Phone fraud in Switzerland: Fake police calls down 75 per cent

Federal measures against spoofing are showing results: reports of fraudulent calls fell below 100 in July. AI makes cyber-attacks more dangerous according to the 2026 half-yearly report.

Phone fraud in Switzerland: Fake police calls down 75 per cent

Federal measures against spoofing taking effect – cybercrime remains at high level

Fraudulent calls from alleged police officers, customs officials or bank staff have plummeted by 75 per cent in Switzerland in July. This is reported by SRF on the basis of the 2026 half-yearly report from the Federal Office of Cybersecurity (Bacs). Before the most recent expansion of countermeasures, Bacs received more than 400 reports of phone fraud monthly – in July it was under 100.

Since July, the obligation to identify foreign calls has also applied to mobile phone numbers. Telecommunications providers must label forged Swiss numbers as "unknown" or "anonymous", which is intended to prompt those called to exercise heightened caution. This measure appears to have worked.

Nevertheless, the number of malicious activities in the digital space overall has stagnated at a high level, Bacs reports. Fraud remains a lucrative mass-market business, said Florian Schütz from the Federal Office of Cybersecurity.

Hacking attacks dominate critical infrastructure reports

Operators of critical infrastructure have been required since this year to report cyber-attacks to Bacs within 24 hours. In the first half of 2026, 200 such reports were received. Around a quarter of these involved hacking attacks: criminals gain access to digital systems and use cracked email accounts for phishing and further fraud attempts. Also reported were stolen access credentials, websites disabled by overload attacks, and data breaches and extortion attempts involving malware.

AI makes fraud schemes more personal and harder to detect

Cyber-fraud often begins on advertising platforms or following data breaches, according to Bacs. With the help of artificial intelligence, cybercriminals are increasingly making their contact with victims more personal, emotional and technically sophisticated.

Particularly targeted: job seekers. In the first half of 2026, attackers used fake recruitment processes to deceive individuals and companies. People in IT and management positions were offered supposed dream jobs or lucrative investment opportunities. Using manipulative methods, the alleged recruiters stole cryptocurrencies worth millions.

Bacs' antiphishing.ch platform registered over 9,000 phishing reports. Dominant amongst these is voice phishing: criminals call or leave voice messages to steal sensitive data or money.

Polish energy companies as warning signal for critical infrastructure

At the end of 2025, several Polish energy and industrial companies were attacked through coordinated cyber-operations. The attackers exploited simple security gaps: missing multi-factor authentication, standard passwords or repeatedly used passwords. Some attacks were thwarted by existing security solutions.

Bacs draws a clear conclusion from this: highly sophisticated attack techniques are not needed to endanger critical infrastructure. Strong passwords and multi-stage login procedures (MFA) are essential for operators of critical installations.

Twint phishing and malicious email attachments on the rise

Twint phishing has also increased significantly according to Bacs, for instance via adverts on platforms such as Ricardo or Tutti. For companies, the threat from malicious email attachments is also growing: staff members receive messages with dangerous documents or links that can circumvent security measures.

Source: SRF

Read this article in the original language