Swiss Authorities Warn Of Surge In Callback Scams Using Fake Migros And Bank Alerts
Source: NCSC

Switzerland’s National Cyber Security Centre (NCSC) is warning the public about a sharp rise in “callback fraud,” in which scammers send fake invoices or payment alerts via email and text to trick victims into phoning a number that connects them directly to fraudsters.

The scam typically begins with an email or text message claiming that a suspicious or unauthorised transaction has occurred on the recipient’s bank account. The fraudsters claim they can stop or reverse the charge, but only if the recipient calls a specific phone number within a set deadline. If the person doesn’t respond in time, the message warns, the payment will supposedly go through. These claims are entirely fabricated.

The NCSC said reports of this scam have escalated significantly in recent weeks, with a further spike in the last few days.

The Clear Regulatory Gap

The NCSC currently has no official authority to force telecom providers to deactivate phone numbers being used for fraud. It can notify providers of the fraudulent activity, but the final decision to shut down a number rests with the provider itself.

That is expected to change under a pending amendment to Switzerland’s Telecommunications Act, which would place greater responsibility on service providers, requiring them to block or deactivate numbers linked to fraud. However, the NCSC cautions that this legislation is likely still some time away from taking effect, meaning heightened public vigilance remains the main defence for now.

Swiss Area Codes Being Used To Build False Trust

The fraudulent messages usually provide a phone number to call with questions or to cancel the supposed payment. While many of these numbers are foreign landlines, the NCSC says fraudsters are increasingly using Swiss numbers as well, particularly those with the area codes 021, 022, 026 and 071, specifically to make the calls appear legitimate and encourage victims to dial in.

Anyone who calls is connected to what sounds like a genuine support or customer service line. As the call progresses, the scammers attempt to extract sensitive information, including credit card details and personal data. They also try to convince victims to share verification codes or approve TWINT payment requests.

In some cases, callers are asked to install remote-access software, ostensibly to help cancel the invoice or reverse a charge. In reality, the software gives the fraudsters direct control of the victim’s computer. If the victim then logs into online banking, the scammers can watch the session in real time and potentially gain access to the account itself.

Callback Scams: Fake Migros Invoices Among The Latest Lures

The NCSC noted that fraudulent messages are being sent under a variety of different senders and scenarios beyond fake bank alerts. Last week, the agency received numerous reports of fraudulent emails sent in the name of Swiss retailer Migros, claiming the recipient had purchased goods worth more than CHF 765, including, notably, a bottle of white wine priced at around CHF 250.

The NCSC pointed out a telling inconsistency in this particular scam: Migros does not sell alcohol. Despite this red flag, the unusually high invoice amount is often enough to unsettle victims into calling the provided number anyway.

Similar fake messages have also been circulated in the name of TWINT and other well-known payment providers. Regardless of the sender used, the fraudsters’ goal remains the same: get the victim to call the provided number so they can be pressured or manipulated into revealing sensitive data or authorizing payments.

What The NCSC Recommends

The agency’s guidance is direct:

  • Never call a phone number provided in an unsolicited email or text message, especially under time pressure.

  • If in doubt about an invoice’s authenticity, use only the official contact details listed on the real website of the supposed sender — your bank, TWINT, Migros, or whichever company is named.

  • Never install remote-access software at the request of someone who contacted you unsolicited or whom you called back from a suspicious message.

Read More: Fresh Off A Data Breach, Revolut Applies For Swiss Banking Licence

Akriti Seth
About the Author

Akriti Seth

Akriti Seth is a Zürich-based editor with more than a decade of experience, anchored by foundational training at Bloomberg. As a journalist, she covers global affairs, financial markets and technology. Her career has taken her from television studios to digital newsrooms. She has reported as an on-air correspondent for Channel NewsAsia and covered markets, corporate finance and business strategy for Informa UK. Her work has appeared in Entrepreneur Magazine, Hindustan Times, Yahoo Finance, TradingView, the Crypto Council for Innovation, DailyCoin, Tech Panda and more. She founded Helvetica Times to bring independent, English-language journalism to Switzerland — serving the expats, international professionals and global readers who want Swiss news reported with clarity and rigor.

View all articles