Businesses
Fraud and cyberattacks against businesses
In a company, fraud often plays out within a few hours and involves management, the accounts department, IT and the bank at the same time. This page is written for those who then have to decide quickly and is kept brief. More detailed pages are available in French.
If a fraudulent transfer has just gone out
Call the bank at once, on a number you already know, and ask it to recall the payment and to alert the receiving bank, then have the request confirmed in writing. A payment can sometimes be recovered as long as it has not been credited or the funds have not been withdrawn, and much more rarely afterwards.
The first 24 hours
- Appoint one person to coordinate the response, who centralises decisions and keeps a time-stamped log of what is done, by whom and at what time.
- Disconnect the affected computers and servers from the network without reinstalling or erasing anything, since the traces left by the attack also serve as evidence.
- From a clean device, change the passwords of the compromised accounts, starting with email and online banking, and close any open sessions.
- Keep the fraudulent emails with their full headers, the system logs, the bank statements and the exchanges with the attacker, working on copies and changing nothing.
- Do not reply to the attacker and pay nothing until the legal and practical consequences of a payment have been weighed.
For most companies, reporting a cyberattack to the National Cyber Security Centre (NCSC) remains voluntary. It is mandatory, however, for the authorities and organisations listed in art. 74b of the Information Security Act (ISA), among them banks and insurers, energy suppliers, hospitals on a cantonal list, telecommunications providers, licensed transport companies, higher education institutions, and cloud computing providers and data centres with their registered office in Switzerland. These organisations report a cyberattack where it endangers the functioning of the infrastructure, leads to the manipulation or leakage of information, went undetected for a long time or is accompanied by blackmail, threats or coercion (art. 74d ISA). They have 24 hours from detection to do so (art. 74e ISA). Where not all the necessary information is known within that time, the NCSC grants 14 days to complete the report (art. 16 of the Cybersecurity Ordinance). The fine of up to CHF 100,000 under art. 74h ISA applies to anyone who wilfully fails to comply with a final decision that the NCSC has served on them under threat of that fine.
Organisations subject to the duty preferably report through the NCSC's Cyber Security Hub, which allows the information to be shared with other authorities, or, if they have no access to it, through the reporting button on the NCSC website or the email template it provides. Other companies report voluntarily through the NCSC's online form, and the Confederation's SME portal recommends reporting any incident, even one that caused no significant harm or was merely an attempt.
Where personal data is affected and the breach is likely to result in a high risk for the people concerned, the controller notifies the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible, using the online form the FDPIC provides (art. 24 of the Federal Act on Data Protection, FADP), and also informs the people concerned where this is necessary for their protection.
According to NCSC, how to report (in French), NCSC, report to the NCSC (in French), SME portal of the Confederation, cybersecurity and FDPIC, DataBreach (in French).
A criminal complaint is filed with the police or the Office of the Public Prosecutor, in writing or orally (art. 304 of the Criminal Procedure Code, CrimPC), and it is the criminal proceedings that allow the funds which passed through accounts to be seized (art. 263 CrimPC). Check the company's insurance policy as well, since cyber cover often requires prompt notification and provides an assistance line.
Management takes the decisions, while the head of IT or a specialist provider contains the attack and documents what happened, the bank deals with the payments and the insurer is notified. Where funds have gone out, personal data is at stake or an employee may be implicated, a lawyer can prepare the complaint and request seizures. If the company's mailbox has been compromised, warn the customers and suppliers with whom exchanges were under way without delay and through another channel, and confirm your bank details to them. The Confederation's SME portal recommends informing partners so that the damage does not spread, particularly where the attackers may have obtained passwords or other information they could exploit.
Some precautions are best taken before any incident. It sometimes happens that a company's account with a cloud provider is hijacked to run computing services without its knowledge, and the bill then rises very quickly. Budget alerts warn without blocking anything, so quotas and restricted access keys limit this risk more effectively.
CEO fraud and fake IBAN changes
In CEO fraud, a message or call that appears to come from the chief executive, or sometimes from a lawyer or an auditor, announces a confidential transaction and insists that the payment go out the same day without anyone else being told. The voice can be imitated, and a video call can be faked as well. In May 2024, the press reported that in Hong Kong an employee of an engineering group had made fifteen transfers totalling 200 million Hong Kong dollars, about 25.6 million US dollars, after a video conference in which the chief financial officer and other colleagues were imitations generated by artificial intelligence. The company confirmed that fake voices and images had been used.
