the NCSC is attributable primarily to them. As the calls are made during office hours, it can be assumed that the fraudsters are organised like a company.

26 October 2023

European Cybersecurity Month (ESCM): Tips for senior citizens

26.10.2023 - Senior citizens appreciate the opportunities offered by digital tools. They use the internet in their daily lives, which enables them to carry out errands from the comfort of their own homes, especially if they have limited mobility. However, they are often insufficiently aware of the risks. Cybercriminals take advantage of this and use social engineering. Known methods of attack against senior citizens include pretending to be from the police (fake police officers), shock calls and computer support.

24 October 2023

Week 42: Dynamite phishing – DarkGate follows Emotet and Qakbot

24.10.2023 - After a short respite, the NCSC has again received several reports of malicious emails in the last two weeks that use old emails to trick the recipients into believing that they had already been in contact with each other. Since both the email sender and the old message seem familiar to the victim, the likelihood increases that the victim will click on the link and malware, in this case DarkGate, will be installed on the device. DarkGate is a downloader with advanced functions and also a door opener for ransomware.

17 October 2023

Week 41: How trade fair information can be misused by fraudsters

17.10.2023 - Autumn is also trade fair season. In order to optimise trade fair planning for visitors, many organisers provide information about exhibitors and their products online. Such information is helpful for visitors, but it can also be misused by fraudsters, as illustrated by an example reported to the NCSC.

12 October 2023

European Cybersecurity Month (ESCM): Tips for working people

12.10.2023 - The term "hacker" is often used in connection with cyberattacks. It is easy to have the impression that attackers primarily penetrate companies' IT systems through technical vulnerabilities – but this impression is misleading. In many cases, malware enters a company's system through its own employees because they have become victims of social engineering. For this reason, it is important that employees know the attack methods involved in social engineering and how they should behave in the event of an attack. Companies therefore sometimes use professional social engineers to raise employee awareness.

10 October 2023

Week 40: Social engineering in the gaming community

10.10.2023 - Last week, a special case of social engineering was reported to the NCSC: in the video game community, a gamer was tricked into downloading a game that eventually turned out to be malware.

6 October 2023

European Cybersecurity Month (ESCM): Tips for young people

06.10.2023 - For children and young people, the so-called digital natives, surfing the internet is a normal part of their daily lives. The internet opens doors for them that previous generations never even dared to dream of – but the internet also harbours dangers. Young people in particular are often more trusting than adults. This can make them easy targets for criminals, who exploit this trust for their own personal gain through social engineering.

3 October 2023

Week 39: The various types of fake sextortion

03.10.2023 - The big waves of fake sextortion have been easing off for a few months now, which seems to indicate that the phenomenon is no longer so lucrative for the scammers. The approach has been repeatedly adapted in the past in order to nevertheless find victims willing to pay among those who received the emails. With the latest version, it is no longer possible to rule out the possibility that malware has actually infected the computer. The attackers present a recent screenshot of the victim's computer as proof.

2 October 2023

Launch of the European Cybersecurity Month devoted to social engineering

02.10.2023 - The European Cybersecurity Month (ECSM) campaign is taking place in October. The annual Europe-wide initiative is organised by the European Union Agency for Cybersecurity (ENISA), together with the EU member states, and this year is dedicated to the topic of social engineering. As a cooperation partner of ENISA, the NCSC is taking an active role in the campaign. In order to raise awareness of social engineering among the general public, the NCSC has worked with various organisations to develop targeted content for young people, working people and senior citizens. The partner networks distribute all campaign material across Switzerland.

26 September 2023

Week 38: When the customer is not king, but actually a hacker

26.09.2023 - A key element for every company is customer relations. The customer is king, so they say. As a result, companies are keen to fulfil their customers' every wish. This approach is regularly exploited by hackers. A particularly sophisticated case was reported to the NCSC last week. Every company should therefore consider what company data it publishes on its website, as this can be used for fraud, but also for phishing.

18 September 2023

Week 37: Many roads lead to fake support

19.09.2023 - In recent months, cybercriminals have come up with a variety of fake support scams that are aimed at installing a remote access tool on the victim's computer and then making credit card payments or e-banking transactions.

