In this semi-annual report, the National Cyber Security Centre (NCSC) presents the relevant incidents and developments in the context of cyberthreats against Switzerland and internationally. During the second half of 2025, the NCSC received 29,006 voluntary and 145 mandatory reports of cyber incidents. Of the reports received, 52% were classified as fraud; however, the number of fraudulent threat calls made in the name of authorities, which had dominated since mid-2023, declined significantly. While the core cyberthreat phenomena in Switzerland remained largely unchanged, the reporting period saw notable developments in how these threats were implemented and combined.
Phishing campaigns tailored to Switzerland
Cybercriminals continued to carry out voice phishing ('vishing') and real-time phishing campaigns via fraudulent search engine advertisements. At the same time, more sophisticated and highly targeted approaches emerged, incorporating Swiss-specific features such as loyalty points programmes. Additionally, attackers increasingly relied on double phishing, exploiting a recent successful phishing incident to defraud its victims a second time over the phone. From summer 2025 onwards, criminals began using SMS blasters in Switzerland for the first time, enabling them to bypass the filtering mechanisms deployed by telecommunications providers to curb text message phishing.
Ransomware: A constant and serious threat
Ransomware and the associated extortion of stolen data continue to pose an opportunistic threat to all types of organisations in Switzerland. Akira was already the leading ransomware strain in Switzerland in the first half of 2025 and further intensified its activities during the reporting period. A key contributing factor was the exploitation of SonicWall devices, as corrective measures issued by the manufacturer following a vulnerability disclosed in 2024 were not consistently implemented by all affected organisations.
Attacks on international software supply chains
In the second half of 2025, many Swiss organisations were affected by vulnerabilities in widely used software products and compromises involving well-established, widely used components in open-source software (OSS). For example, in the context of the two Shai-Hulud campaigns in September and November 2025, more than a thousand npm (Node Package Manager) packages with monthly download figures in the hundreds of millions were infected. Such complex technical dependencies place significant demands on those responsible for IT security, as a vulnerability in these software libraries can potentially expose all applications incorporating the affected component in their code.
ORB networks in Switzerland
The number of compromised devices being used in covert Operational Relay Box (ORB) networks continues to grow. These networks usually comprise internet-connected devices (Internet of Things, IoT) and routers that have been infected with malware. These devices are then used to carry out various types of attack, while also undermining the privacy of their owners. As a result, a significant number of devices belonging to individuals and organisations in Switzerland have been misused to carry out attacks against third-party targets. For this reason, regularly updating devices exposed to the internet is key to combatting such networks. As early as 2024, international observations showed that state-supported actors were also using infrastructures such as ORB networks for espionage and sabotage activities.
Further sections of the semi-annual report examine observations and developments relating to malware, attacks affecting the availability of websites and web services, data management, as well as cyber espionage and sabotage. Despite an increasingly tense geopolitical environment, the impact of the cyberthreat landscape on Switzerland remains relatively stable overall, and cyber resilience can be assessed as largely robust.
Your opinion matters to us!
We would like to know your opinion on the content of the current semi-annual report, so that we can better adapt such products to your needs in the future. Therefore, we would be grateful if you could reply to the following questions (about 2 minutes). You can then send us the form by clicking on the "Submit" button.
The questionnaire is anonymous and personal information such as your age or profession are only aimed to understand the needs of each target audience. But you can leave your email address should you have any questions or comments which you would like us to follow up upon. We are looking forward to reading your thoughts and comments.
Last modification 30.03.2026