Skip to main content

Semi-Annual Reports

The NCSC publishes a report entitled ‘Cybersecurity: The Situation in Switzerland and Internationally’ half-yearly.

The reports describe the most important trends and developments relating to events and occurrences in information and communication technologies (ICT), explain the technical functioning of current attacks, provide an overview of events in Switzerland and abroad, illuminate the most important developments in the area of prevention, and summarize the most important activities of public and private players.

24 August 2026

Semi-Annual Report 2026/1

In this semi-annual report, the National Cyber Security Centre (NCSC) presents the relevant incidents and developments relating to cyberthreats in Switzerland and internationally. During the first half of 2026, the NCSC received 27,128 voluntary reports and 200 notifications of cyberincidents that were subject to mandatory reporting. Thus, the number of reports has stabilised at a high level. Fraud continues to dominate the statistics as a lucrative mass-market business, with telephone-based scams – such as voice phishing – having become particularly established methods. By using classifieds platforms, search engine listings and even data breaches as points of contact, cybercriminals are luring their victims using personalised, emotionally manipulative and, in some cases, technologically very sophisticated methods. Attackers are now systematically using artificial intelligence (AI) to deliver tailored, personalised and credible content to their victims.

30 March 2026

Semi-Annual Report 2025/2

In this semi-annual report, the National Cyber Security Centre (NCSC) presents the relevant incidents and developments in the context of cyberthreats against Switzerland and internationally. During the second half of 2025, the NCSC received 29,006 voluntary and 145 mandatory reports of cyber incidents. Of the reports received, 52% were classified as fraud; however, the number of fraudulent threat calls made in the name of authorities, which had dominated since mid-2023, declined significantly. While the core cyberthreat phenomena in Switzerland remained largely unchanged, the reporting period saw notable developments in how these threats were implemented and combined.

18 November 2025

Semi-Annual Report 2025/1

In the first half of 2025, the NCSC received 35,727 cyberincident reports, confirming that the volume of reports has stabilised at a high level. Of these reports, 58 % were related to fraud. The main cyberthreats facing Switzerland remained the same, although attackers continued to innovate in their methods.

6 May 2025

Semi-Annual Report 2024/2

IThe NCSC received 28,165 reports of cyberincidents in the second half of 2024. This is slightly lower than in the first half of 2024, but the figure rose by 13,574 to a total of 62,954 reports over 2024 as a whole. The fluctuations are mainly due to the large ripple effect of the phenomenon of fake threatening calls from authorities. The ratio between the number of reports received from private individuals and companies remains constant at 90% and 10% respectively. The categories of fraud, phishing and spam stay the most reported phenomena.

7 November 2024

Semi-annual report 2024/1

The NCSC semi-annual report outlines the key cyber phenomena shaping Switzerland's threat landscape. It examines how various threat actors in cyberspace employ different methods to achieve their goals, based on cyberincidents and developments in Switzerland and internationally during the first half of 2024.

6 May 2024

Semi-annual report 2023/2

The various fields of activity of the Federal Office are the focus of the new NCSC semi-annual report. It also looks at the most important cyber incidents in Switzerland and internationally in the second half of 2023.

2 November 2023

Semi-annual report 2023/1

The National Cybersecurity Centre's (NCSC) semi-annual report looks at the main cyberincidents that occurred in Switzerland and abroad in the first half of 2023, with a special focus on hacktivism.

10 May 2023

Semi-annual report 2022/2

The National Cybersecurity Centre's (NCSC) second semi-annual report deals with the most important cyberincidents of the second half of 2022 in Switzerland and internationally. It focuses on the most important issues surrounding cybersecurity in SMEs.

2 November 2022

Semi-annual report 2022/1

The latest semi-annual report of the National Cybersecurity Centre NCSC deals with the most important cyberincidents of the first half of 2022 both in Switzerland and internationally. The focus topic concerns cyberspace and armed conflicts.

31 October 2021

Semi-annual report 2021/2

The NCSC's latest semi-annual report deals with the most important cyberincidents of the second half of 2021 both in Switzerland and internationally. The focus topic concerns attacks on IT product supply chains.

31 October 2021

Semi-annual report 2021/1

The NCSC's second semi-annual report deals with the most important cyberincidents of the first half of 2021 in Switzerland and internationally. The main topic is dedicated to vulnerabilities in IT systems that can be exploited to carry out cyberattacks.

10 May 2021

Semi-annual report 2020/2

The NCSC's first semi-annual report deals with the most important cyberincidents of the second half of 2020 in Switzerland and internationally. It replaces the former MELANI semi-annual report. The main topic is digitalisation in the healthcare sector and the challenges it faces with regard to current cyberthreats.

28 October 2020

Semi-annual report 2020/1

The 30th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) addresses the most important cyberincidents of the first half of 2020 both in Switzerland and abroad. The current report focuses on the coronavirus pandemic, which has been used to entice victims in many cyberattacks.