18 September 2023

S-U-P-E-R.ch – How to properly delete data that is no longer needed

18.09.2023 - Backing up data is not the only important thing. If information is no longer required, it should be properly deleted or destroyed. However, «deleting» is not the same as «permanently deleting». Deleting data is generally a multi-stage process, as electronic data is not completely removed when it is deleted with the delete key or the delete function. To delete data permanently, the storage location of the information must be repeatedly overwritten.

12 September 2023

Week 36: New variants of fake threatening emails from authorities in circulation

12.09.2023 - For the past two years, threatening emails purporting to come from the police or other authorities have been among the most reported cases at the NCSC. After using similar content for a long time, the attackers are now using a new variant to try and unsettle the recipients with allegations of tax evasion.

7 September 2023

S-U-P-E-R.ch – What to bear in mind when backing up data

07.09.2023 - Much of the data that is important to us, such as photos, appointments or contacts, is now stored on our smartphones, tablets or computers. But what happens if your smartphone is lost, your computer is attacked or your tablet develops a technical defect? All of the data is lost in a split second. Unless you have a backup. At times like these, it becomes all too clear just how important it is to back up your data regularly.

5 September 2023

Week 35: Fake job offers 2.0

05.09.2023 - Fake job offers have already been reported on in previous NCSC weekly reviews. New variants have emerged in recent weeks. In contrast to previous approaches, payments do not have to be made before starting work, but only once the victim has started work.

31 August 2023

Security authorities launch national awareness campaign on backing up data

31.08.2023 - Regularly backing up data is very important and makes a significant contribution to cybersecurity. If you can rely on a backup of your data, you have a safety net should it be encrypted and blackmailed by cybercriminals or if you lose your device. In September, the NCSC, Swiss Crime Prevention (SCP) and the cantonal and city police forces will launch a national awareness campaign on the importance of backing up data. The campaign is supported by the internet security platform iBarry and "eBanking – but secure!" (EBAS).

29 August 2023

Week 34: When attackers try to determine the behaviour of email recipients

29.08.2023 - Fraudsters use various methods to optimise their spam lists. Last week, the NCSC discovered scam emails that exploit the read receipt function. In these cases, if the recipients confirm that they have opened and read the email, they receive further scam emails that increase the pressure and urge them to pay.

22 August 2023

Week 33: Office365 phishing with valid website certificates

22.08.2023 - Phishing attacks on Office365 are increasingly in the form of man-in-the-middle attacks, with the attacker slipping in unnoticed between two parties involved in an exchange. In this way, content can be changed in a network connection that is actually protected. What is so perfidious is that the current variants of these attacks are almost undetectable, as the attackers' valid certificates are displayed in the browser.

15 August 2023

Week 32: WhatsApp hacking via voicemail

15.08.2023 - Cybercriminals are still targeting WhatsApp accounts. Attackers are pulling out all the stops to obtain the PIN code for resetting an account and they particularly appreciate having the code read out over the phone. If this is done at night, the code usually ends up being sent to voicemail, which is then hacked to obtain the information. The NCSC is currently receiving a lot of reports of hacked WhatsApp accounts.

10 August 2023

Holiday time: what to watch out for when you return home

10.08.2023 - After you have enjoyed your summer holidays, it is important to take care of your cybersecurity too when you return home.

8 August 2023

Week 31: Identifying fraudulent webshops early on

08.08.2023 - Buying online from unknown webshops is always a risk. The goods paid for in advance may not arrive at all, or the buyer may receive something of inferior quality. If the shop which is supposedly located in Switzerland turns out to be located in Asia, the legal options are soon exhausted. Last week, the NCSC was notified of several fake shops that could have been recognised with a little prior knowledge.

31 July 2023

Week 30: Online fraud with little technical knowledge and a lot of perseverance

31.07.2023 - The NCSC receives many reports concerning typical fraud patterns where IT is used only as a means of committing the crime. Unfortunately, this means that it is also possible for fraudsters with minimal IT skills to launch attacks via the internet. Two typical methods are presented here: advance-fee fraud and requests for financial help from "acquaintances".

27 July 2023

Holiday season: be mindful of cybersecurity even while travelling

27.07.2023 - While you are enjoying your summer holidays and travelling, it is important that you also keep on top of your cybersecurity. Protecting your personal data and avoiding online threats should also be a priority during your trip.

