Mandatory caller ID is working: Fraudulent calls from government agencies have dropped by over 75 percent

Measures to combat fraudulent calls made in the name of government agencies are proving effective: Following the expansion of the requirement to identify spoofed international calls made using Swiss numbers, reports dropped by more than 75 percent in July 2026. At the same time, the cyber threat remains high: In the first half of the year, the Federal Office for Cybersecurity (BACS) received 27,128 voluntary reports as well as 200 mandatory reports of attacks on critical infrastructure. According to the latest BACS semi-annual report, cybercriminals are also increasingly using AI for personalized attacks.

Photo: depositphotos/BrianAJackson

Calls in which scammers impersonate government officials and call from a Swiss number have been among the most frequently reported incidents to BACS in recent years. From January through June 2026, more than 400 reports were received regularly each month. With the expansion of the caller ID requirement to include cell phone numbers effective July 1, 2026, the number of reports in July fell to fewer than 100—a decline of more than 75 percent compared to previous months. The initial implementation phase in January 2026 for landline numbers had already shown an initial downward trend. Despite the decline in fraudulent calls made in the name of government agencies, the number of reports remains high, with 27,128 voluntary reports and 200 reportable cyber incidents. Fraud remains dominant as a lucrative mass-market business.

Tailoring Attacks Using AI

The report for the first half of 2026 shows that the trend toward personalization and the use of artificial intelligence (AI)—which were already discussed in the previous report—continue to advance. Classifieds platforms, targeted search engine placements, and data breaches are increasingly being used by cybercriminals to make contact with their victims, whom they target using personal, emotional, and sometimes technically sophisticated methods. Attackers systematically use AI to convey tailored, personalized content in a credible manner. Job seekers, in particular, were specifically targeted during this reporting period and lured with supposed dream jobs or investment opportunities.

Cyber Incidents at Swiss Companies

There were no major «CEO fraud» campaigns targeting schools, municipalities, or churches during this reporting period. In contrast, BACS recorded numerous reports of «Microsoft 365» phishing in the first half of 2026. The attackers took over their victims’ business email accounts and impersonated, in particular, executives and help desk staff to compromise systems or directly initiate financial transactions. The pretext of a pending security update was also increasingly used to spread malware. Reports of ransomware attacks remained steady at 79, but showed a clear trend toward diversification and fragmentation among ransomware families.

Cyber Resilience in a Politicized International Environment

In international conflicts, cyber sabotage has become a viable and increasingly overt activity for individual states. Although there have been no targeted cyber sabotage attacks against critical infrastructure to date, However, given Switzerland’s proximity to other Western countries and its economic and political interdependence, Swiss organizations must continue to prepare to maintain their resilience in an increasingly hostile cyber threat environment. A case study of an incident in Poland illustrates this issue.

200 reports submitted under the mandatory reporting requirement

Operators of critical infrastructure must report cyberattacks to the BACS within 24 hours. In the first half of 2026, the BACS received 200 reports. Most reports came from the public administration sector (19.4 %) and from companies in the IT and telecommunications industries (18.6 %). Among the reported types of attacks, hacking incidents were the most common (about 26 %), followed by the theft of access credentials (13.5 %) and reports of data breaches and DDoS attacks (12.7 % each).

Source: ncsc.admin.ch

(Visited 67 times, 1 visits today)

More articles on the topic

SECURITY NEWS

Stay informed about current security topics - practical and reliable. Receive exclusive content directly to your inbox. Don't miss any updates.

Register now!
register
You can unsubscribe at any time!
close-link