According to CNN, 16 May 2024.
The same year, the NCSC described the case of a supposed lawyer who telephoned a company's head of finance and invited him to a video conference with his superior a few minutes later. The video of the boss shown to him had been manipulated, the face having been recreated from publicly available footage.
According to NCSC, 9 April 2024.
In a fake IBAN change, a regular supplier announces new bank details, sometimes from its own hacked mailbox and in the middle of a genuine exchange, and the invoice may be authentic, differing from the previous one only in the account number.
The number of CEO fraud cases reported to the NCSC rose from 719 in 2024 to 971 in 2025. The fraudsters work out the hierarchy, responsibilities and absences from professional social networks, the company's website and the commercial register, then write from a domain name that differs from the real one by a slight misspelling, a practice known as typosquatting.
According to NCSC, 27 January 2026.
A written payment procedure costs little, although it works only if it is applied without exception, and the NCSC recommends that everything relating to payments be clearly regulated internally. Every payment and every change to master data, such as a supplier's new IBAN, requires joint signature or the approval of a second person under the four-eyes principle. A payment request received by email, particularly one described as urgent or confidential, is verified through a second channel by calling the sender on a number you already know rather than the one given in the message. The procedure allows no exception for management, and a call or video conference with an executive that ends in a payment request follows it like any other.
The mail server can be set up so that emails from external senders carry a visible marker in the subject line or the body, so that a message imitating an executive's address shows up as external. The people who make payments, deputies included, are trained in these frauds, starting with recent recruits, whom fraudsters often target. The company website should publish no more about staff than is strictly necessary, videos included, and show email addresses only where needed. The first payment to a new account is made after a set waiting period.
According to NCSC, CEO fraud, NCSC, 27 January 2026 and NCSC, 9 April 2024.
If the transfer has already gone, warn the supplier through a channel you know, since its mailbox may be compromised. A transfer obtained by posing as an executive or a supplier may amount to fraud (art. 146 of the Swiss Criminal Code, SCC), which is prosecuted ex officio, so that the three-month time limit for offences prosecuted on complaint (art. 31 SCC) does not apply. It is still advisable to file a criminal complaint without delay, since the complaint makes the company a private claimant (art. 118(2) CrimPC) and the Public Prosecutor can have funds seized only while they are still available (art. 263 CrimPC).
Two situations must be distinguished when it comes to who bears the loss. Where a third party gave the bank an order by posing as the company, with a forged email or signature, the question is whether the bank is liable. Banks' general terms and conditions often place that risk on the customer, but such clauses are limited by art. 100(1) of the Code of Obligations (CO), which renders void any agreement excluding liability in advance for unlawful intent or gross negligence. The Federal Supreme Court weighs the bank's fault against the customer's contributory fault case by case (judgments 4A_386/2016 of 5 December 2016, 4A_9/2020 of 9 July 2020 and 4A_610/2023 of 8 January 2025). Where the company itself made the payment, misled as to the identity of the payee, the discussion moves to the supplier. Whether payment to the wrong account discharged the debt depends on the contract and the circumstances, and it is better to examine that point before paying a second time.
Ransomware
Files are encrypted and a message demands a ransom, often with a threat to publish data copied during the attack. Unplug the network cable and switch off Wi-Fi on the affected machines without shutting them down or reinstalling anything, since the traces help to understand the attack and to prove it, and have a specialist copy their memory and disks before any attempt at repair or restart. Keep the encrypted files, which it may be possible to decrypt later, together with the ransom note, the contact and cryptocurrency addresses it gives and the system logs. The specialist contains the attack and establishes what was copied. Inform the law enforcement authorities early and discuss the next steps with them. The affected systems are reinstalled from a trusted medium before the data is restored, and only once the backups have been checked and found intact. Avoid negotiating in haste, since a first exchange with the attackers already commits the company.
The NCSC advises against paying a ransom, since nothing guarantees that the attackers will not publish the data and payment finances future attacks. Nor does paying ensure a working decryption key. If the company is nonetheless considering payment, the NCSC strongly recommends discussing it with the cantonal police. Before any decision, check on the No More Ransom website, a joint project of the Dutch police and Europol in which Switzerland takes part, whether a decryption key has been published for the ransomware concerned. The decision also raises legal and insurance questions that need to be examined before any payment.