25 July 2023

Week 29: Music festival season – a festival for online ticket scammers

25.07.2023 - The fraudulent trade in tickets for festivals and concerts thrives during the summer season. Cybercriminals take advantage of the fact that many people spontaneously decide to attend an event and are looking for a ticket, or that ticket holders cannot use their ticket and want to sell it. From the mass of reports received, the following are two examples of a fraudulent sale and a fraudulent purchase of festival tickets. In addition, the NCSC received more than 1,000 reports for the first time last week, despite it being the holiday season. This flood of reports was due to a wave of fraudulent telephone calls in which the English-speaking callers pretended to be customs or police authorities and asked for personal information.

18 July 2023

Week 28: TWINT – isolated cases of phishing and fraud

18.07.2023 - The uncomplicated payment service TWINT is also attractive for fraudsters. No fewer than three different approaches using TWINT with criminal intent were reported to the NCSC last week. In addition to phishing attempts that pretend to be from TWINT, there are also fraudulent classified ad offers.

13 July 2023

Holiday season: what you should consider before you leave home

13.07.2023 - The summer holidays are upon us, and holiday time often means travel time. In an increasingly connected world, where various mobile devices such as mobile phones, laptops and tablets also travel with you, it is important to protect yourself from the dangers present in cyberspace. This is particularly the case when travelling abroad.

11 July 2023

Week 27: Online investment fraud – serious money at stake

11.07.2023 - Online investment fraud starts out benignly. Together with a likeable person, the aim is to explore the world of cryptocurrency with an investment of just USD 250. The victims are soon asked to invest more, and thus the damage keeps increasing. This is illustrated by five similar-sounding incidents reported to the NCSC, in which the scammers stole a combined total of over USD 220,000.

4 July 2023

Week 26: Right website, wrong hotline number

04.07.2023 - When holiday season rolls around, the fraudsters are never far behind. They use special tricks to get to their victims' holiday funds. Sometimes these tricks are hard to spot, as illustrated by a case reported to the NCSC last week. Even when you are relaxing on holiday, it is still good to have your wits about you, and to be suspicious too often rather than not often enough.

29 June 2023

Government District Open Days – the NCSC awaits you

29.06.2023 - The Federal Constitution is celebrating its 175th anniversary and to mark the occasion, the federal government in Bern is opening its doors on 1 and 2 July 2023. The National Cybersecurity Centre (NCSC) is looking forward to welcoming visitors to the Open Federal Mile at its outdoor stand near the Federal Palace East Wing, and to exchanging ideas and information on cybersecurity.

28 June 2023

Xplain hack: Federal Council commissions a policy strategy crisis team on data leaks

28.06.2023 - During its meeting on 28 June 2023, the Federal Council commissioned a policy strategy crisis team on data leaks. The aim of the cross-departmental crisis team is to coordinate the ongoing efforts to deal with the ransomware attack on Xplain, which has also affected Federal Administration data, and to propose related measures. In addition, the Federal Council ordered that a mandate be drawn up for an administrative investigation. Moreover, it decided to review existing contracts with federal IT service providers and to amend them where necessary in order to improve service providers' cybersecurity and allow the federal government to react swiftly in the event of a successful attack. Finally, it ordered an examination of measures to ensure that the essential services currently provided by Xplain for the police and the security and migration authorities can be guaranteed in any case.

27 June 2023

Week 25: Spotting phishing is becoming increasingly difficult

27.06.2023 - The NCSC received 985 reports last week, the highest number in its history. This was due to a wave of fake threatening emails claiming to be from the police, as well as numerous reports concerning various phishing emails. Two phishing attempts reported to the NCSC last week indicate that phishers are putting more and more effort into creating accurate phishing pages. Just minor errors indicate the malicious nature of the phishing emails and the websites referred to.

20 June 2023

Week 24: The QakBot malware is still active – and has some new tricks up its sleeve

20.06.2023 - The QakBot malware is still active. With Microsoft severely restricting macro functions for documents obtained from the internet last year, the attackers are now trying other methods to trick their victims into clicking on an infected file and installing the malware.

