Cyberattack
Disconnect affected devices from the network immediately, do not open suspicious links or attachments and do not pay ransomware demands. Report the incident to the Federal Office for Cybersecurity (NCSC), for criminal matters to police on 117. Stay calm and switch to official information channels such as radio.
A cyberattack is the deliberate disruption or takeover of IT and control systems. Common forms are ransomware (encryption of data with extortion, often combined with data theft), DDoS (overload so that services are no longer reachable) and supply-chain attacks (via software or third-party providers). Some attacks act within seconds, others go unnoticed for weeks before striking.
When critical infrastructure is hit, the population feels it directly: public services go down, hospitals have to switch to paper, payments, communication or administrative systems come to a standstill. In Switzerland the Federal Office for Cybersecurity (BACS) is responsible; it has existed as an independent federal office since 1 January 2024. For operators of critical infrastructure a reporting obligation has applied since 1 April 2025: cyberattacks must be reported within 24 hours.
Private individuals are not helpless. Anyone who regularly makes offline backups, enables two-factor authentication, installs updates and can recognise phishing is far better protected. A small cash reserve helps if payment systems are temporarily down.
Risk rating
Likelihood: High · Impact: Medium → Overall risk: High.
| Impact | |||
|---|---|---|---|
| Low | Medium | High | |
| High | This hazard's rating | ||
| Medium | |||
| Low | |||
Legend: Low (green) · Medium (yellow) · High (red). Overall risk is likelihood multiplied by impact.
Attacks on critical infrastructure can paralyse public services, hospitals, payments and communications. Offline backups, two-factor authentication and some cash make you resilient.
Immediate measures
- If suspected: disconnect the affected device from the network
- Do not open links/attachments from unexpected emails
- Back up important data offline regularly (3-2-1 rule)
Warning signs
- Unexpected lock screens or extortion messages (ransomware)
- Services of banks, authorities or hospitals fail or are slow
- Suspicious emails/SMS with links, attachments or payment requests (phishing)
- Unknown logins or activity in your own accounts
- Official warnings from BACS or operators
Before · During · After
Before
- Create offline backups of important data (3 copies, 2 media, 1 off-site)
- Enable two-factor authentication, use strong and unique passwords
- Install updates for devices and programs promptly
- Learn to recognise phishing; keep a small cash reserve
During
- Disconnect affected devices from the network, do not pay any ransom
- Report the incident: BACS and – in case of crimes – the police
- Switch to official information channels (radio, authorities)
- If payment systems fail, use the cash reserve
After
- Change passwords, monitor accounts and account movements
- Restore systems from a clean backup
- Learn from the incident: improve backups and protective measures
This really happened
-
2023 Data theft at Xplain
In a ransomware attack on the IT service provider Xplain in 2023, large amounts of data were stolen and published on the darknet. Sensitive data of the federal administration was also affected – one of the largest data leaks at the federal level.
Source -
2023 Pro-Russian DDoS attacks on the federal government
In June 2023 the pro-Russian group NoName temporarily took several federal and Swiss Federal Railways (SBB) websites offline with DDoS attacks — in response to parliamentary decisions and the Ukrainian president's address to the National Council.
Source -
2023 Cyberattack on the University of Zurich
In February 2023 the University of Zurich was the target of a multi-day major cyberattack; in the same period around a dozen universities in the region were affected.
Source -
2020 Ransomware attack on Stadler Rail
In May 2020 the rolling-stock manufacturer Stadler Rail was attacked with malware; the perpetrators demanded 6 million US dollars in ransom. Stadler did not pay, which led to stolen data being published.
Source
Frequently asked questions
How do I protect myself in advance against a cyberattack?
Create offline backups of important data following the 3-2-1 rule: three copies, two different media, one off-site. Enable two-factor authentication, use strong unique passwords and install updates promptly. Learn to recognise phishing and keep a small cash reserve.
What consequences can a cyberattack have for the population?
If it hits critical infrastructure, the population feels it directly: government services fail, hospitals switch to paper, payment traffic and communications can stop. Common attack forms are ransomware (encryption with extortion), DDoS (overload) and supply-chain attacks. A small cash reserve helps if payment traffic fails temporarily.
Where do I report a cyberattack in Switzerland?
The competent authority is the Federal Office for Cybersecurity (NCSC), which has existed as an independent federal office since 1 January 2024; incidents can be reported there. If it is a criminal matter, also alert police on 117. For operators of critical infrastructure, a reporting obligation has applied since 1 April 2025: cyberattacks must be reported within 24 hours.
Official sources
- BACS Federal Office for Cybersecurity: report & protect
- Alertswiss Current notices
- Police In case of crimes
- Disinformation Cyber operations and information manipulation often go hand in hand
- Payment System Failure When cashless payment stops