Skip to main content

Hot topics 2024

31 December 2024

Week 52: Around 63,000 reports in 2024

31.12.2024 - In our final weekly review of the year, we take a look back on the around 63,000 reports of cyber incidents we received over the past twelve months. Once again, scams involving threatening phone calls purporting to be from the police stood out: this type of scam accounted for more than a third of all reports this year. This and other types of scams are featured in this week’s review. Cybercriminals are working across all channels, calling people on the phone, sending emails, text messages and letters, and even pasting fake QR codes over real ones. We would like to thank all of you for the valuable information and reports you have provided to help us better assess the situation in cyberspace and provide early warning to potential victims.

24 December 2024

Week 51: "All I want for Christmas is your Money"

24.12.2024 - The song "All I want for Christmas is you" is almost impossible to avoid during the festive season. Avoiding phishing and other scams can be just as difficult, as scammers try to trick you in a variety of ways. For them,"All I want for Christmas is your money" is the motto at this time of year.

17 December 2024

Week 50: Spying on business emails

17.12.2024 - As a business, you send emails to your customers all the time: project enquiries and processing, order placement, payment and delivery terms – a lot of things happen through this communication channel. It takes little effort for scammers to exploit this, but the damage to the victim can be enormous. A very interesting case of this happening was recently reported to us.

10 December 2024

Week 49: Churches, schools, associations and political parties increasingly the victims of CEO scams

10.12.2024 - Over the past week, the NCSC has received numerous reports of attempted CEO fraud phishing scams. Churches, schools, associations and political parties are particularly affected as they often publish a lot of information on their websites that criminals can use to create credible scams. The scammers' aim is to get victims to make payments or buy gift cards online and send them the codes so that the scammers can redeem them.

6 December 2024

Federal Council adopts strategic goals for cybersecurity exercises in the Federal Administration and Armed Forces

06.12.2024 - At its meeting on 6 December, the Federal Council approved the report on cybersecurity exercises in the Federal Administration and the Armed Forces in response to the postulate submitted by Marcel Dobler (22.4081). The Federal Council has defined three strategic goals for cybersecurity exercises in the Federal Administration and the Armed Forces: it wants to strengthen internal coordination and cooperation, standardise the preparation and follow-up of cybersecurity exercises, and institutionalise cooperation across the Federal Administration and at international level. The National Cyber Security Centre (NCSC) is to play a key coordinating role in this process.

5 December 2024

ECSM 2024 in review: Cybersecurity and AI awareness

05.12.2024 - For this year's European Cyber Security Month (ECSM), the NCSC focused on raising awareness of social engineering and artificial intelligence (AI). We worked with a range of partners to develop targeted content for young people, professionals and seniors. This review highlights the campaign’s successes and key findings.

3 December 2024

Week 48: How scammers ruin your holidays

03.12.2024 - When the first snow falls and the Christmas holidays are just around the corner, many of us dream of visiting one of Switzerland’s famous holiday destinations. To find the right place to stay, we use a search engine or one of the popular booking sites. But there are scammers out there who want to steal your money and don’t care if they ruin your holiday. In this week’s review, we discuss recent examples of this type of scam.

2 December 2024

E-mails with malware in the name of debt collection agencies and health insurance companies

02.12.2024 - The NCSC is currently receiving numerous reports of e-mails that claim to come from a debt collection agency or a health insurance company. They concern an alleged claim or reminder. Do not click on the link, as this is an attempt to distribute malware to Windows users.

26 November 2024

Week 47: Social media - Bogus public transport offers lure you into a subscription trap

26.11.2024 - The NCSC has received a growing number of reports of advertisements on social media that offer competitions or low-cost travelcards purportedly from Swiss and Liechtenstein transport companies. What may at first glance appear to be a tempting offer or a chance to win something may turn out to be a subscription or season ticket scam that could end up costing you dearly.

24 November 2024

DDoS attack on the website of the Canton of Schwyz causes various cantonal and municipal websites to go down

24.11.2024 – Since the early hours of the morning, the website of the Canton of Schwyz has been the target of an overload attack, a so-called DDoS attack. The attack is still ongoing and is currently causing the websites of various municipalities in different cantons, as well as various cantonal websites, to be unavailable. No information is currently available regarding the motivation.

19 November 2024

Week 46: How fraudsters bypass providers' SMS filters

19.11.2024 - Phishing using text messages has increased significantly in recent weeks. A wave of text messages demanding payment of bogus parking fines is now being followed by messages about fake parcel deliveries. Interestingly, these text messages no longer come in the standard form of an SMS, but via RCS, a protocol mainly used on Android devices, or via iMessage, Apple's text messaging service. This allows fraudsters to bypass mobile phone providers’ SMS filters.

14 November 2024

Caution: Fake letters on behalf of MeteoSwiss – Instead of a ‘Severe Weather Warning App’, malware is downloaded

14.11.2024 - Physical letters with MeteoSwiss as the sender are currently being sent out. The letters ask the recipients to download a new ‘Severe Weather Warning App’ via a QR code. However, malware is downloaded to the smartphone instead. This looks similar to the Alertswiss app from the Federal Office for Civil Protection on the smartphone's home screen.