14 June 2023

Xplain hack: initial findings from data analyses indicate need for action

14.06.2023 - Following the discovery of the ransomware attack on Xplain, intensive investigations concerning the data affected have been under way in the Federal Administration. The data analysed to date also includes operational data from various authorities and organisations. How this data got onto the Xplain infrastructure is now being meticulously clarified.

13 June 2023

Week 23: How a phishing attempt turns into a subscription scam

13.06.2023 - Every week, the NCSC receives countless reports concerning bogus parcel notifications, claiming that a parcel is being held by Customs and cannot be released until a fee is paid. But what is behind these? Contrary to initial suspicions, phishing sites are not involved. Instead, shady schemers would like to mislead the victims into unknowingly taking out a paid subscription.

12 June 2023

DDoS attack on Federal Administration: various Federal Administration websites and applications unavailable

12.06.2023 - Several Federal Administration websites are/were inaccessible on Monday 12 June 2023, due to a DDoS attack on its systems. The Federal Administration's specialists quickly noticed the attack and are taking measures to restore accessibility to the websites and applications as quickly as possible.

8 June 2023

Federal Administration also impacted by Xplain hack

08.06.2023 - Based on the information currently available, it appears that operational data of the Federal Administration could also be affected by the ransomware attack on the IT company Xplain, which resulted in some of the stolen data being published on the darknet. In-depth analyses are still ongoing.

6 June 2023

Week 22: Smishing gives way to vishing

06.06.2023 - An interesting combination of a phishing text message and subsequent voice phishing was reported to the NCSC last week. After entering his credit card details on a website opened via a phishing text message, effective security measures enabled the victim to stop his payment to the phishers. When the phishers noticed this, they called the victim and offered telephone support.

2 June 2023

Critical vulnerability in file transfer software «MOVEit»: Apply Patch quickly

02.06.2023 - The file transfer software called «MOVEit», which is mainly used by businesses, has a critical vulnerability that is already being exploited by cybercriminals. The attackers are exploiting the vulnerability to steal files from the file transfer software. The NCSC started to receive corresponding reports from organisations in Switzerland on 1 June. The NCSC recommends applying the security patch as quickly as possible.

30 May 2023

Week 21: Hacked Linux servers as a money mules

30.05.2023 - When we hear about systems being hacked, few of us would think that the cybercriminals were interested in the system's resources rather than the data stored in it. It is well known that cybercriminals often take systems over and use them to carry out computing operations for crypto-mining purposes. A case reported to the NCSC revealed another method which cybercriminals are using to try and make money with hacked systems.

25 May 2023

S-U-P-E-R.ch – Double up on securing your access

25.05.2023 - 2-factor or multi-factor authentication (2FA or MFA) is a security mechanism that requires users to provide two or more forms of identification in order to access a system or application.

24 May 2023

Manuel Suter appointed Deputy Director of National Cyber Security Centre (NCSC)

22.12.2023 - The head of the DDPS, Federal Councillor Viola Amherd, has appointed Manuel Suter as Deputy Director of the NCSC as of 1 January 2024. The Federal Council was informed of the appointment at its meeting on 22 December.

23 May 2023

Week 20: Oops! – Phishing email addressed to the wrong person

23.05.2023 - Phishers are constantly trying new ways to trick victims into providing their access details. In doing so, they also do not shy away from telling the victim that intimate pictures have supposedly been published. However, things do not always go according to plan, as a second example reported to the NCSC last week demonstrates.

22 May 2023

Ransomware gangs are still very active in Switzerland

22.05.2023 - In recent weeks, there have been more reports in the media about ransomware attacks against Swiss companies in which company data was stolen and encrypted. In the process, data from the affected companies was also published on the dark web. Implementing basic protection measures can do a lot to improve cybersecurity. Therefore, the NCSC is once again highlighting the best practices regarding cyberthreats from ransomware. These have been in place for many years and we urge companies to rigorously enforce them. This is because various ransomware gangs are very active and are attacking companies in Switzerland.

16 May 2023

Week 19: SIM swapping – how a SIM card can be stolen online

16.05.2023 - Access to many applications and digital services is now protected with two-factor authentication. Smartphones are playing an increasingly important role in this. They are not only used to run applications and services, they are also often used to generate the second factor, be it through a one-time password generator or by receiving a text message. Therefore, cybercriminals are also increasingly trying to gain access to these devices in order to obtain all the required factors. In a recent report to the NCSC, the attackers used a technique called SIM swapping to do this.

