ctipilot.ch

PDAG email-account compromise

incident · incident:pdag-email-phishing-2026 single-source-victim

Individual @pdag.ch mailboxes at the Swiss cantonal psychiatric-care provider PDAG were compromised via phishing and abused to relay spam/phishing to external recipients; disclosed ~2026-07-08/09, accounts locked and all-staff passwords reset, no patient-data compromise confirmed (SwissCybersecurity.net, 2026-07-09).

Coverage timeline
3
first 2026-07-09 → last 2026-07-12
Peak priority
high
1 high · 2 notable
Sources cited
8
7 hosts
Sections touched
2
active-threats, weekly-sector-patterns
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.1 · see below
2026-07-093 appearances2026-07-12

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Resource Development TA0042

T1586.002Compromise Accounts: Email Accounts×1

Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).

Evidence: 2026-07-09/pdag-aargau-email-account-compromise-spam-relay · ATT&CK page ↗

Initial Access TA0001

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-07-09/pdag-aargau-email-account-compromise-spam-relay · ATT&CK page ↗

Story timeline

  1. 2026-07-12Healthcare across Switzerland and the UK saw ransomware confirmation, mailbox compromise and an insider-access clampdown this week
    weekly-sector-patternsHealthcare this week — Swiss radiology network confirms Akira attribution, Aargau psychiatric authority mailboxes phished, NHS England tightens insider access
  2. 2026-07-12Government and public administration across Switzerland and Europe took a broad spread of attacks this week — ransomware, espionage watering-holes, AI-tooled APTs and credential-phishing
    weekly-sector-patternsCH/EU government under broad attack this week — Latvia forestry ransomware, Swiss cantonal mailbox compromise, e-gov watering-hole, Ghostwriter phishing
  3. 2026-07-09Psychiatrische Dienste Aargau (PDAG) email accounts compromised via phishing and abused to relay spam
    active-threatsSwiss cantonal psychiatric provider PDAG discloses phishing-driven takeover of staff mailboxes used to send outbound spam/phishing

Where this entity is cited

  • weekly-sector-patterns2
  • active-threats1

Source distribution

  • swisscybersecurity.net2 (25%)
  • cert.lv1 (12%)
  • cert.pl1 (12%)
  • england.nhs.uk1 (12%)
  • inside-it.ch1 (12%)
  • securelist.com1 (12%)
  • sentinelone.com1 (12%)

explore in graph

Entries about PDAG email-account compromise (3)

2026-07-12 · view entry permalink →

NOTABLENATOB1

Healthcare across Switzerland and the UK saw ransomware confirmation, mailbox compromise and an insider-access clampdown this week

Healthcare surfaced three ways this week, and the value of reading them together is that they cover the sector's external, identity and internal threat surfaces in a single window.

Externally, Groupe 3R — the Réseau Radiologique Romand, a Western-Swiss radiology network — confirmed in its own forensic report that the Akira ransomware operation was responsible for the intrusion that had twice disrupted it, and that stolen data had been published on Akira's darknet leak site (SwissCybersecurity.net, 2026-05-07). On the identity surface, Psychiatrische Dienste Aargau (PDAG), a cantonal psychiatric authority, had email accounts phished and abused as a spam relay (SwissCybersecurity.net, 2026-07-09). Internally, NHS England issued new controls after staff were found inappropriately accessing high-profile patients' records, tying repeat "snooping" to dismissal and potential prosecution (NHS England, 2026-07-11).

Why this belongs to the constituency's healthcare lens: two of the three are Swiss (a Romand radiology provider and an Aargau cantonal authority), and the third is a transferable governance lesson for any large healthcare data controller. Healthcare's threat model is not just ransomware on clinical systems — it is equally the mailbox identity that attackers abuse and the legitimate-but-excessive internal access that no perimeter control addresses.

Builds on: 2026-07-09/groupe-3r-akira-forensic-confirmation-darknet-publication · 2026-07-11/nhs-england-insider-patient-record-access-controls · 2026-07-09/pdag-aargau-email-account-compromise-spam-relay

synthesis12 Jul 23:32Zmulti-sourceOpen finding ↗

2026-07-12 · view entry permalink →

HIGHNATOB1

Government and public administration across Switzerland and Europe took a broad spread of attacks this week — ransomware, espionage watering-holes, AI-tooled APTs and credential-phishing

Government and public administration — the profiled constituency's core — absorbed an unusually broad spread of activity in 2026-W28, notable less for any single incident than for how many different attack classes landed on the sector in one week.

On the ransomware front, CERT.LV disclosed that a crew breached Latvijas Valsts Meži (LVM), Latvia's state forestry operator, through a service left unpatched for roughly two years, and framed it explicitly as an EU/NATO-shared-threat matter for a state-owned critical operator (CERT.LV, 2026-06). In Switzerland, Psychiatrische Dienste Aargau (PDAG), a cantonal health authority, had staff email accounts compromised via phishing and abused to relay spam — a low-sophistication but high-frequency pattern against public-sector mailboxes (SwissCybersecurity.net, 2026-07-09). On the espionage axis, SentinelLabs documented converging China- and India-nexus operations weaponising a citizen-facing e-government complaint portal as a watering hole with a CMS implant (SentinelLabs, 2026-07-10); Kaspersky profiled Armored Likho hitting government and electric-power targets with an AI-generated loader and the BusySnake stealer (Kaspersky Securelist, 2026-07-11); and CERT Polska tracked UNC1151/Ghostwriter moving to Gmail with real-time 2FA-relay phishing against officials (CERT Polska, 2026-06).

Why this is a sector pattern for the constituency: two of the five strands carry a direct home-region or EU-critical-operator nexus (a Swiss cantonal authority and a Latvian state operator); the e-government watering-hole targeted a Pakistani law-enforcement programme (EU-funded but with no direct European victim nexus) and is carried for its transferable technique, while the remaining two are actors whose targeting profile — government and energy — matches the constituency. The exposed surfaces recur: unpatched internet-facing services, public-sector email identity, and citizen-facing web applications.

Builds on: 2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat · 2026-07-09/pdag-aargau-email-account-compromise-spam-relay · 2026-07-10/e-government-portal-watering-hole-cms-implant-espionage · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · 2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing

synthesis12 Jul 23:30Zmulti-sourceOpen finding ↗

2026-07-09 · view entry permalink →

NOTABLENATOC2

Psychiatrische Dienste Aargau (PDAG) email accounts compromised via phishing and abused to relay spam

Psychiatrische Dienste Aargau AG (PDAG), a Swiss cantonal psychiatric-care provider, disclosed that unauthorised parties gained access to individual @pdag.ch email accounts and abused them to send spam and phishing messages to external recipients (SwissCybersecurity.net, 2026-07-09; Inside IT, 2026-07-08). On discovery, PDAG locked the affected accounts immediately, reset passwords for all employees as a precaution, notified the competent cantonal and national authorities, and engaged internal and external IT-security experts plus its external ICT service provider to analyse and harden. By its current assessment the incident is limited to account misuse for outbound spam/phishing, with no indication that patient data was accessed or exfiltrated; the organisation is warning recipients about suspicious mail purporting to come from its domain.

No technical root cause — the initial-access vector into the mailboxes, whether MFA was enforced, or whether the takeover was via credential phishing or an OAuth consent grant — was disclosed, so the mechanism is unknown rather than assumed. The pattern maps to T1566 Phishing for the initial access and T1586.002 Compromise Accounts: Email Accounts for the takeover and downstream abuse.

incident09 Jul 12:28Zsingle-source · victim disclosureOpen finding ↗