2026-07-09NOTABLESwiss cantonal psychiatric provider PDAG discloses phishing-driven takeover of staff mailboxes used to send outbound spam/phishing
PDAG email-account compromise
incident · incident:pdag-email-phishing-2026 single-source-victim
Individual @pdag.ch mailboxes at the Swiss cantonal psychiatric-care provider PDAG were compromised via phishing and abused to relay spam/phishing to external recipients; disclosed ~2026-07-08/09, accounts locked and all-staff passwords reset, no patient-data compromise confirmed (SwissCybersecurity.net, 2026-07-09).
Coverage
1
first 2026-07-09 → last 2026-07-09
Latest activity
2026-07-09
Swiss cantonal psychiatric provider PDAG discloses phishing-driven takeover of staff mailboxes used to send…
Peak priority
notable
1 notable
Targets
healthcare
sectors: healthcare, public-sector · regions: switzerland
Sources cited
2
2 hosts
Action items (2)
Do-now tasks recorded on the entries about PDAG email-account compromise, newest first. Check the date before acting on an older one.
- Any Swiss public-sector or health body operating an @<domain>.ch mail estate should implement per-mailbox outbound-volume anomaly detection: a legitimate mailbox suddenly sending bulk external mail is an earlier and stronger compromise signal than waiting for external abuse reports.2026-07-09Swiss cantonal psychiatric provider PDAG discloses…
- Monitor DMARC/DKIM alignment reporting for your own domain to catch when it starts being used as a relay (authenticated sending from compromised accounts) rather than merely spoofed, and enforce MFA plus conditional-access on all mailboxes.2026-07-09Swiss cantonal psychiatric provider PDAG discloses…
Defender insights
What each entry about PDAG email-account compromise tells a defender to do, newest first.
Story timeline
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentCompromise Accounts: Email Accounts
- Initial AccessPhishing
Resource Development TA0042
T1586.002Compromise Accounts: Email Accounts×1
Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).
Evidence: 2026-07-09/pdag-aargau-email-account-compromise-spam-relay · ATT&CK page ↗
Initial Access TA0001
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-07-09/pdag-aargau-email-account-compromise-spam-relay · ATT&CK page ↗
Entries about PDAG email-account compromise (1)
Where this entity is cited
Source distribution
- inside-it.ch1 (50%)
- swisscybersecurity.net1 (50%)