15 May 2023

S-U-P-E-R.ch - Be sure to manage your passwords securely

15.05.2023 - The issue of password security can be a nuisance, as you have to create complex passwords and remember them. In addition, you are supposed to use a different password for every online account and can lose track of them.

11 May 2023

NCSC semi-annual report focuses on cybersecurity in SMEs

11.05.2023 - The NCSC's second semi-annual report deals with the most important cyberincidents of the second half of 2022 in Switzerland and internationally. It focuses on the most important issues surrounding cybersecurity in SMEs.

9 May 2023

Week 18: A wolf in sheep's clothing or an incident involving a malicious software update

09.05.2023 - Software updates are an integral part of computer security. However, cybercriminals also exploit this to install malware, as shown by an example reported to the NCSC last week. To convince victims to click on the link, the attackers also used information taken from leaked data.

4 May 2023

S-U-P-E-R.ch - Create secure passwords

04.05.2023 - Strong passwords are important, as they protect against unauthorised access to personal and sensitive data. Weak passwords can easily be guessed or hacked, thereby posing the risk of identity theft, fraud and other types of cybercrime.

2 May 2023

Week 17: Advertisement using a deepfake video for a giveaway scam

02.05.2023 - Was Elon Musk really giving away cryptocurrency, as a report last week to the NCSC indicated? No, he wasn't. In this case, fraudsters used a deepfake video and the launch of the Starship space vehicle to make their story seem credible. In the video in question, Elon Musk promised to double every cryptocurrency payment made to him and return it to the sender.

1 May 2023

Launch of the national cybersecurity awareness campaign

01.05.2023 - Stolen user data is often at the origin of a cyberattack. Strong passwords can prevent considerable damage. The National Cybersecurity Centre (NCSC), Swiss Crime Prevention (SCP) and the cantonal and city police forces, with the support of the internet security platform iBarry and "eBanking – but secure!" (EBAS), will be conducting a national awareness campaign on password security in May.

25 April 2023

Week 16: Bug or feature – secure use of apps and social media

25.04.2022 - Every additional app poses a potential security risk. So any apps that you are no longer using should be deleted. The fewer apps you have, the easier it is to keep track of them, resulting in a lower security risk. Permission is requested when an app is used for the first time, and sometimes for updates. Many apps access personal data. An unusual example reported to the NCSC shows that these permissions can also be exploited and abused.

20 April 2023

Cybertip: Things to watch out for in the Internet of Things

20.04.2023 - The Internet of Things (IoT) offers many advantages: heating systems, fridges, TVs, WiFi routers and various other devices can be connected to the internet, allowing them to be operated and monitored remotely. In manufacturing too, entire production processes can be operated via the internet. Yet, in addition to all the opportunities and convenience, the IoT also carries risks. What exactly is the IoT, and what opportunities and risks does it involve?

18 April 2023

Week 15: NFT fraudsters target digital art

18.04.2023 - For some time now, cases of fraud involving NFT art have also been reported to the NCSC. Last week, the NCSC received two identical reports of artists being approached by a supposed art enthusiast. This person probably would have gone on to steal their digital art file. Anyone interested in NFTs ought to be able to recognise the most common scams.

Federal Council and cantons define new national cyberstrategy

13.04.2023 - The new national cyberstrategy (NCS) was approved by the Federal Council during its meeting on 5 April 2023 and by the cantons during today's plenary session of the CCJPD. The strategy sets out the objectives and measures with which the federal government and the cantons, together with the business community and universities, intend to counter cyberthreats. A steering committee will be established to plan and coordinate the implementation of the strategy, and will also refine it. Its role is to be expanded and its independence increased.

11 April 2023

Week 14: Phishing in Swiss German and an invoice from Schweizerische Rettungsfahrtwacht (imitation of Swiss Air-Rescue)

11.04.2023 - Fraudsters, phishers and enterprising schemers repeatedly refer to Switzerland to try to gain the trust of their victims and lure them into acting rashly. In a case reported to the NCSC last week, Swiss German was even used to trick the victim into providing their credit card details. In another case, the trusted name of Swiss Air-Rescue (Schweizerische Rettungsflugwacht) was misappropriated in order to prevent the victim from reading the small print.

