2026-08-28 · view entry permalink →
Martigny-Combe (Valais) municipal email account compromised and used to send a fraudulent message to administration contacts — second Valais municipality hit in 2026
The municipality of Martigny-Combe (canton Valais) detected unauthorised access to its administrative secretariat's business email system on 2026-08-18: "die Gemeinde Martigny-Combe im Wallis hat am 18. August einen unbefugten Zugriff auf das geschäftliche E-Mail-System ihres Gemeindesekretariats festgestellt" (Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net, 2026-08-24). Per the municipality's own statement, the access was used to send a fraudulent message to contacts of the administration, and personal data contained in that email may have been passed to an unauthorised third party: "konnte durch den Angriff eine betrügerische Nachricht versendet werden. Diese sei unter anderem an Kontakte der Verwaltung verschickt worden" (Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net, 2026-08-24) — the municipality specifically flags phishing and identity-theft risk for recipients of the fraudulent message.
The compromised access was blocked immediately on discovery, technical security measures were applied, and external specialists are now conducting a scoping analysis. The incident was reported to Switzerland's Bundesamt für Cybersicherheit (BACS) and to the cantonal data-protection and transparency commissioner: "Martigny-Combe hat den Vorfall zudem dem Bundesamt für Cybersicherheit (BACS) sowie dem kantonalen Beauftragten für Datenschutz und Transparenz gemeldet" (SwissCybersecurity.net, 2026-08-24), and a criminal complaint has been filed with the Valais cantonal police. This is the second Valais municipality reported hit by a cyberattack in 2026 — Vétroz was disabled by a cyberattack in April, a separate, already-dated incident of an undisclosed type not otherwise covered here — a pattern this pipeline has not previously tracked as a recurring theme for the canton.
No access vector is stated by any source, hence techniques[] carries only T1078 (Valid Accounts) for the unauthorised mailbox access itself; no technique is mapped for the onward fraudulent message, since the source does not state whether recipients were internal or external, or what the message contained. actions[] is empty: small-scale, single-municipality incident with no transferable technical detail beyond the standard business-email-compromise response already known to this audience.
Die Gemeinde Martigny-Combe im Wallis hat am 18. August einen unbefugten Zugriff auf das geschäftliche E-Mail-System ihres Gemeindesekretariats festgestellt.
konnte durch den Angriff eine betrügerische Nachricht versendet werden. Diese sei unter anderem an Kontakte der Verwaltung verschickt worden.
Martigny-Combe hat den Vorfall zudem dem Bundesamt für Cybersicherheit (BACS) sowie dem kantonalen Beauftragten für Datenschutz und Transparenz gemeldet.