Skip to main content

Press releasePublished on 24 August 2026

Mandatory caller ID is proving effective: Fraudulent calls made in the name of public authorities have fallen by over 75 per cent

Bern, 24.08.2026 — Measures to combat fraudulent calls made in the name of public authorities are proving effective. The number of reports fell by over 75 per cent in July following the extension of the mandatory caller ID requirement to calls from abroad that use spoofed Swiss numbers. Nevertheless, the threat of cybercrime remains high: in the first half of 2026, the National Cyber Security Centre (NCSC) received 27,128 voluntary reports and 200 mandatory reports of attacks on critical infrastructure. The latest NCSC semi-annual report also highlights how cybercriminals are using AI to carry out increasingly personalised attacks.

Calls in which fraudsters pose as officials calling from a Swiss number have been among the most frequently reported incidents to the NCSC in recent years. From January to June 2026, more than 400 reports were received regularly every month. With the extension of the caller ID requirement to mobile phone numbers on 1 July, the number of notifications in July fell to under 100 – a drop of more than 75 per cent compared with previous months. The initial roll-out phase for landline numbers in January had already shown the first signs of a downward trend. Despite the decline in fraudulent calls made in the name of public authorities, the number of reports remain high, with 27,128 voluntary reports and 200 reportable cyberincidents. Fraud remains a dominant and lucrative mass market business.

Attacks personalised using AI

The 2026 semi-annual report shows that the trend towards personalisation and the use of artificial intelligence (AI) – which were already highlighted in the previous report – are continuing to gain momentum. Classifieds platforms, targeted search engine rankings and data breaches are increasingly being used by cybercriminals to make contact with their victims, whom they target using personal, emotional and – in some cases – technically sophisticated methods. Attackers are systematically using AI to make tailored, personalised content appear credible. Jobseekers, in particular, were specifically targeted during this reporting period and lured with seemingly dream jobs or investment opportunities.

Cyberincidents at Swiss companies

There were no major ‘CEO fraud’ campaigns targeting schools, communes or churches during this reporting period. By contrast, the NCSC recorded numerous reports of ‘Microsoft 365’ phishing in the first half of 2026. The attackers took control of their victims' business email accounts and, in particular, impersonated senior managers and helpdesk staff in order to compromise systems or directly initiate financial transactions. The pretext of a pending security update has also been increasingly used to distribute malware. The number of ransomware attacks reported remained stable at 79, but showed a clear trend towards diversification and fragmentation among ransomware families.

Cyber resilience in a politicised international environment

In international conflicts, cybersabotage has become a viable and increasingly overt form of activity for individual states. Admittedly, there have been no targeted cybersabotage attacks against critical infrastructure to date. However, given Switzerland’s close ties with other Western countries and its economic and political interdependence, Swiss organisations must continue to focus on maintaining their resilience in the face of an increasingly hostile environment of cyberthreats. A case study of an incident in Poland illustrates this issue.

200 reports submitted under the reporting obligation

Operators of critical infrastructure must report cyberattacks to the NCSC within 24 hours. In the first half of 2026, the NCSC received 200 such reports. Most reports come from the public administration sector (19.4 per cent) and companies in the IT and telecommunications sectors (18.6 per cent). In terms of the types of attacks reported, hacking incidents accounted for the largest share (around 26 per cent), followed by login data theft (13.5 per cent) and data breaches and DDoS attacks (12.7 per cent each).