CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

PDAG email-account compromise

incident · incident:pdag-email-phishing-2026 single-source-victim

Individual @pdag.ch mailboxes at the Swiss cantonal psychiatric-care provider PDAG were compromised via phishing and abused to relay spam/phishing to external recipients; disclosed ~2026-07-08/09, accounts locked and all-staff passwords reset, no patient-data compromise confirmed (SwissCybersecurity.net, 2026-07-09).

Coverage
1
first 2026-07-09 → last 2026-07-09
Latest activity
2026-07-09
Swiss cantonal psychiatric provider PDAG discloses phishing-driven takeover of staff mailboxes used to send…
Peak priority
notable
1 notable
Targets
healthcare
sectors: healthcare, public-sector · regions: switzerland
Sources cited
2
2 hosts

Action items (2)

Do-now tasks recorded on the entries about PDAG email-account compromise, newest first. Check the date before acting on an older one.

Defender insights

What each entry about PDAG email-account compromise tells a defender to do, newest first.

2026-07-09NOTABLESwiss cantonal psychiatric provider PDAG discloses phishing-driven takeover of staff mailboxes used to send outbound spam/phishing

Story timeline

  1. 2026-07-09Psychiatrische Dienste Aargau (PDAG) email accounts compromised via phishing and abused to relay spam
    active-threatsSwiss cantonal psychiatric provider PDAG discloses phishing-driven takeover of staff mailboxes used to send outbound spam/phishing

Hunting pivots

ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Resource DevelopmentCompromise Accounts: Email Accounts
  • Initial AccessPhishing

Resource Development TA0042

T1586.002Compromise Accounts: Email Accounts×1

Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).

Evidence: 2026-07-09/pdag-aargau-email-account-compromise-spam-relay · ATT&CK page ↗

Initial Access TA0001

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-07-09/pdag-aargau-email-account-compromise-spam-relay · ATT&CK page ↗

Entries about PDAG email-account compromise (1)

2026-07-09 · view entry permalink →

NOTABLENATOC2

Psychiatrische Dienste Aargau (PDAG) email accounts compromised via phishing and abused to relay spam

Psychiatrische Dienste Aargau AG (PDAG), a Swiss cantonal psychiatric-care provider, disclosed that unauthorised parties gained access to individual @pdag.ch email accounts and abused them to send spam and phishing messages to external recipients (SwissCybersecurity.net, 2026-07-09; Inside IT, 2026-07-08). On discovery, PDAG locked the affected accounts immediately, reset passwords for all employees as a precaution, notified the competent cantonal and national authorities, and engaged internal and external IT-security experts plus its external ICT service provider to analyse and harden. By its current assessment the incident is limited to account misuse for outbound spam/phishing, with no indication that patient data was accessed or exfiltrated; the organisation is warning recipients about suspicious mail purporting to come from its domain.

No technical root cause (the initial-access vector into the mailboxes, whether MFA was enforced, or whether the takeover was via credential phishing or an OAuth consent grant) was disclosed, so the mechanism is unknown rather than assumed. The pattern maps to T1566 Phishing for the initial access and T1586.002 Compromise Accounts: Email Accounts for the takeover and downstream abuse.

incident09 Jul 12:28Zsingle-source · victim disclosureOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • inside-it.ch1 (50%)
  • swisscybersecurity.net1 (50%)