13 November 2024

Exchange with the Swedish Minister for Civil Defence Carl-Oskar Bohlin in Bern

12.11.2024 - Today, President Viola Amherd and Federal Councillor Guy Parmelin received Sweden’s Minister for Civil Defence Carl-Oskar Bohlin for an exchange on current security policy issues. Cybersecurity was also addressed. During the exchange with the director of NCSC, Florian Schütz, it was shown how the public administration, the private sector and researchers are working together to strengthen Switzerland's resilience to cyberthreats.

Week 45: How attackers try to spread malware using fraudulent CAPTCHAs and supposed updates

12.11.2024 - Over the past week, the NCSC has received an increasing number of reports about websites that are compromised in order to make visitors believe that the browser needs to be updated or a CAPTCHA needs to be solved. The aim is to infect website visitors' devices with malware.

8 November 2024

Digital Switzerland Advisory Board: Cybersecurity is an important basis for digitalisation

08.11.2024 - At the meeting of the Digital Switzerland Advisory Board on 8 November, the National Cyberstrategy (NCS) was the focus of discussions. Under the leadership of the President of the Swiss Confederation Viola Amherd and with the participation of Federal Chancellor Viktor Rossi, representatives of the cantons, business, science and civil society took stock of cybersecurity measures and highlighted the challenges and opportunities of the current strategy.

7 November 2024

A cyberincident reported every 8.5 minutes

07.11.2024 - Cyberthreats are increasing significantly: so far this year, the National Cyber Security Centre (NCSC) has received, on average, a cyberincident report every 8.5 minutes. With 34,789 cyberincidents reported to the NCSC in the first half of 2024, numbers have almost doubled compared to the same period last year. The increase is due in particular to a massive rise in fraud attempts, which at 23,104 cases account for two thirds of all reports. Most of these cases involve telephone fraud, as explained in a separate report.

5 November 2024

Week 44: "Black Basta" - A clever way to defraud businesses: using spam to trick people into installing ransomware

05.11.2024 - A case was reported to us last week that shows how criminals associated with the Black Basta group infect businesses with ransomware. Victims are bombarded with spam emails and then contacted by fake support staff via Microsoft Teams and by phone. Ostensibly, the support staff are there to repair the damage – but in reality, they are scammers trying to gain access to their victims' devices in order to install malware.

4 November 2024

Caution: Phishing e-mails in the name of the OASI

04.11.2024 - The NCSC is currently receiving reports of phishing e-mails in the name of the OASI compensation office. The message advises recipients that an alleged refund is pending and that they should provide their personal data and credit card information for this. In reality, the cybercriminals are trying to make purchases with the phished credit card data in their favour.

29 October 2024

Week 43: Parking fee phishing with fake QR codes

29.10.2024 - Over the past few years, we have seen a significant change in the tactics used in credit card phishing scams. With two-factor authentication becoming increasingly common, it is no longer enough for scammers to simply trick their victims into sharing their credit card details. Now they have to trick their victims into going through the entire payment process and authorising the payment at the end. That's why they’re always looking for ways to deceive their victims and make them do things they shouldn’t. A particularly brazen example was reported to the NCSC last week.

24 October 2024

European Cyber Security Month (ESCM): Tips for senior users:

24.10.2024 - Criminals have been scamming the elderly with distressing phone calls for some time. But now they are also using AI to carry out these attacks: they use voice cloning software that takes one or more voice samples of a person known to the victim and creates a fake voice that sounds similar. This allows scammers to pose as trustworthy people and deceive their unsuspecting victims. These scams are becoming increasingly difficult to detect.

22 October 2024

Week 42: Scams involving abandoned or forgotten domains

22.10.2024 - Domain owners who forget to renew their domains on time, or who give their domains up voluntarily, may be in for a nasty surprise. We are aware of several scams where cybercriminals have taken advantage of domain owners’ lapses in attention.

21 October 2024

NCSC Director attends meeting of ASEAN Committee in Bern

21.10.2024 - On Monday, 21 October, the ambassadors of the ASEAN countries in Switzerland met with NCSC Director Florian Schütz for a working meeting. The FDFA was represented by the South-East and Pacific Regional Coordination Team. The agenda included a presentation of the National Cyber Security Centre, Switzerland's cooperation with ASEAN countries in the digital sector, and initiatives on cybersecurity and digitalisation within ASEAN.

17 October 2024

The importance of addressing perceptions and cultural context in European Cyber Security Month (ECSM) campaigns

17.10.2024 - As part of this year’s ECSM, the European Union Agency for Cybersecurity (ENISA) invited its member states to create short videos on how they have adapted the ECSM campaign in terms of messaging and content to best suit the culture and people’s perceptions in their respective countries.

