Incident Report 15 articles

Ixa Systems Ransomware Claim Exposes Swiss Security Supply Chain

TheGentlemen ransomware group claims a Swiss security integrator serving police, hospitals and prisons as a victim.

SonicWall SMA1000 Zero-Days Hit Swiss Firms in 2026

INC ransomware weaponised SonicWall SMA1000 zero-days and listed Swiss victims, turning remote-access appliances into extortion footholds.

FOITT SharePoint Breach 2026: ISA Incident Response Live

CVE-2026-56164 compromised ~200 federal accounts at FOITT. The first confirmed ISA-reportable incident in the Swiss federal IT estate tests the 24-hour clock.

Analog Devices Breach: Swiss Industrial Supplier Risk 2026

Analog Devices confirmed data exfiltration after a June breach. Swiss precision manufacturing and medtech firms must test supplier notification clauses now.

Accenture Data Breach 2026: Swiss Third-Party Risk Response

Threat actor "888" listed 35 GB of Accenture data including Azure PATs, SSH keys and source code. Swiss DORA-supervised clients must activate third-party incident playbooks.

Payload Ransomware Hits Two Swiss SMEs in One Week: 2026

Payload ransomware claimed Swiss broker ENB and automation firm Qualiflex in one week, testing ISA reporting duties and Swiss SME resilience.

AI Agent Hijacking: Instagram VIP Takeover and EU Risk 2026

Meta's Instagram AI support agent was manipulated via prompt injection to bypass MFA and hand attackers control of verified VIP accounts.

Exchange OWA CVE-2026-42897: Swiss On-Prem Alert 2026

CVE-2026-42897 exploits Exchange OWA via crafted email with no permanent patch available. Swiss on-premises deployments face active exploitation risk.

Unimed Breach: Swiss Healthcare Third-Party Risk 2026

The Unimed third-party billing breach at German university hospitals exposes 12,600 patients. Swiss hospitals face identical data concentration risk.

Akira Ransomware Hits Swiss Medical Network 3R Again 2026

Akira ransomware struck Groupe 3R's 20 imaging centres in April 2026 — the second attack in 12 months on Swiss healthcare infrastructure.

Canvas LMS Breach: Swiss Universities Data at Risk 2026

ShinyHunters stole data from 15,000 Canvas LMS institutions. Swiss universities face nDSG breach notifications and student data exposure risks.

NCSC Week 19: Business Email Compromise Wave Hits Swiss SMEs — CHF 2.3M in Confirmed Losses

The NCSC Week 19 alert documents a BEC campaign targeting Swiss SMEs in manufacturing and logistics, with CHF 2.3M in confirmed wire transfer losses.

Identity Fraud with a Swiss Face: The NCSC's Warning on Fake Company Job Scams

The NCSC's Week 12 alert documents a new tactic: cloning registered Swiss companies to post fraudulent job ads and harvest applicants' data.

The HTML Invoice Trap: Anatomy of the Phishing Campaign Targeting Swiss Companies Right Now

The NCSC's Week 11 alert covers a live campaign hitting Swiss companies: fake invoice ZIPs with HTML credential stealers and CAPTCHA evasion.

Spear Phishing in Swiss Finance: Anatomy of a 2025 Campaign

A spear phishing campaign targeting Swiss wealth managers used impersonated correspondence from Swiss financial regulators.