According to NCSC, ransomware, what to do (in French) and SME portal of the Confederation, cybersecurity.
The duty to report cyberattacks on critical infrastructure covers the organisations listed in art. 74b ISA. These critical infrastructure operators report an attack to the NCSC within 24 hours of detection where it endangers the functioning of the infrastructure, leads to the manipulation or leakage of information, went undetected for a long time or is accompanied by blackmail, threats or coercion (arts. 74d and 74e ISA), and they have 14 days to complete the report where not all the information is yet known (art. 16 of the Cybersecurity Ordinance). Other companies are not obliged to do so, although a voluntary report to the NCSC remains useful. In the first half of 2026, 79 ransomware cases were reported to it.
According to NCSC, half-yearly report 2026/1, 24 August 2026.
Breaking into a computer system may constitute unauthorised access to a data processing system (art. 143bis SCC), provided the system was specially secured, and encrypting someone else's data may constitute damage to data (art. 144bis SCC). Both offences are prosecuted on complaint, which must be filed within three months of the day the company learned who the offender is (art. 31 SCC). Damage to data is, however, prosecuted ex officio where the offender caused considerable damage (art. 144bis no. 1 para. 2 SCC). The ransom demand itself may amount to extortion (art. 156 SCC), which is prosecuted ex officio. The NCSC recommends filing a criminal complaint with the cantonal police where the company has its seat, which allows the authorities to link the attack to other cases and, where payments were made, to try to trace the funds.
Internal fraud
It may involve payments to a supplier that does not exist, inflated expense claims or a manager helping himself to the company's funds. A person who, without right, uses entrusted assets for their own or a third party's benefit commits misappropriation (art. 138 SCC). Criminal mismanagement covers a person bound by law, by an official mandate or by a legal transaction to manage another's financial interests or to supervise their management, and who harms them in breach of their duties (art. 158 SCC), and the penalty is heavier where the offender acted for unlawful gain. Both offences are prosecuted ex officio, except where committed against relatives or members of the same household, so that once the authority has been informed the company no longer fully controls the course of the proceedings.
Keep the circle of people informed small and have the accounts, supporting documents, bank statements and relevant IT data copied before any conversation. Access to mailboxes and the monitoring of employees are subject to rules, and ignoring them may compromise the use of the evidence. The employer may process data about an employee only insofar as it concerns their suitability for the job or is necessary for the performance of the employment contract (art. 328b CO), and monitoring systems designed to watch employees' behaviour at their workplace are prohibited (art. 26 of Ordinance 3 to the Employment Act). Do not confront the person too early, since a premature interview gives them time to remove documents or move funds.
If summary dismissal for good cause is being considered (art. 337 CO), time matters as well. The Federal Supreme Court generally allows two to three working days for reflection, which may be extended by a few days where, in a legal entity, the decision lies with a body of several members. Where checks are needed to assess the extent of the misconduct, that period runs only once they are complete, but an employer with a concrete suspicion must start them without delay, failing which the dismissal may be held to have come too late (ATF 138 I 113, consid. 6.3.2 and 6.3.3).
In a bank or another institution supervised by FINMA, finding that funds have been embezzled also raises the question of informing FINMA without delay of any significant event (art. 29(2) of the Financial Market Supervision Act, FINMASA). A financial intermediary whose clients' assets are affected must also consider a report to the Money Laundering Reporting Office Switzerland (art. 9 of the Anti-Money Laundering Act, AMLA).
A criminal complaint gives access to means the company does not have itself. Only the criminal authority can order searches, interviews, requests to banks or the seizure of funds (art. 263 CrimPC), and it decides whether to do so. The company can join the proceedings as a private claimant, propose evidence and assert its civil claims there (arts. 107(1)(e), 118 and 122 CrimPC). Civil proceedings alone leave the company more control over timing and confidentiality. The choice depends on the amount at stake, the offender's solvency and the need for investigative measures that a criminal authority alone can order, and the two routes can be pursued together.
A company impersonated by fraudsters
Fraudsters sometimes use the name of an existing company to deceive its customers, job applicants or investors. One method is to register a domain name close enough to the company's own to cause confusion, which the NCSC calls cybersquatting, or one that differs from it by a typing error, known as typosquatting, and to use the fake site for phishing or to spread malware. In March 2026 the NCSC described fake websites set up in the name of companies listed in the commercial register that had no website of their own, notably in logistics, with fake job offers posted on legitimate job platforms and even in newspapers. The domains had been registered a few days earlier, and applicants were asked for their CVs, certificates and diplomas, and sometimes for a payment.
