Cyberattacks in Switzerland Rose by 35 Percent in July

In July, the number of cyberattacks in Switzerland averaged 1,489 per company per week, representing a 35 percent increase from the previous year. Ransomware attacks doubled year-over-year, and the number of cyber threats also rose in July 2026.

Image: depositphotos/ryanking999

Check Point Research, the threat intelligence division of Check Point Software Technologies Ltd., has released its «Global Threat Intelligence» findings for July 2026. The cyber threat landscape in July deteriorated in several areas. The global volume of attacks continued to rise, and ransomware activity deviated from the relatively stable pattern observed at the beginning of the year. In addition, risks associated with GenAI became more apparent than operational risks. Across the enterprise, AI tools are being used more frequently and more prompts are being generated, mostly without appropriate governance.

In a comparison with Austria and Germany, Switzerland ranks in the middle of the pack. In Switzerland, organizations faced an average of 1,489 attacks per week, representing a 35 percent increase. In contrast, while Austria recorded 2,314 attacks per week per organization—a higher number—the baseline level has always been high, so the year-over-year growth rate of 34 percent is slightly lower. In Germany, 1,723 cyberattacks per week were recorded, representing a 40 percent increase.

«Once again, we saw an increase in attacks on Swiss organizations, and the headlines about the victims speak for themselves. Phishing and ransomware, in particular, are among the most common attack techniques. »Our data shows that in July, cybercriminals primarily targeted government agencies, hospitals, medical technology companies, and retail businesses,” explains Marco Pierro, Country Manager for Switzerland at Check Point Software.

Attacks by Industry.png
Cyberattacks by Industry (Source: Check Point Research 2026)

The education sector remains the hardest-hit industry, while the energy and hospitality sectors saw growth

In July, the education sector remained the hardest-hit industry worldwide, with an average of 4,848 attacks per week per organization, representing a 14 percent increase over the previous year. It was followed by the public sector with 3,044 attacks and the telecommunications industry with 2,927 attacks, while the number of attacks on the energy and utilities sector rose by 20 percent to 2,759, and the hospitality, travel, and leisure sector, with 2,614 attacks (an increase of 28 %), made it into the top 5 for the first time.

Europe is seeing a sharp rise in cyberattacks

Overall, Europe stood out in a continental comparison due to its sharp increase in cyberattacks: The number rose by 18 percent compared with the previous year to 2,051 attacks per week per company, while in North America it increased by 9 percent to 1,613.

GenAI risks are evolving from theory to an everyday business risk

Risks associated with GenAI have become an everyday business issue: One in every 36 prompts posed a high risk of sensitive data loss. 88 percent of companies that regularly use GenAI were affected by high-risk prompts. Twenty-two percent of prompts contained potentially sensitive information. Companies used an average of eight GenAI tools, with users generating an average of 95 prompts. Personal data was the most common category of leaked sensitive data, appearing in 70 percent of the cases examined, followed by financial data and network and IT infrastructure, each at 68 percent.

GenAI Risk by Industry.png
GenAI Risks by Industry (Source: Check Point Research 2026)

Emails remain a key entry point for cyber risks

Email remained a high-risk channel with a high volume of traffic: One in every 128 emails was classified as phishing. This figure underscores the role of email as a common starting point for the theft of login credentials, the spread of malware, and business email compromise.

Omer Dembinsky, Data Research Manager at Check Point Research, explains: «The data from July shows that cyber risks are mounting on multiple fronts simultaneously. The volume of attacks continues to rise, ransomware has increased significantly, and the threat posed by GenAI is now part of day-to-day business operations. Companies need proactive, AI-driven security that protects networks, users, data, and AI workflows before attacks can have an impact.»

Email Phishing by Region.png
Email Phishing by Region (Source: Check Point Research 2026)

Number of Reported Ransomware Victims Skyrockets

The most significant change in July was seen in ransomware. The number of reported attacks rose to 964. In percentage terms, this represents a 49 percent increase compared to June and an 87 percent increase compared to July 2025. This marks a significant departure from the first half of 2026, when monthly ransomware activity averaged around 672 incidents. The «Business Services» sector remained the hardest hit, accounting for 32 percent of reported victims, followed by «Manufacturing» at 14 percent and «Consumer Goods and Services» at 13 percent.

Ransomware Global Trend.png
Trends in Ransomware Victims (Source: Check Point Research 2026)

 

North America remained the hardest-hit region, accounting for 45 percent of reported ransomware incidents, followed by Europe with 28 percent. The business of encryption and extortion software therefore remains as lucrative as ever.

Ransomware by Region.png
Distribution of Ransomware Victims by Region (Source: Check Point Research 2026)

«The Gentlemen» and «Qilin» are the most active ransomware groups

«The Gentlemen» and «Qilin» were the most active ransomware groups in July, each accounting for 14 percent of reported attacks. «DeadLock» ranked third with 10 percent and 97 reported victims, highlighting the ongoing shifts in the ransomware ecosystem.

«The sharp rise in cyberattacks continues unabated, and one major factor remains despite all efforts: ransomware. Among the most active groups in July were «the Gentlemen» and «Qilin.» The «Gentlemen» group specifically targets internet-connected devices (VPNs, firewalls) as entry points and, once it gains access, encrypts the entire network within a few hours. Partners affiliated with the RaaS group Qilin are known for employing double extortion tactics,» explains Patrick Fetter, Lead Sales Engineer & Cyber Security Evangelist at Check Point Software.

Source: Checkpoint

(Visited 105 times, 1 visits today)

More articles on the topic

SECURITY NEWS

Stay informed about current security topics - practical and reliable. Receive exclusive content directly to your inbox. Don't miss any updates.

Register now!
register
You can unsubscribe at any time!
close-link