Decoding the world of cybersecurity

Swiss cyber reporting exposes enterprise attack patterns

Switzerland received 200 mandatory critical-infrastructure cyber reports in the first half of 2026, alongside rising Microsoft 365 phishing and persistent ransomware activity.

Swiss cyber reporting exposes enterprise attack patterns
Summary
  • Switzerland’s NCSC received 27,128 voluntary reports and 200 mandatory critical-infrastructure incident notifications in the first half of 2026.
  • Public administration, IT and telecommunications accounted for large shares of mandatory reporting.
  • Microsoft 365 phishing, helpdesk impersonation and executive impersonation featured prominently in incidents affecting organisations.

Switzerland received 200 mandatory reports of cyber incidents affecting critical infrastructure during the first half of 2026, giving regulators an early view of the threat patterns emerging since compulsory reporting came into force.

Switzerland’s National Cyber Security Centre said it also received 27,128 voluntary reports during the six-month period, with the overall volume of notifications stabilising at a high level.

The mandatory reports offer a more focused view of organisational exposure. Public administration accounted for 19.4% of notifications under the reporting obligation, while IT and telecommunications organisations accounted for 18.6%. Hacking incidents represented roughly 26% of the reported attack types, followed by theft of login credentials at 13.5%. Data breaches and distributed denial-of-service attacks each accounted for 12.7%.

Those figures sit alongside a broader pattern of identity-led compromise. The NCSC recorded numerous reports involving Microsoft 365 phishing, where attackers gained control of business email accounts and then used the access for further phishing or fraud.

Attackers also impersonated IT helpdesk staff and senior managers in attempts to manipulate employees into compromising systems or authorising financial transactions. Security updates were increasingly used as a pretext for malware delivery, while compromises of popular open-source projects created another route for distributing credential-stealing software.

Ransomware remained persistent rather than accelerating sharply. The NCSC recorded 79 reported or observed Swiss ransomware cases during the first half, broadly stable against the previous period, while noting continued fragmentation among ransomware families.

The reporting figures provide an early indication of what mandatory disclosure can add to national cyber visibility. Voluntary reporting will naturally capture a broad mixture of fraud, attempted compromise and individual complaints. A requirement applying specifically to critical infrastructure creates a second dataset weighted towards incidents with organisational and operational significance.

That distinction becomes more important as European governments expand mandatory incident reporting through national legislation and sector rules. The usefulness of those regimes will depend not simply on collecting more notifications but on whether authorities can turn them into a reliable picture of attack types, affected sectors and recurring control failures.

The Swiss data already indicates that credential theft and business identity remain central to that picture. Microsoft 365 compromise, helpdesk impersonation and executive impersonation do not depend on exotic technical capabilities. They target authentication and organisational trust, often creating a path into services that businesses have moved into cloud environments precisely because those platforms are easier to operate centrally.

The same report also points to a more industrialised fraud environment. The NCSC said attackers are systematically using artificial intelligence to create more tailored and credible material, including approaches built around job offers, investments and information drawn from breaches or online platforms.

Switzerland has separately seen a sharp fall in fraudulent calls made using spoofed Swiss numbers after extending caller-identification requirements to calls from abroad. Reports dropped by more than 75% in July, according to the NCSC, illustrating how changes in telecommunications controls can reduce one established fraud channel even while attackers shift towards more personalised methods elsewhere.

The first six months of mandatory reporting therefore show both the scale and the composition of cyber incidents reaching Swiss authorities. The figures do not represent every attack against the country, but they provide a developing benchmark for how critical infrastructure operators are being affected and what organisations are choosing — or are now required — to disclose.

×