CTIPilot

Martigny-Combe municipal email compromise (Valais, Switzerland, 2026-08)

incident · incident:martigny-combe-email-compromise-2026-08 single-source

Unauthorised access to the business email system of the Martigny-Combe (Valais) municipal secretariat, detected 2026-08-18, used to send a fraudulent message to administration contacts with possible exposure of personal data contained in that email; reported to BACS and the cantonal data-protection commissioner (SwissCybersecurity.net, 2026-08-24).

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-28/martigny-combe-valais-municipal-email-compromise · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-28/martigny-combe-valais-municipal-email-compromise · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-28/martigny-combe-valais-municipal-email-compromise · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-28/martigny-combe-valais-municipal-email-compromise · ATT&CK page ↗

Story timeline

  1. 2026-08-28Martigny-Combe (Valais) municipal email account compromised and used to send a fraudulent message to administration contacts, second Valais municipality hit in 2026
    active-threatsA Swiss communal administration's business mailbox is compromised and weaponised against its own contact list

Where this entity is cited

  • active-threats1

Source distribution

  • swisscybersecurity.net1 (100%)

explore in graph

Entries about Martigny-Combe municipal email compromise (Valais, Switzerland, 2026-08) (1)

2026-08-28 · view entry permalink →

NOTABLENATOC2

Martigny-Combe (Valais) municipal email account compromised and used to send a fraudulent message to administration contacts, second Valais municipality hit in 2026

The municipality of Martigny-Combe (canton Valais) detected unauthorised access to its administrative secretariat's business email system on 2026-08-18: "the municipality of Martigny-Combe in Valais detected unauthorised access to the business email system of its municipal secretariat on 18 August" (translated from German) (Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net, 2026-08-24). Per the municipality's own statement, the access was used to send a fraudulent message to contacts of the administration, and personal data contained in that email may have been passed to an unauthorised third party: "the attack made it possible to send a fraudulent message, which was distributed among others to contacts of the administration" (translated from German) (Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net, 2026-08-24), the municipality specifically flags phishing and identity-theft risk for recipients of the fraudulent message.

The compromised access was blocked immediately on discovery, technical security measures were applied, and external specialists are now conducting a scoping analysis. The incident was reported to Switzerland's Bundesamt für Cybersicherheit (BACS) and to the cantonal data-protection and transparency commissioner: "Martigny-Combe has additionally reported the incident to the Federal Office for Cybersecurity (BACS) and to the cantonal commissioner for data protection and transparency" (translated from German) (SwissCybersecurity.net, 2026-08-24), and a criminal complaint has been filed with the Valais cantonal police. This is the second Valais municipality reported hit by a cyberattack in 2026; Vétroz was disabled by a cyberattack in April, a separate, already-dated incident of an undisclosed type not otherwise covered here.

No source states how the mailbox was accessed (only the unauthorised use of a valid account is established) and nothing is disclosed about the onward fraudulent message's recipients or content.

The municipality of Martigny-Combe in Valais detected unauthorised access to the business email system of its municipal secretariat on 18 August. (translated from German)

the attack made it possible to send a fraudulent message, which was distributed among others to contacts of the administration. (translated from German)

Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net

Martigny-Combe has additionally reported the incident to the Federal Office for Cybersecurity (BACS) and to the cantonal commissioner for data protection and transparency. (translated from German)

SwissCybersecurity.net 2026-08-24
incident28 Aug 06:42Zsingle-sourceOpen finding ↗