4 April 2023

Week 13: More than just an empty website – the business model that exploits abandoned domains

04.04.2023 - There may be more to an empty website than meets the eye, as shown by a case reported to the NCSC last week. Some Java script on an empty website redirected the visitor to a dubious website, but only if the original website had been accessed via a search engine or social media pages. Cybercriminals systematically take over abandoned domains, especially those with a trustworthy reputation and thus a good search engine ranking, and try to deliberately redirect visitors to dubious advertising websites in order to then make money using various tricks.

31 March 2023

Cybertip: Back up your data regularly

31.03.2023 - Accidental deletion, technical problems and cyberattacks are common causes for the loss of important electronic data. An effective backup strategy, and therefore good data protection, helps to minimise the adverse effects of data loss. World Backup Day on 31 March is intended to remind everyone to back up their data regularly.

28 March 2023

Week 12: Easy money, or how hackers and fraudsters launder money

28.03.2023 - Using fake identities or hacked accounts to get at money is merely the first step for cybercriminals. The methods used to cover their tracks afterwards in order to evade the investigators are just as sophisticated as the fraud itself. The repayment of a fraudulently obtain sum of money to the victim's account shines a spotlight on the shadowy world of money laundering. The NCSC is using this an opportunity to report about the recruitment of money mules.

21 March 2023

Week 11: Fraud attempts with social media data

21.03.2023 - In CEO fraud attempts, attackers gather data from public sources in advance. They usually use company websites that list their employees and their functions. However, data on social media platforms can also be used for such fraud attempts, as shown by a case reported to the NCSC last week that targeted a company's HR department.

14 March 2023

Week 10: Two years of the weekly review and how to dispose of a computer correctly

14.03.2023 - Two years ago, the first NCSC weekly review was published. It was the start of a weekly series in which we report on the latest cyberincidents. Each week, we provide various tips on how to protect yourself and what to do in case of an incident. Including today's, more than 100weekly reviews have been published. The NCSC would like to thank all its readers for their interest. The current review shows what risks arise when disposing of or passing on computers, smartphones and USB sticks. The number of reports received by the NCSC fell sharply last week as the wave of fake extortion is now easing.

13 March 2023

Cybertip: For a secure mobile workspace

13.03.2023 - New ways of working are being introduced in many companies and organisations. For example, employees increasingly have the option of working away from the office and accessing the network remotely. However, remote access technologies carry certain risks. For this reason, it is important to observe a few security rules, both at home and on the road. Below you will find some tips on what you can do to make your mobile workspace more secure.

7 March 2023

Week 9: Threatening emails supposedly sent by the NCSC and real-time phishing

07.03.2023 - The number of reports received by the NCSC increased again in the ninth week of 2023, with 871 reports, the highest number received this year and the fourth highest in its history. Threatening emails purportedly from authorities accusing the recipient of a criminal offence accounted for the largest share. Now, the NCSC is often being given as the sender of these scam emails. Reports of phishing have also increased in the last three months. This week, a case of real-time phishing was discovered, which seeks to exploit second-factor authentication.

2 March 2023

Cybermyth: With my IBAN, address and a copy of my ID card, my online banking account can be hacked

02.03.2023 - In many types of fraud, the attackers demand personal details such as name, address and telephone number. In some cases, they also ask for an IBAN or ask the victim to send a copy of a passport or ID card. A widespread myth is that it is possible to hack an online banking account with this information alone.

28 February 2023

Week 8: Text messages supposedly from the Federal Council and other new phishing methods

28.02.2023 - The number of reports received by the NCSC rose again in the eighth week of 2023. Phishing messages in both email and text message form are among the cyberphenomena most frequently reported to the NCSC. In most cases, they are simple standard phishing attempts. However, last week saw a few very sophisticated and original variants being reported. This included apparent voice messages, password-protected phishing PDFs and phishing websites disguised as special offers on belated motorway tax sticker purchases.

21 February 2023

Week 7: Encrypted VMware ESXi systems and purported stopping of social security benefits

21.02.2023 - The number of reports received by the NCSC fell slightly in the seventh week of 2023. The NCSC received an increasing number of reports of encrypted VMware ESXi systems and urgently recommends that all updates be applied. In addition, emails attracted attention in which it was claimed that the recipient's social security benefits would be stopped. However, a daily amount could be won in a competition. Other emails claimed that the minimum pension will be increased and that credit card details were needed for this.