29 April 2020

Semi-annual report 2019/2

The 30th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) addresses the most important cyberincidents of the second half of 2019 both in Switzerland and abroad. The latest report focuses on handling personal data on the internet and the problems involved. For the jubilee edition, we gave the report a more linear structure. It is now leaner and more practical. At the same time, we added a technical appendix to meet the needs of readers with in-depth technical knowledge.

28 October 2019

Semi-annual report 2019/1

The 29th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) addresses the most important cyberincidents of the first half of 2019 both in Switzerland and abroad. The main focus of the current report is cyberattacks with encryption Trojans, which caused considerable damage worldwide during the first half of the year.

30 April 2019

Semi-annual report 2018/2

IoT devices can be misused to a large extent for cyber attacks, successful blackmail attempts (e.g. fake sextortion) as well as money transfer fraud with Office 365 access data and the main topic “Dealing with purchased risks in hardware and software”. The 28th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) deals with the most important cyber incidents of the second half of 2018 in Switzerland and abroad.

6 November 2018

Semi-annual report 2018/1

The 27th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI), published on 8 November 2018, addresses the most important cyber incidents of the first half of 2018 both in Switzerland and abroad. The key topic is dedicated to the vulnerabilities in hardware. The focus is also on targeted malware attacks, for which the name of the Spiez Laboratory was misused, as well as various data leaks and the problem of multiple use of a password.

24 April 2018

Semi annual report 2017/2

The 26th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) addresses the most important cyber incidents of the second half of 2017 both in Switzerland and abroad. Among other things, the focus is on the widespread use of crimeware and attacks on industrial control systems in the medical technology sector. The spate of data leaks and their repercussions are examined in the main topic.

31 October 2017

Semi-annual report 2017/1

The 25th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI), published on 2 November 2017, addresses the most important cyber incidents of the first half of 2017 both in Switzerland and abroad. The encryption Trojans Wanna Cry and NotPetya, which made the headlines worldwide in spring 2017, are the focal point of the report.

18 April 2017

Semi-annual report 2016/2

The 24th semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI) addresses the most important cyber incidents of the second half of 2016 both in Switzerland and abroad. The focal point of the report is the internet of things, which is becoming increasingly significant.

26 October 2016

Semi-annual report 2016/1

The 23rd semi-annual Report highlights the main national and international cyber incidents of the first half of 2016. In its key topic, the report analyses the increased numbers of attacks using cyberextortion. The report also focuses on various data leaks.

26 April 2016

Semi-annual report 2015/2

In the second half of 2015, there were once again some spectacular cyber-related incidents worldwide. These were primarily DDoS attacks, phishing attacks and attacks on industrial control systems. The 22nd MELANI semi-annual report features handling security vulnerabilities as its key Topic.

28 October 2015

Semi annual report 2015/1

The 21st MELANI semi-annual report is dedicated to incidents such as espionage attacks, including those which affected Switzerland, the ever-present phishing attacks and the key topic of website security. The key topic is one of several innovations which the semi-annual report underwent.

24 June 2015

Semi-annual report 2014/2

The Reporting and Analysis Centre for Information Assurance MELANI has celebrated its tenth anniversary. Therefore, the 20th semi-annual report does not merely focus on the main events of the second half of 2014, which concerned primarily incidents of blackmail and attacks on poorly protected systems. The report also takes a look at the development of cybercrime over the past decade.

20 October 2014

Semi annual report 2014/1

In the first half of 2014, the main focus was on sophisticated attacks on companies using social engineering, phishing attacks tailored to Switzerland and the Heartbleed security vulnerability in encryption software. The 19th semi-annual report by the Reporting and Analysis Centre for Information Assurance MELANI highlights these and other incidents.

13 April 2014

Semi annual report 2013/2

Blackmail using malware is not only on the rise, but is becoming extremely malicious. In September 2013 the malware «Cryptolocker» was detected for the first time. It encrypts all data stored on the computer and thereby blackmails its victims to make payments. This, as well as other common incidents of customer and credit card data theft, the newest revelations surrounding the NSA, Bitcoin and tampering with industrial control systems, are the main focus of the MELANI Report for the second half of 2013.

23 October 2013

Semi annual report 2013/1

The biggest DDoS attack in the history of the Internet, e-banking attacks using smartphone trojans and numerous targeted espionage attacks all constitute the focus of the 17th semi-annual report by the Reporting and Analysis Centre for Information Assurance (MELANI).

24 April 2013

Semi annual report 2012/2

Increasingly sophisticated methods of phishing to attack e-banking accounts; massive DDoS attacks on US banks; the latest on cyber conflict in the Middle East; and the information we do not know we are revealing while surfing the net: these are the focus areas of the second semi-annual report for 2012 from the Reporting and Analysis Centre for Information Assurance (MELANI).

15 October 2012

Semi annual report 2012/1

The main topics covered include the multiplication of data theft incidents affecting SMEs, the hampering of client communication by phishing attacks, the cyber component of the Middle East conflict and the plans for cooperation on information security at national and international level.