15 October 2024

Week 41: Fake support scams – now with phishing

15.10.2024 - In fake support scams, criminals pretend to be from an IT company – such as Microsoft – in order to convince their victims to give them remote access to their computers. In a new type of fake support scam that has recently been reported to us, the scammers also try get hold of the victims’ login details.

10 October 2024

Brief technical analysis of the "Gorilla" botnet

10.10.2024 - In September 2024, the NCSC recorded an increase in DDoS attacks carried out by a botnet called "Gorilla". This is a "DDoS-as-a-service" service offered on Telegram, which can be rented for some fee. As an operator of a critical infrastructure in Switzerland was affected by such DDoS attacks, the NCSC has published the technical findings in a short report.

10 October 2024

European Cyber Security Month (ESCM): Tips for business users

10.10.2024 - Social engineering is successful because it exploits human needs and weaknesses. Studies show that social engineering plays a role in almost all cases of cybercrime. AI is also increasingly being used in these attacks. Audio deepfakes in particular are increasingly being used to attack businesses.

8 October 2024

Week 40: Artificial intelligence – Now also used for reviews

08.10.2024 - There are increasing reports of scams being carried out with the help of artificial intelligence (AI). AI can be used to imitate voices, create deepfake videos or write texts in Swiss German. Last week, we received a report that a fake entry had been made on a review site using AI.

7 October 2024

Florian Schütz attends Counter Ransomware Initiative annual summit

07.10.2024 - Florian Schütz, Director of the National Cyber Security Centre (NCSC), took part last week in the Counter Ransomware Initiative annual summit as head of the Swiss delegation. Approaches and solutions to combat ransomware attacks were discussed and concrete measures presented at the four-day summit. In a bilateral meeting, the NCSC director and the director of the Information Technology Laboratory of the National Institute for Standards and Technology (NIST) agreed to boost their technical cooperation.

3 October 2024

European Cyber Security Month (ESCM): Tips for young users

03.10.2024 - TikTok, Instagram, Snapchat and other similar apps offer many features that use artificial intelligence (AI), such as image generators, chatbots and tools that make AI-generated human faces. When an image or video is uploaded to the app, it is automatically analysed to suggest effects, filters or subtitles. These AI-driven background functions are not problematic in themselves, but their risks become apparent when they are used by criminals to manipulate their victims.

1 October 2024

Week 39: Another fake sextortion scam: Now the scammers know where you live.

01.10.2024 - The NCSC reported on the use of data leaks in fake sextortion emails a few weeks ago. To make victims believe their computers had been hacked, scammers told them they knew their phone number. The scammers have now adapted their approach and are using home addresses to increase pressure on their victims. Our research shows that scammers also get this information from data leaks.

30 September 2024

AI in cyberattacks – the NCSC's focus during European Cyber Security Month

30.09.2024 - Artificial intelligence (AI) is increasingly being used in cyberattacks, particularly social engineering attacks. For this year's European Cyber Security Month (ECSM), the National Cyber Security Centre (NCSC) will be raising public awareness of this cyberthreat. The ECSM takes place every October and is organised by the European Union Agency for Cybersecurity (ENISA) together with the European member states.

26 September 2024

2024 National Cybersecurity Conference: focus on geopolitics and operational security

26.09.2024 - Cyberthreats play an important role in today's tense geopolitical climate, but they have long been an everyday risk for businesses and governments. The National Cybersecurity Conference held today highlighted how a comprehensive approach can be taken to tackle cyberthreats. In her opening remarks, President Viola Amherd stated that the foundations for cybersecurity are now in place so that emphasis can now be placed on setting strategic priorities. The conference, organised by the National Cyber Security Centre (NCSC) and the Swiss Security Network (SSN), was attended by over 280 participants from business, science, and cantonal and federal offices.

24 September 2024

Week 38: Investment scams – fake help after big losses

24.09.2024 - Fraudulent investments, especially those involving cryptocurrencies, are a widespread scam. The NCSC is now seeing a lot of advertising on social media for companies and their websites that claim to be able to recover lost money. Unfortunately, they are just another scam.

17 September 2024

Week 37: Visiting the USA – look out for Green Card and ESTA scams

17.09.2024 - The NCSC receives many reports of private sector providers offering to help people access government services for a fee. However, these providers usually do very little: their service consists of transferring your data from the form on their website to the official form on the government website. These kinds of scams are common for ordering criminal records extracts or motorway tax stickers. Last week, two cases were reported to the NCSC that have to do with travel to the USA.

10 September 2024

Week 36: Motorists targeted by cyber criminals

10.09.2024 - Fraudsters take advantage of every opportunity to get their hands on your money. Last week, two cases were reported to the NCSC in which motorists were targeted by fraudsters. The schemes involved fake websites for motorway stickers in Austria and parking fines in Switzerland.