14 February 2023

Week 6: Real-time phishing of secured Office365 accounts

14.02.2023 - The number of reports received by the NCSC remained at the same high level last week. Attacks on Microsoft Office365 accounts stand out. These accounts are often secured with a second factor and are therefore harder to hack. So attackers are going to considerable lengths, using real-time phishing to obtain login credentials nonetheless. They use the stolen credentials to send phishing emails or for business email compromise attacks.

7 February 2023

Week 5: Sophisticated telephone phishing

07.02.2023 - The number of reports received by the NCSC rose slightly in the fifth week of 2023, with 726 reports. In a phishing case reported last week, the attackers promise to activate a fast 6G network. This phishing attempt is very sophisticated and comprises a number of stages. The attackers even use stolen personal details from the victim's client portal.

6 February 2023

Cybertip: Five steps to ensure your digital security

06.02.2023 - Launched by the European Commission, Safer Internet Day takes place every year in February to promote a common awareness of safe and responsible use of digital media. In Switzerland, the Youth and Media national platform and the National Cybersecurity Centre, among others, use this day to raise public awareness. Thanks to the mnemonic S-U-P-E-R, internet users can easily check and optimise their cyberspace conduct.

2 February 2023

Microsoft Exchange servers still vulnerable in Switzerland (ProxyNotShell) despite NCSC warning

02.02.2023 - Back in November 2022, the National Cybersecurity Centre (NCSC) indicated that more than 2,800 Microsoft Exchange servers in Switzerland were vulnerable because of the critical vulnerability called ProxyNotShell. A month later, the NCSC sent registered letters to around 2,000 operators, asking them to patch the vulnerability. Nevertheless, the message has still not got through to everyone. More than 600 servers in Switzerland are still affected by the gateway for cybercriminals.

31 January 2023

Week 4: Malware in hotels: booking data used for fraud against hotel guests

31.01.2023 - The number of reports received by the NCSC fell slightly again in the fourth week of 2023, with 716 reports. In a recent case, a bogus receptionist contacted a hotel guest in order to obtain credit card details and to persuade him to make an additional payment. Following on from such cases being observed in France in recent weeks, a case has now also been reported in Switzerland. The guests' booking data is stolen in advance from the affected hotels by the RedLine Stealer malware.

24 January 2023

Week 3: From invoice manipulation to subscription scams – a growing number of different types of fraud using QR codes

24.01.2023 - QR codes are becoming increasingly popular and are used for various purposes. They are used not only to provide links to websites, but also to organise entire logistics processes. QR codes have also found their way into invoices. Effective since 1 October 2022, only invoices with QR codes are accepted in Switzerland. Clearly, QR codes can also be misused, as illustrated by two examples reported to the NCSC last week.

19 January 2023

Include your security contact on your website

19.01.2023 - In case of cybersecurity problems in a company or organisation, it is very important to quickly inform the relevant security contact. Often, however, these contacts are not easy to find on websites, or are not even listed. The "security.txt" standard provides a way to publish the security contact of an organisation or company in a uniform way, thus making it quicker to find.

17 January 2023

Week 2: CEO fraud targeting companies in French-speaking Switzerland – the scammers also contact their victims by phone

17.01.2023 - In the second week of 2023, the number of reports received by the NCSC was up significantly on the first week of the new year, with a total of 836 reports. The already familiar CEO fraud scam is currently experiencing a revival, with the scammers not only sending emails, but also calling the victims to stress their fraudulent demands.

12 January 2023

Cybertip: manipulated USB flash drives are a gateway for cyberattacks

12.01.2023 - USB flash drives have long been part of everyday computer life and are used to store data or transfer it from one computer to another. However, many people do not realise that manipulated USB flash drives can also be used to hack into computers.

10 January 2023

Week 1: Hacked websites exploited for search engine optimisation

10.01.2023 - With a total of 559 reports, the number of reports received by the NCSC in the first week of 2023 has increased again compared to the previous week. A report on a Google search that returned dubious search results turned out to be a case of search engine manipulation. Numerous websites were hacked with the aim of tricking Google's search algorithm.