BACS Halbjahresbericht 2026/I (Swiss cyber threat landscape, January–June 2026)
report · report:bacs-halbjahresbericht-2026-1 single-source-national-cert
Semi-annual report of Switzerland's Bundesamt für Cybersicherheit on the cyber threat landscape in Switzerland and internationally for January–June 2026, published 2026-08-24: 27,128 voluntary reports (against 35,727 in H1 2025) and 200 mandatory critical-infrastructure reports, of which the public sector is the largest reporting share at 19.4% ahead of IT and telecommunications at 18.6%. Two focus chapters, an anatomy of the 29 December 2025 Polish energy-sector sabotage with lessons for Swiss resilience, and a Swiss-specific 'Dream Job' crypto-theft playbook with more than 20 confirmed cases and losses up to roughly CHF 60 million (BACS, 2026-08-24).
Aliases: Halbjahresbericht 2026/I, Cyberbedrohungslage 1. Halbjahr 2026, BACS semi-annual report 2026/1
Coverage
1
first 2026-08-24 → last 2026-08-24
Latest activity
2026-08-24
BACS report: the public sector remains the largest share of Swiss mandatory CI reports at 19.4%, and basic…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, energy, telco · regions: switzerland, europe, dach
Sources cited
3
3 hosts
Defender insights
What each entry about BACS Halbjahresbericht 2026/I (Swiss cyber threat landscape, January–June 2026) tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
ATT&CK techniques (23 across 10 tactics)
23 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts · Valid Accounts: Default Accounts · External Remote Services · Drive-by Compromise · Supply Chain Compromise: Compromise Software Supply Chain · Phishing · Phishing: Spearphishing via Service
- ExecutionUser Execution: Malicious Copy and Paste
- PersistenceValid Accounts · Valid Accounts: Default Accounts · External Remote Services · Modify Authentication Process: Multi-Factor Authentication
- Privilege EscalationValid Accounts · Valid Accounts: Default Accounts · Domain or Tenant Policy Modification: Group Policy Modification
- StealthValid Accounts · Valid Accounts: Default Accounts · Social Engineering: Impersonation
- Defense ImpairmentDomain or Tenant Policy Modification: Group Policy Modification · Modify Authentication Process: Multi-Factor Authentication
- Credential AccessOS Credential Dumping: LSASS Memory · OS Credential Dumping: NTDS · Modify Authentication Process: Multi-Factor Authentication · Adversary-in-the-Middle · Steal or Forge Kerberos Tickets
- Lateral MovementRemote Services: SMB/Windows Admin Shares · Use Alternate Authentication Material: Application Access Token · Lateral Tool Transfer
- CollectionEmail Collection: Remote Email Collection · Data from Information Repositories: Sharepoint · Adversary-in-the-Middle
- ImpactData Destruction · Firmware Corruption · Disk Wipe
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1189Drive-by Compromise×1
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1566.003Phishing: Spearphishing via Service×1
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Execution TA0002
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1684.001Social Engineering: Impersonation×1
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Defense Impairment TA0112
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Credential Access TA0006
T1003.001OS Credential Dumping: LSASS Memory×1
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1003.003OS Credential Dumping: NTDS×1
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1558Steal or Forge Kerberos Tickets×1
Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC). Clients request access to a service and through the exchange of Kerberos tickets, originating from KDC, they are granted access after having successfully authenticated. The KDC is responsible for both authentication and ticket granting. Adversaries may attempt to abuse Kerberos by stealing tickets or forging tickets to enable unauthorized access.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Lateral Movement TA0008
T1021.002Remote Services: SMB/Windows Admin Shares×1
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1550.001Use Alternate Authentication Material: Application Access Token×1
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1570Lateral Tool Transfer×1
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Collection TA0009
T1114.002Email Collection: Remote Email Collection×1
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1213.002Data from Information Repositories: Sharepoint×1
Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Impact TA0040
T1485Data Destruction×1
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1495Firmware Corruption×1
Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use the devices and/or the system. Firmware is software that is loaded and executed from non-volatile memory on hardware devices in order to initialize and manage device functionality. These devices may include the motherboard, hard drive, or video cards.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1561Disk Wipe×1
Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources. With direct write access to a disk, adversaries may attempt to overwrite portions of disk data. Adversaries may opt to wipe arbitrary portions of disk data and/or wipe disk structures like the master boot record (MBR). A complete wipe of all disk sectors may be attempted.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Entries about BACS Halbjahresbericht 2026/I (Swiss cyber threat landscape, January–June 2026) (1)
Where this entity is cited
Source distribution
- bacs.admin.ch1 (33%)
- cms.news.admin.ch1 (33%)
- expel.com1 (33%)
All cited sources (3)
- bacs.admin.chBundesamt für Cybersicherheit (BACS), press releasehttps://www.bacs.admin.ch/de/newnsb/vzO9wG1V7K0D-m73EJw8W
- cms.news.admin.chBundesamt für Cybersicherheit (BACS), Halbjahresbericht 2026/Ihttps://cms.news.admin.ch/fileservice/sdweb-docs-prod-nsbcch-files/files/2026/08/24/25a75eab-7e61-467e-aeeb-47a7329ad921.pdf
- expel.comthis pipeline covers today from Expel's SynkLoader casehttps://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/