According to NCSC, cybersquatting and corporate identity theft and NCSC, 24 March 2026.
Keep the exact address of the fake site, dated screenshots, the domain's registration date where it is public and any emails received, with their full headers, then warn customers and applicants through your own website and your usual channels, restating your official addresses and bank details. Every registrar has an address for abuse reports, usually abuse@, to which the fake domain can be reported. Phishing and malware sites are reported to the NCSC, which passes them on to the hosting provider and the registrar so that they block the site, and for a .ch or .swiss domain the NCSC states that it can have the site blocked directly.
For a .ch domain, the registry may block it for up to five working days where there are good reasons to believe that it is used to obtain critical data by unlawful means or to spread malware, and may extend the block to 30 days where there are good reasons to believe that the holder is using false identification data or impersonating a third party, and it is urgent to prevent imminent harm that would be difficult to repair (art. 15 of the Ordinance on Internet Domains, OID). A block does not transfer the domain. Where its allocation or use clearly infringes a right in a distinctive sign that the company holds under Swiss law, the company can start the dispute resolution procedure that the WIPO Arbitration and Mediation Center runs for .ch domains. It begins with a conciliation telephone conference of up to one hour, after which, failing agreement, an expert decides on transfer or revocation of the domain. The expert's decision binds the registry unless a civil action is brought within the time limit set by the rules of procedure (art. 14(1)(c) OID).
According to WIPO, dispute resolution for .ch domains.
A person who gives inaccurate or misleading information about themselves, their business or their business name, or who takes steps likely to cause confusion with another's services or business, acts unfairly (art. 3(1)(b) and (d) of the Federal Act against Unfair Competition, UCA). A company harmed in its clientele, credit or reputation, or threatened with such harm, can ask the court to prohibit or stop the infringement, have a correction communicated to third parties and claim damages (art. 9 UCA). It can also act against the usurpation of its name (art. 29(2) of the Civil Code, CC) and against unauthorised use of its registered business name (art. 956 CO). These civil actions require the perpetrator to be identified. Intentional unfair competition is punishable on complaint, which anyone entitled to bring a civil action may file (art. 23 UCA) within three months of learning who the offender is (art. 31 SCC). Where customers or applicants were induced to pay, the facts may amount to fraud (art. 146 SCC), which is prosecuted ex officio, and each injured party can file a criminal complaint.
FINMA describes cloned websites that can barely be told apart from the site of an authorised firm, behind which there may be a financial operator acting illegally under that firm's name. It asks to be told of any doubt about a provider, its reporting page covers providers operating without the required authorisation, and it can add the perpetrator to its warning list and, where appropriate, have the website and Swiss telephone numbers blocked. Report a clone to FINMA without delay, in addition to the steps described above.
According to FINMA, examples of investment fraud (in French), FINMA, action against unauthorised providers (in French) and FINMA, making a report.
Monthly business fraud alert
Once a month, a short email describes the schemes targeting businesses in Switzerland, as reported by the NCSC and the police, and what they mean for your internal controls. It is written in French and contains no offer of services. To unsubscribe, simply reply to it.
Your address is used for this mailing alone. For anything else, the data protection page applies.
The publisher of this site
Matthias Traussnig, attorney at law (Geneva Bar), founder of Sentinel Legal. He acts for businesses hit by fraud or a cyberattack, whether on the criminal complaint, the seizure of funds, dealings with the bank and the authorities or the civil claim.
About the firm · info@arnaques-suisse.ch
A first message does not create a lawyer-client relationship.
This page relies on arts. 74b, 74d, 74e and 74h ISA, art. 16 of the Cybersecurity Ordinance, art. 24 FADP, arts. 100, 328b, 337 and 956 CO, art. 29 CC, arts. 3, 9 and 23 UCA, arts. 14 and 15 OID, art. 26 of Ordinance 3 to the Employment Act, art. 29 FINMASA, art. 9 AMLA, arts. 31, 138, 143bis, 144bis, 146, 156 and 158 SCC, arts. 107, 118, 122, 263 and 304 CrimPC and ATF 138 I 113. It gives general information and does not replace the examination of a particular case, which may call for other steps. Checked on 11 October 2026.