RearmRadar
Get the brief
Context · CH federal · Switzerland

Mandatory caller ID is proving effective: Fraudulent calls made in the name of public authorities have fallen by over 75 per cent

Federal Office for Cybersecurity (BACS/NCSC) · published 24 Aug 2026 · auto-extracted, not yet reviewed · Source ↗

Deadline
Budget / value
Statusunknown
CyberAI / MLAirInfrastructure & protection

Summary

Measures to combat fraudulent calls made in the name of public authorities are proving effective. The number of reports fell by over 75 per cent in July following the extension of the mandatory caller ID requirement to calls from abroad that use spoofed Swiss numbers. Nevertheless, the threat of cybercrime remains high: in the first half of 2026, the National Cyber Security Centre (NCSC) received

Source text (raw, may be non-English)
Measures to combat fraudulent calls made in the name of public authorities are proving effective. The number of reports fell by over 75 per cent in July following the extension of the mandatory caller ID requirement to calls from abroad that use spoofed Swiss numbers. Nevertheless, the threat of cybercrime remains high: in the first half of 2026, the National Cyber Security Centre (NCSC) received 27,128 voluntary reports and 200 mandatory reports of attacks on critical infrastructure. The latest NCSC semi-annual report also highlights how cybercriminals are using AI to carry out increasingly personalised attacks.

Calls in which fraudsters pose as officials calling from a Swiss number have been among the most frequently reported incidents to the NCSC in recent years. From January to June 2026, more than 400 reports were received regularly every month. With the extension of the caller ID requirement to mobile phone numbers on 1 July, the number of notifications in July fell to under 100 – a drop of more than 75 per cent compared with previous months. The initial roll-out phase for landline numbers in January had already shown the first signs of a downward trend. Despite the decline in fraudulent calls made in the name of public authorities, the number of reports remain high, with 27,128 voluntary reports and 200 reportable cyberincidents. Fraud remains a dominant and lucrative mass market business.
Attacks personalised using AI
The 2026 semi-annual report shows that the trend towards personalisation and the use of artificial intelligence (AI) – which were already highlighted in the previous report – are continuing to gain momentum. Classifieds platforms, targeted search engine rankings and data breaches are increasingly being used by cybercriminals to make contact with their victims, whom they target using personal, emotional and – in some cases – technically sophisticated methods. Attackers are systematically using AI to make tailored, personalised content appear credible. Jobseekers, in particular, were specifically targeted during this reporting period and lured with seemingly dream jobs or investment opportunities.
Cyberincidents at Swiss companies
There were no major ‘CEO fraud’ campaigns targeting schools, communes or churches during this reporting period. By contrast, the NCSC recorded numerous reports of ‘Microsoft 365’ phishing in the first half of 2026. The attackers took control of their victims' business email accounts and, in particular, impersonated senior managers and helpdesk staff in order to compromise systems or directly initiate financial transactions. The pretext of a pending security update has also been increasingly used to distribute malware. The number of ransomware attacks reported remained stable at 79, but showed a clear trend towards diversification and fragmentation among ransomware families.
Cyber resilience in a politicised international environment
In international conflicts, cybersabotage has become a viable and increasingly overt form of activity for individual states. Admittedly, there have been no targeted cybersabotage attacks against critical infrastructure to date. However, given Switzerland’s close ties with other Western countries and its economic and political interdependence, Swiss organisations must continue to focus on maintaining their resilience in the face of an increasingly hostile environment of cyberthreats. A case study of an incident in Poland illustrates this issue.
200 reports submitted under the reporting obligation
Operators of critical infrastructure must report cyberattacks to the NCSC within 24 hours. In the first half of 2026, the NCSC received 200 such reports. Most reports come from the public administration sector (19.4 per cent) and companies in the IT and telecommunications sectors (18.6 per cent). In terms of the types of attacks reported, hacking incidents accounted for the largest share (around 26 per cent), followed by login data theft (13.5 per cent) and data breaches and DDoS attacks (12.7 per cent each).

Related

Funding call UKDI · UK · deadline 22 Sep 2026 (28d) · €1.2m
UK Defence Innovation (incl. former DASA) · Cyber
This UKDI Themed Competition seeks innovative, cost competitive proposals that are designed for manufacture and scalable in twelve-months. Introduction This UK Defence Innovation (UKDI) themed competition is looking for …
Tender · Denmark · deadline 17 Sep 2026 (23d) · €3.2m
Statens It · Cyber
Med henblik på at beskytte Statens IT (Ordregiver) mod aktuelle og fremtidige cybertrusler anvender Ordregiver en række sikkerhedsteknologier, herunder en Extended Detection and Response (XDR)-platform. XDR-platformen un…
Context UKDI · UK
UK Defence Innovation (incl. former DASA) · Dual-use industrialCyberOther
Process guidance rather than an opportunity, but it sets the mechanics every UKDI applicant must clear — notably that SAQ/cyber compliance gates contract award and that Desirable/Feasible/Viable answers submitted as attachments are sifted out. Relevant to bid managers and consultants preparing UK MOD innovation bids for the first time. Do: Register a UKDI online submission service account, obtain a D-U-N-S number and GOV.UK One Login, and pre-complete the Supplier Assurance Questionnaire before your next UKDI competition deadline.
Award · Poland · €2.3m
Centrum Zasobów Cyberprzestrzeni Sił Zbrojnych · Secure commsCyber
CZCSZ is Poland's central buyer for military ICT and repeatedly procures routers and node equipment, here via Polish integrators/resellers rather than vendors directly. Relevant to tactical/industrial networking hardware makers and secure-comms integrators wanting a Polish channel partner. Do: Approach Axians IT Solutions Poland or EFAB as a channel/subsystem partner for ruggedised routers and monitor CZCSZ notices on the Polish e-Zamówienia portal for the next tranche.
Award · Romania · €31.8m
Serviciul de Telecomunicatii Speciale · Secure commsInfrastructure & protectionCyber
STS is Romania's state operator for secure/critical government and defence communications, and this framework locks in three domestic integrators as call-off channels for switch hardware through the framework period. Relevant to network equipment vendors and secure-networking SMEs without a Romanian entity, who will need to sell through these resellers. Do: Contact ARCTIC STREAM and DATANET SYSTEMS as the dominant framework holders to position your switching/secure-networking products for STS call-off contracts.
Context CH federal · Switzerland
Swiss Federal Council · CyberDual-use industrial
The report names ISMS rollout, tool harmonisation, legacy-system replacement and supplier management as priorities, signalling future Swiss federal IT-security spend and stricter supply-chain security requirements. Relevant to cyber/GRC software vendors and IT security service SMEs with Swiss presence, and to any supplier bidding into federal ICT contracts. Do: Track FS BIS/SEPOS and DigiSec-related publications on simap.ch and align your ISO 27001/ISMS and supply-chain-security evidence for upcoming Swiss federal ICT tenders.

Source: Swiss federal News Service (admin.ch), press release vzO9wG1V7K0D-m73EJw8W. Enrichment: heuristic (confidence 40%).