Fraudulent phone calls impersonating Swiss authorities have plummeted by more than 75% following the extension of mandatory caller identification to calls from abroad using spoofed Swiss numbers, Switzerland’s National Cyber Security Centre (NCSC) reported Monday. The improvement comes even as overall cyberthreat levels remain elevated, with attackers increasingly turning to artificial intelligence to personalise their scams.
A Sharp Drop In Impersonation Calls
Calls in which fraudsters pose as government officials using a spoofed Swiss phone number have been among the most frequently reported cyber incidents to the NCSC in recent years. Between January and June 2026, the centre regularly received more than 400 such reports per month.
That changed after Switzerland extended its mandatory caller ID requirement to cover calls from abroad using spoofed Swiss numbers, with the rollout reaching mobile phone numbers on July 1, 2026. In July alone, reports fell to fewer than 100, a decline of more than 75% compared with previous months. An earlier rollout phase covering landline numbers in January 2026 had already produced an initial downward trend, suggesting the requirement is having a cumulative effect as it expands across network types.
Read More: Lunar Eclipse To Appear Over Switzerland On 28 August
Cyberthreats Remain High Overall
Despite the improvement on impersonation calls, the broader threat picture remains serious. In the first half of 2026, the NCSC received 27,128 voluntary reports of cyber incidents from the public, alongside 200 mandatory reports of attacks on critical infrastructure. Fraud, the centre notes, “remains a dominant and lucrative mass market business.”
Fraud Calls In Switzerland Drop 75%: AI-Driven Personalization On The Rise
The NCSC’s semi-annual report highlights a continuing shift toward personalized, AI-assisted attacks, a trend already flagged in the centre’s previous report. Cybercriminals are increasingly using classifieds platforms, targeted search engine placements and data leaked from breaches to identify and approach victims, employing personal, emotional and sometimes technically sophisticated methods. Attackers are systematically using AI to make tailored, fabricated content appear credible.
Jobseekers were singled out as a specific target during this reporting period, lured with fake “dream jobs” or fraudulent investment opportunities.
Corporate Attacks Shift Toward Microsoft 365 Phishing
While large-scale “CEO fraud” campaigns targeting schools, municipalities and churches were notably absent this period, the NCSC recorded numerous reports of Microsoft 365 phishing attacks. In these cases, attackers compromised victims’ business email accounts and impersonated senior executives or help-desk staff to either breach further systems or directly initiate fraudulent financial transactions. Fake “pending security update” prompts were also increasingly used as a pretext to distribute malware.
Ransomware reports remained stable at 79 cases, though the report notes a clear trend toward diversification and fragmentation among ransomware families, meaning attacks are increasingly carried out by a wider and more fragmented set of actors rather than a few dominant groups.
Geopolitical Risk To Critical Infrastructure
The report also addresses the international dimension of cyber conflict, noting that cybersabotage has become an increasingly overt tool used by individual states in geopolitical conflicts. While no targeted cybersabotage attacks against Swiss critical infrastructure have occurred to date, the NCSC warns that Switzerland’s close economic and political ties with other Western countries mean Swiss organizations must remain focused on resilience amid an increasingly hostile cyberthreat environment. The report includes a case study examining a related incident in Poland to illustrate the risk.
Operators of critical infrastructure are legally required to report cyberattacks to the NCSC within 24 hours. Of the 200 such mandatory reports received in the first half of 2026, most came from the public administration sector (19.4%) and companies in IT and telecommunications (18.6%). By attack type, hacking incidents made up the largest share at roughly 26%, followed by stolen login credentials (13.5%) and data breaches and DDoS attacks (12.7% each).