2026-07-26 · view entry permalink →
Swiss and European public-sector bodies carried the week's home-region incident load — and nearly every one was reached through a third party, a shared platform or a fiduciary, then followed by a disclosure that had to be walked back
The week's confirmed incidents with a direct Swiss or European home-region nexus landed almost entirely on public-sector and critical-infrastructure bodies, and two structural patterns are more useful to defenders than any single victim.
The first is the access path: the breach rarely started inside the named victim. Swiss rolling-stock manufacturer Stadler Rail disclosed that the Everest group compromised a data-exchange platform it shares with a supplier and demanded CHF 10 million, which the company did not pay — "Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht", while its own production ran normally (swissinfo.ch, 2026-07-21). A Vaud fiduciary breach claimed by BravoX published more than 100,000 client files — some 220 GB — exposing tax and administrative records of roughly fifteen Nord-Vaudois municipalities and the personal tax file of a sitting cantonal State Councillor (Le Temps, 2026-07-22). A Bern autism-support foundation, Stiftung Autismuslink, confirmed that "grössere Datenmengen" were exfiltrated and its server temporarily encrypted (Stiftung Autismuslink, 2026-07); the INC Ransom RaaS group claimed the attack via a matching leak-site listing (Ransomware.live, 2026-07-24), and the foundation's constituency-relevance is that it serves Swiss cantonal education-directorate and disability-insurance-linked clients. In each case the sensitive public-sector data sat with a supplier, a fiduciary or a small third-party service organisation, not on a government perimeter.
The second pattern is a disclosure that had to be walked back. Geneva's IFAGE adult-education foundation had earlier framed its incident as affecting employee data; the attackers — the DragonForce group (ICTjournal, 2026-07-17) — published the stolen set, which included identity-document photographs, addresses and multi-year student exam results, and 20 minutes reported the disclosure "concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.)" (20 minutes, 2026-07-24). The starkest reversal is Romania's national land registry ANCPI, which stated on 2026-07-20 that its databases "have not been affected"; the national cybersecurity directorate DNSC's interim report describes attackers compromising the authentication servers, entering VMware vCenter, enumerating all 1,083 virtual machines, deleting roughly 100 and encrypting ESXi hosts, and exfiltrating about two million ePayment-platform user records — "nume; e-mailuri; identificatori; hash-uri ale parolelor" (PS News relaying DNSC, 2026-07-24), with the report also noting the affected servers ran no antivirus.
Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht
atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor
Leur divulgation par les cybercriminels concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.).
Builds on: 2026-07-22/everest-ransomware-stadler-rail-supplier-platform-breach · 2026-07-24/bravox-vaud-fiduciary-municipalities-breach · 2026-07-25/stiftung-autismuslink-bern-inc-ransom-breach · 2026-07-26/ifage-geneva-dragonforce-data-published-student-records · 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-21/ancpi-romania-cadastre-databases-not-affected-update