3 September 2024

Week 35: Cheque fraud – but with crypto instead

Overpayment scams and cheque fraud are outdated. Under such scams companies are commonly asked to purchase services from third parties that go beyond the original order. Under normal circumstances the cheque provided should cover all expenses – but in such scams there are no funds to cover the cheque. The third parties to whom the payments are made are fake companies that belong to the scammers. As cheques are now rarely used in Switzerland, scammers are testing new approaches using modern payment methods, as a case reported to the NCSC last week shows.

27 August 2024

Week 34: What's up with my friend's WhatsApp account? How scammers can use the messaging service to trick you.

27.08.2024 - The NCSC has received more reports of hacked WhatsApp accounts in recent days. The approach is similar to what we already observed last year: someone you know contacts you on WhatsApp and asks you to help them with an urgent problem. All you have to do is forward them an SMS code. What's different now is that the scammers are writing in dialect and trying to get you to send them money via TWINT.

22 August 2024

Cybersecurity in the supply chain

22.08.2024 -The increasing interconnectedness of systems along the supply chain provides cybercriminals with many different ways to attack an organisation. It is therefore important for companies and public authorities to understand their supply chains and be aware of the cyber risks they face. National Cyber Security Centre (NCSC) has launched a pilot project together with Planzer Transport AG so that companies, authorities and organizations in Switzerland can easily implement their cyber security requirements in the supply chain. A simple cycle was designed to demonstrate protective measures against cyber attacks in the supply chain. The pilot project also provides specific tools that are published on the NCSC website. At the Online Brownbag Lunch on 5 September 2024, the NCSC and Planzer Transport AG will demonstrate how organizations can correctly assess cyber risks in their supply chains.

20 August 2024

Week 33: Fake sextortion and data leaks

20.08.2024 - Data leaks from online service providers are giving scammers new ideas. They are combining information from multiple data leaks to create new data sets that they can then use to scam their victims. The NCSC has received reports of several cases of sextortion where scammers have done exactly this.

13 August 2024

Week 32: Sharing and preserving holiday memories

13.08.2024 - The holiday season is slowly coming to an end and we have all made wonderful memories to look back on. To ensure that our memories remain safe, it is important that we think about cybersecurity. Read on to learn what to look out for.

6 August 2024

Week 31: Beware when scanning QR codes!

06.08.2024 - QR codes have become ubiquitous. A quick scan and you can call up the menu in a restaurant and then pay the bill, for example. They are often to be found on parking meters, which can be useful if you don’t have any change. But beware: QR codes can also be faked. Quishing , or QR phishing, where attackers use QR codes to steal sensitive information, is on the rise.

30 July 2024

Week 30: Secure your smartphone: keep your data safe from sticky fingers

30.07.2024 - Mobile phones have become an indispensable companion, even on holiday. Whether you're trying to find directions, buy tickets or look up information: you can do it all on your smartphone. The camera also allows us to take photos and create memories wherever we go. But along with holiday snaps, these compact devices also store personal information such as contacts, emails and login details. If your smartphone is lost or stolen, the consequences can quickly become very serious. That's why it's important to have the best possible security measures on your phone so as to protect your data from fraud if it's stolen.

23 July 2024

Week 29: Be careful using public WiFi

23.07.2024 - Public WiFi networks at hotels, cafes and airports are a convenient and often free way to access the internet while avoiding roaming charges. Unfortunately, they are also a popular target for cybercriminals looking to steal personal information such as credit card details. Recently, a person was arrested in Australia for setting up fraudulent networks on planes and in airports.

19 July 2024

Worldwide system failures due to faulty updates

19.07.2024 - The NCSC is aware of system failures worldwide and has received corresponding reports from various companies and critical infrastructures in Switzerland. It is a faulty update or misconfiguration by the company CrowdStrike that is causing these system failures. NCSC is in contact with the affected companies. There are currently no known outages in the Federal Administration.

16 July 2024

Week 28: What to look out for when you book a hotel

16.07.2024 - Holidaymakers like to spend the best and most relaxing days of the year in different ways: some want to explore foreign cities, others want to sunbathe on an idyllic beach or go on walks or bike rides in the countryside. These days many of these holiday activities can be booked online. Cybercriminals know this too: they use phishing scams to impersonate travel companies in order to obtain login details or credit card information. Scammers also create fake hotel websites. In one recent case, they even hijacked a hotel's Booking.com account.

11 July 2024

Brief technical analysis of the "Poseidon Stealer" malware

11.07.2024 - At the end of June 2024, cybercriminals spread the malware "Poseidon Stealer" in German-speaking Switzerland by email, using AGOV as a lure with the aim of infecting computers with the macOS operating system. The NCSC has now produced and published a brief technical analysis of the malware.

10 July 2024

Florian Schütz in Seoul to take part in the OECD's Global Forum on Digital Security for Prosperity

10.07.2024 - Florian Schütz, Director of the National Cyber Security Centre (NCSC) and Chairman of the Working Party on Digital Security (WPDS) of the Organisation for Economic Co-operation and Development (OECD), will take part in the Global Forum on Digital Security for Prosperity, which is being held in Seoul from 10 to 11 July 2024. His schedule includes chairing a panel dealing with the topic of regulation in digital security. The aim of the event is to conduct a joint dialogue, exchange experiences and work on the development of public strategies in the field of digital security.