3 May 2012

Semi annual report 2011/2

In the second half of 2011, the Reporting and Analysis Centre for Information Assurance (MELANI) observed an increase in phishing attacks, attempted fraud and ransomware. Attacks from cyberspace are becoming technically more sophisticated. Human beings are still the greatest risk, however, for instance due to negligently or intentionally incorrect operation. The current semi-annual report of MELANI examines issues such as the various types of fraud and attacks occurring in the second half of 2011.

27 October 2011

Semi annual report 2011/1

In the first half of 2011, the Reporting and Analysis Centre for Information Assurance (MELANI) detected higher numbers of espionage attacks on the most diverse range of companies worldwide. The number of hacker attacks aimed at accessing sensitive data also increased. There was a massive increase in skimming cases in Switzerland. These are some of the focus areas of the latest semi-annual report.

14 April 2011

Semi-annual report 2010/2

The primary goal of cyber attacks continues to be to deny the availability of websites or to infect them with malware. In terms of motivation, a shift from pure acts of vandalism toward acts of revenge, damage to competitors, or political goals has been noted. The computer worm Stuxnet also shows that practically any system can be attacked. These are some of the focus areas of the 12th semi-annual report of MELANI.

31 October 2010

Semi-annual report 2010/1

In the first half of 2010, the number of cases of espionage and stolen data rose worldwide. Websites and networks were often hacked for this purpose. Hacking is also used to distribute malicious software or to pursue politically motivated goals. To find Swiss websites harmed in this way, the Reporting and Analysis Centre for Information Assurance (MELANI) has been employing a new tool since this year. MELANI can now also request the blocking of .ch domains for the purpose of combating misuse of Internet addresses.

28 April 2010

Semi annual report 2009/2

In its latest report, the Reporting and Analysis Centre for Information Assurance (MELANI) examines cybercriminal activities in the second half of 2009. The focus is on global information theft, politically-motivated hacking and blackmailing through the use of DDoS attacks. Cybercrime has many facets, ranging from data theft for the purposes of making money to hacking websites as a way of giving vent to political frustration. Those affected are companies, administrations and political parties. Even the federal administration has not been spared.

26 October 2009

Semi-annual report 2009/1

Supervisory control and data acquisition systems for industrial facilities and utilities are increasingly being targeted by cybercriminals. Also apparent is a shift away from attacks by way of e-mail with attachments or links toward attacks by way of "drive-by" infections of websites. These are two of the main topics of the ninth semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI). The report assesses the situation in the first half of 2009.

1 June 2009

Semi-annual report 2008/2

The spread of malicious software directed at e-banking applications and phishing attacks directed at Swiss Internet service providers continue to be a huge problem in the second half of 2008. Even the use of USB sticks as a means for possible attacks and dealing with waste data which is continually growing are topics of the eighth semi-annual report 2008 of the Reporting and Analysis Centre for Information Assurance (MELANI). The report assesses the situation in the second half of 2008.

12 October 2008

Semi-annual report 2008/1

The increase in mass hacking of websites, developments in the area of politically-motivated hacking, the risks posed by open wireless networks and the dangers involved in using social network sites: these are the topics of the seventh semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI). The report assesses the situation in the first half-year of 2008.

7 May 2008

Semi-annual report 2007/2

The human-computer interface as a point of attack, developments in espionage and data theft, and the threats emanating from botnets and distributed denial of service (DDoS) attacks: These are the topics discussed in the sixth semi-annual report of the Reporting and Analysis Centre for Information Assurance (MELANI). The report assesses the situation in the second half of 2007.

22 October 2007

Semi-annual report 2007/1

The attacks on Swiss financial institutes with the aim of unjustified enrichment and the threat of the targeted industrial espionage via the internet are the main topics of the fifth semi-annual report of the Reporting and Analysis Centre for Information Assurance. The report assesses the situation of the first half of the year 2007 in Switzerland.

29 April 2007

Semi-annual report 2006/2

Increased and more sophisticated Social Engineering, the increase in identity- and data-thefts and the newest methods of attack: These are the most important topics of the fourth semi-annual report of the Reporting and Analysis Center for Information Assurance (MELANI). The report asseses the situation of the second half of the year 2006 in Switzerland.

16 January 2007

Semi-annual report 2006/1

The recruitment of Swiss citizens for the assistance in phishing, the targeted industrial espionage against national companies and the terror discussion in the field of the internet: That are the most important topics of the third semi-annual report of the "Reporting and Analysis Centre for Information Assurance" (MELANI).

16 January 2006

Semi-annual report 2005/2

Targeted espionage attacks originating in China, phishing and pharming, and an extended assessment of cyberterrorism: These are the main topics of the second semi-annual report of the "Reporting and Analysis Centre for Information Assurance" (MELANI).

16 July 2005

Semi-annual report 2005/1

The focus areas of issue 2005/1 (January to June) are the topics of botnets, increasing organized crime, professionalization of the hacker scene and targeted espionage attacks.