9 July 2024

Week 27: Cyberattacks in the art industry

09.07.2024 - The NCSC has recently received several reports of attempted scams targeting artists and art organisations. One of the scams involves purported donations from a charitable foundation, while the other involves a fake overseas purchase.

2 July 2024

Week 26: Scammers use the Federal Administration's name for a broad range of attacks

02.07.2024 - Phishers pretending to be from the Federal Tax Administration, menacing emails claiming to be from the Federal Office of Justice and Police and the NCSC, and a barrage of emails last week containing malware hiding behind a fake 'AGOV' government login: scammers and attackers use the names of authorities to put pressure on or gain the trust of the public.

28 June 2024

Cybercriminals spread malware for macOS in emails purportedly from AGOV

28.06.2024 - On the evening of 27 June 2024, cyber criminals launched a major 'malspam' campaign against citizens in German-speaking Switzerland. An attempt is being made to infect computers using the macOS operating system with malware called 'Poseidon Stealer' via an email purporting to be from AGOV.

25 June 2024

Week 25: How scammers exploit major events such as the European Football Championship and the Olympics

25.06.2024 - The European Football Championship is in full swing and the Olympic Games in Paris are just around the corner. But it's not just the fans who look forward to such major events: scammers also see an opportunity to benefit from these events and defraud fans. Last week, the NCSC received a number of reports from people who paid for tickets they never received. Particularly at major events such as the Olympic Games and international football tournaments, it is important to be cautious when buying tickets and to observe basic cybersecurity rules.

20 June 2024

Summit on Peace in Ukraine: first NCSC report on Cyber Situation Network

20.06.2024 - Even before the Summit on Peace in Ukraine got under way, cyberattacks on the conference and network infrastructure in Switzerland were expected. A number of cyberattacks were then confirmed, but they were all detected early and quickly averted. In order to jointly counter the expected cyberattacks, Switzerland set up a Cyber Situation Network coordinated by the National Cyber Security Centre (NCSC). Today, the NCSC published an initial review of the work of the Cyber Situation Network.

19 June 2024

Cyber Europe 2024: Focus on the energy sector

18.06.2024 - Cyber Europe 2024, the 7th edition of the European cyber exercise, will take place over the next two days. In recent years, exercises have been based on scenarios covering the healthcare sector, civil aviation and telecommunications. This year, the focus is on the energy sector. Switzerland is a co-organiser and an important partner of Cyber Europe 2024. Under the lead of the NCSC, the exercise will also involve other federal agencies and around 30 organisations from the Swiss energy sector.

18 June 2024

Week 24: When influencers get hacked – and then fall victim to fraud

18.06.2024 - A few months ago, a popular influencer contacted the National Cyber Security Centre (NCSC) because his Facebook account had been hacked. Social media presence and follower engagement is central to his profession. After Facebook closed the account that had been hacked, he set up a new account – but the story wasn't over yet.

17 June 2024

Update: Even after the conclusion of the high-level conference on peace in Ukraine, the overload attacks on websites of organisations involved continue

17.06.2024 - As expected, the overload attacks continue even after the conclusion of the high-level conference on peace in Ukraine. The websites of the organisations involved in the conference are still being targeted. The National Cyber Security Centre is monitoring the situation and is in contact with the organisations concerned.

11 June 2024

Introducing SMEs to cybersecurity

11.06.2024 - The NCSC joined forces with the association ITSec4KMU to organise an awareness-raising event on cybersecurity for SMEs. This free event held at the Cinématte in Bern gave more than 100 interested rep-resentatives from SMEs an easy introduction to this important topic. There are plans to repeat the event in other regions of Switzerland.

11 June 2024

Week 23: Types of fake sextortion scams

11.06.2024 - Over the past few days, the NCSC has again received a number of reports of fake sextortion emails. Some of the emails appear to have been sent by the recipient themselves, or contain their actual password. How is this possible – and how should you respond if this happens to you?

7 June 2024

DDPS sets up National Cyberstrategy steering committee

07.06.2024 - A steering committee has been set up to manage the National Cyberstrategy (NCS) implementation process. It supports the federal, cantonal, business and academic bodies concerned in implementing the NCS in a targeted and effective manner. The Federal Department of Defence, Civil Protection and Sport (DDPS) appointed the members of the steering committee and informed the Federal Council of the appointments at the latter's meeting on 7 June.

6 June 2024

Increasing cyber resilience in the context of major events and international conferences

06.06.2024 - Large-scale events and international conferences are often used as an opportunity to stage a cyberattack. In order to minimise cyber risks for organisations involved in such events, it is important to have broad-based protective measures in place. The NCSC has published recommendations on such protective measures.

4 June 2024

Week 22: How fraudsters try to operate phishing websites undetected for as long as possible

04.06.2024 - Phishing websites have long been one of the cyber incidents most frequently reported to the National Cyber Security Centre (NCSC). In order to protect as many potential victims as possible, the NCSC tries to ensure these websites are deactivated as quickly as possible. Meanwhile, the fraudsters do everything they can to prevent this, as shown by an example reported to the NCSC last week.

28 May 2024

Week 21: Beware of dubious domain registration requests

28.05.2024 - A fake domain name registration company sent an email to the owner of a .ch domain. The email claimed that the fake company had received an application to register the same domain name but with a different ending. Most of the time, these emails come from fake registration companies in Asia. However, in this case, the scammer behind the fake company is German-speaking, has a website and is falsely claiming to have years of experience.

22 May 2024

Federal Council launches consultation on Cybersecurity Ordinance

22.05.2024 - At its meeting on 22 May the Federal Council launched a consultation on the Cybersecurity Ordinance. The Ordinance sets out how the obligation to report cyberattacks on critical infrastructure is to be implemented, regulates how implementation of the National Cyberstrategy is to be organised and specifies the tasks of the new National Cyber Security Centre (NCSC). The Ordinance also specifies which authorities and companies are exempt from the reporting obligation. The consultation will run until 13 September 2024.

21 May 2024

Week 20: Patchday – regular updates keep you safe

21.05.2024 - Microsoft, the manufacturer of the widely used Windows operating system and the well-known Office environment, releases patches (updates) for its products once a month. Other software manufacturers may have a different cycle, but what they all have in common is that these updates should be taken seriously. On the one hand, patches help to improve the functionality or performance of software, but above all they boost product security and thus protect users from potential attacks.

16 May 2024

Cybersecurity in simple terms: Awareness-raising event for SMEs

16.05.2024 - For many small and medium-sized enterprises (SMEs), cyberattacks are still an abstract, intangible threat. Although awareness of cyberthreats has increased, there is still a large gap between knowledge and action. To help SMEs get to grips with cybersecurity, the National Cyber Security Centre (NCSC) and the ITSec4KMU association are organising a free awareness-raising event for SMEs in Bern on 11 June.

14 May 2024

Week 19: Smartphone – an Achilles' heel: How cybercriminals undermine two-factor authentication

14.05.2024 - Access to many applications on the internet is now protected by two-factor authentication. Smartphones are playing an increasingly important role as a second security factor when logging into online applications. Cybercriminals therefore try to gain access to these devices in order to obtain the login data. A case reported to the NCSC last week shows that entering a password in a phishing attack on an apparently non-critical internet service may nonetheless have serious consequences. It may also undermine the two-factor authentication process.

13 May 2024

Florian Schütz in Birmingham: Greater international cooperation in cybersecurity

13.05.2024 - The director of the National Cyber Security Centre (NCSC), Florian Schütz, will be attending two key international events in the field of cybersecurity in Birmingham on 13–15 May 2024. The trip is aimed at strengthening international cooperation on cybersecurity and the fight against ransomware.

7 May 2024

Week 18: Fraud on crowdfunding platforms

07.05.2024 - Crowdfunding platforms have revolutionised the way in which creative projects and innovations can generate financial support. However, even these crowdfunding platforms are not immune to fraudulent practices. Fraud attempts can hinder crowdfunding campaigns or diminish the trust of potential donors. It is therefore important that campaign organisers and donors are aware of the risks, remain vigilant and protect themselves against fraud attempts.

6 May 2024

Twice as many cyber incidents reported and rise in AI scam attempts

06.05.2024 - More than 30,000 cyber incidents were reported to the NCSC in the second half of 2023, twice as many as in the same period last year. The strategy of the new federal office is based on four pillars in order to strengthen cyber security for the general public, businesses and public authorities in the face of increasing threats and the emergence of AI-driven fraud.

30 April 2024

Week 17: Free pianos and fake parcel labels – different types of classified ad scams

30.04.2024 - Classified ad site for buying and selling items have been popular for a number of years – and this makes them interesting to scammers. In fact, classified ad fraud is one of the most commonly reported offences.

25 April 2024

S-U-P-E-R.ch – Beware of malware

25.04.2024 - Cybercriminals develop malware for a number of purposes: to disrupt or prevent the normal operation of a device, steal data or spy on the users' behaviour. Normally what is known as a 'downloader' is first sent to the device. It is not initially clear what damage this type of malware will cause.

23 April 2024

Week 16: When chance plays into the hands of scammers

23.04.2024 - The NCSC frequently receives reports from victims where the scam emails seem plausible because they happen to match a current situation. In such cases, it is particularly difficult to spot scam emails, as shown by three examples that have been reported to the BACS in recent weeks. However, by following a few basic rules, it is still possible to spot such emails.

19 April 2024

Critical vulnerability in Palo Alto firewalls

18.04.2024 - The NCSC warns of the security vulnerability in Palo Alto's Next-Generation Firewall (NGFW). These firewalls are mainly used by companies and public authorities. They have a critical vulnerability that is already being exploited by cyber criminals. The attackers exploit the vulnerability to execute commands. The NCSC has already received corresponding reports from organisations in Switzerland. The NCSC recommends installing the security updates as quickly as possible or even reinstalling the NGFW if possible.

18 April 2024

S-U-P-E-R.ch - Keep your virus protection up to date

18.04.2024 - A virus scanner helps to ensure that your device is not infected by malware. It is one of the most important software components that protects your device and your data. The program scans new files, e.g. email attachments, and the entire device for signs of infection. It is important to install this software and keep it up to date.

16 April 2024

Week 15: Calls from fake authorities at record high – but it’s not all bad

16.04.2024 - The NCSC has been monitoring the phenomenon of fake calls from alleged police authorities for nine months now. In the last three weeks, reports reaching the NCSC about this phenomenon have almost tripled and account for the highest number of reports received since the contact point was founded. However, the high number of incoming reports is not all bad.mittlerweile das Phänomen der gefälschten Anrufe von angeblichen Polizeibehörden. In den letzten drei Wochen haben sich die Meldungen zu diesem Phänomen beim BACS nahezu verdreifacht und sind verantwortlich für den höchsten Meldeeingang seit Gründung der Anlaufstelle. Der hohe Meldeeingang ist jedoch nicht nur negativ einzustufen.

11 April 2024

S-U-P-E-R.ch – Carry out regular updates

11.04.2024 - A healthy lifestyle involves having a good diet and regular exercise. It's the same in the digital sphere: for your software to be kept fit, it must be updated regularly. This is the only way that the software can provide effective protection against unauthorised access to your device.

9 April 2024

Week 14: Online meeting with deepfake boss: CEO fraud 2.0

09.04.2024 - The finance department receives a supposedly urgent payment request from the boss. The boss explains that if the person in accounts does not make the payment as quickly as possible, there will be serious consequences for the company as it risks losing an important order. The request usually cannot be queried as the boss is then not available. That is generally the scenario in cases of CEO fraud. Most of these attacks are not very sophisticated and easy to spot. However, artificial intelligence and deepfakes do not stop at this rather simple fraud method, as a recent example reported to the NCSC shows.

4 April 2024

Improve your digital health – launch of national cybersecurity awareness campaign focusing on updates and virus protection

04.04.2024 - Regular updates and up-to-date virus protection greatly improve cybersecurity. This is why the National Cyber Security Centre (NCSC), Swiss Crime Prevention (SCP) and cantonal and communal police forces are now launching a further part of the national S-U-P-E-R.ch campaign emphasising the importance of up-dates and virus protection. The campaign is supported by the internet security platform iBarry and "eBanking – but secure!" (EBAS).

3 April 2024

Discussions between the National Cyber Security Centre and the French Cybersecurity Agency (ANSSI)

03.04.2024 - Florian Schütz, Director of the National Cyber Security Centre (NCSC), will meet with his French counterpart, Vincent Strubel, Director General of the French Cy-bersecurity Agency (ANSSI), on 3 April to discuss cybersecurity issues and strengthen relations between the two countries.

2 April 2024

Week 13: Scammers posing as Federal Councillors

02.04.2024 - Federal Councillors are highly respected, widely trusted and enjoy a good reputation in Switzerland. Scammers take advantage of this: to lend credibility to their threatening emails, they make them look like they were sent by a member of the Federal Council. The scammers threaten their victims with criminal charges, usually for illegal pornography, unless they pay a certain amount of money.

26 March 2024

Week 13: Scammers posing as Federal Councillors

02.04.2024 - Federal Councillors are highly respected, widely trusted and enjoy a good reputation in Switzerland. Scammers take advantage of this: to lend credibility to their threatening emails, they make them look like they were sent by a member of the Federal Council. The scammers threaten their victims with criminal charges, usually for illegal pornography, unless they pay a certain amount of money.

19 March 2024

Week 11: Recycling is good, but not when it comes to passwords

19.03.2024 - Strong and complex passwords are key when it comes to protecting access to internet services. However, complex passwords have the disadvantage that they are difficult to remember, which tempts many users to either reuse the same password for multiple accounts or create straightforward passwords. This in turn significantly reduces the level of security. It is therefore worth considering using a password manager. However, as an example reported to the NCSC this week shows, that can also have its pitfalls.

12 March 2024

Week 10: Fraudulent emails sent using booking.com platform

12.03.2024 - Most of the phishing-related complaints received by the NCSC relate to emails or text messages designed to look like they originate from Swiss Post, the SBB/SwissPass or banks. In this edition of the week in review, we look at a variation on this theme targeting users of booking.com.

7 March 2024

Xplain hack: National Cyber Security Centre publishes data analysis report

07.03.2024 - The National Cyber Security Centre (NCSC) took over responsibility for incident management in the Federal Administration in the wake of the hacker attack on Xplain, a major provider of IT services to national and cantonal authorities. Part of its activities involved analysing the data that the perpetrators published on the darknet. The NCSC released a report today explaining its analysis and providing information on what type of data was affected and the challenges as-sociated with analysing the data. The report does not evaluate the content of the data, nor does it analyse why certain data was leaked. The latter question will be clarified as part of the ongoing administrative investigation.

5 March 2024

Week 9: Phishing scammers targeting gamers

05.03.2024 - Phishing attempts are among the most frequently reported cyberincidents at the NCSC. Cybercriminals use social engineering methods that they tailor to their target groups. For instance, players of the popular video game "Counter-Strike 2" are currently being asked to take part in a fake vote.

27 February 2024

Week 8: New types of social engineering attacks

27.02.2024 - Classified ad fraud is one of the offences most frequently reported to the police. The fact that new variants continually arise shows that this is a lucrative business for scammers. Three new types of social engineering attacks reported to the NCSC in recent weeks are designed to trick users of the TWINT payment app.

26 February 2024

Florian Schütz takes part in the Common Good Cyber Workshop 2024 in Washington D.C.

26.02.2024 - On 26 and 27 February, Switzerland will once again play an active international role in efforts to improve cyber security. Florian Schütz, Director of the National Cyber Security Centre (NCSC), will take part in the Common Good Cyber Workshop 2024 in Washington D.C., organised by the NGO Global Cyber Alliance.

20 February 2024

Week 7: Mods and cheats - What you should be aware of in video games

20.02.2024 - Computer games are very popular and, as in real life, not everyone always plays by the rules. The following report explains how searching for ways to cheat a game can end badly.

13 February 2024

Week 6: Your email account: a hub for online fraudsters

13.02.2024- The NCSC frequently receives reports of hacked social media accounts or unknown online purchases. In many cases, the scam can be traced back to a hacked email account. Unfortunately, people tend to underestimate the importance of protecting their email accounts.

6 February 2024

Week 5: Secure your home network from unauthorised access

06.02.2024 - The NCSC was recently notified of a case where hackers managed to break into a person's home network. After encrypting family photos and other personal data, they issued a ransom note demanding a substantial sum of money.

30 January 2024

Week 4: The tricks that phishers use to get clean data

30.01.2024 - Many internet users will now recognise phishing attempts when they see them. The main thing is not to click on the link: just ignore or delete the email or text message. Still, a lot of people are tempted to click on the link anyway and enter a made-up name or a password comprising a random combination of letters, just to give the scammers a hard time. This sort of data, which is totally worthless to scammers, then gets mixed up with real credentials stolen from unsuspecting victims. Before they can use or sell lists of stolen passwords, the scammers have to screen out all the junk data – and that takes a lot of time. So they are always looking for new tricks to keep their password lists as clean as possible.

29 January 2024

Anti-Phishing Report 2023

29.01.2024 - Last year, the NCSC received and analysed around 554,000 phishing reports. Of those, 10,007 websites were ultimately identified as phishing websites and the website operators informed. In the Anti-Phishing Report published today, the NCSC provides insight into that analysis and information on the most frequently misused brand names and domains. It also sets out the most important measures and recommendations to protect against phishing.

23 January 2024

Week 3: Alleged payments on the Etsy sales platform

23.01.2024 - Last week, the NCSC received several messages concerning the e-commerce platform Etsy. Immediately after creating an account, new sellers receive a message, purportedly from Etsy, stating that the seller must verify payment before the shop can be activated. This, however, is a phishing message.

17 January 2024

Administration websites disrupted by DDoS attack

17.01.2024 - A DDoS attack disrupted temporarily access to a number of websites today, including some belonging to the Federal Administration. The Russian-linked hacker group ‘NoName’ claimed responsibility for the attack, citing Ukrainian President Zelenskyy's attendance at the WEF Annual Meeting. The cyberattack was promptly detected and the Federal Administration's specialists took the necessary action to restore access to the websites as quickly as possible. An attack of this kind had been expected, and appropriate security measures were in place. DDoS attacks are aimed at making websites unavailable. They do not result in any data being lost or compromised.

16 January 2024

Week 2: The fraudsters who claim to live in the Alps

16.01.2024 - Classified ad fraud is one of the phenomena that is very frequently reported to the NCSC. This type of fraud involves either the buyers or sellers of goods in classified ads on one of the common internet platforms. The reason why the fraudsters often allege that they live in a remote area is explained here.

9 January 2024

Week 1: Fake support call variants

09.01.2024 - Previous weekly reviews have already highlighted the different ways in which scammers try to gain direct access to your device. In the current NCSC weekly review, another duplicitous method is explained.

The NCSC is now a federal office

01.01.2024 - From today, the NCSC is a federal office. The NCSC is now located in the Federal Department of Defence, Civil Protection and Sport (DDPS). The NCSC, which retains the name National Cyber Security Centre in English, will continue its core activities, namely the coordinated implementation of the national cyberstrategy (NCS) and making Switzerland more secure in cyberspace.