CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

NCSC-CH G7 Évian pre-event advisory

report · report:g7-evian-2026

NCSC-CH pre-event cyber advisory for the G7 Évian summit (2026-06-01) warning that DDoS attacks are expected around the event.

Coverage
1
first 2026-06-03 → last 2026-09-30
Latest activity
2026-06-03
NCSC Switzerland warns of cyber operations around the G7 Évian summit (15–17 June)
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, telco, transport · regions: switzerland, europe
Sources cited
2
2 hosts

Story timeline

  1. 2026-06-03NCSC Switzerland warns of cyber operations around the G7 Évian summit (15–17 June)
    active-threats
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ImpactNetwork Denial of Service

Impact TA0040

T1498Network Denial of Service×1

Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Evidence: 2026-06-03/ncsc-switzerland-warns-of-cyber-operations-around-the-g7-via · ATT&CK page ↗

Entries about NCSC-CH G7 Évian pre-event advisory (1)

2026-06-03 · view entry permalink →

HIGHupdatedNATOA3

NCSC Switzerland warns of cyber operations around the G7 Évian summit (15–17 June)

On 2026-06-01 Switzerland's National Cyber Security Centre published a pre-event advisory warning that large events and international conferences are "often used as an opportunity to stage a cyberattack" and that it "expects disruptive maneuvers in cyberspace again" around the G7 summit in Évian (France, 15–17 June) (NCSC Switzerland, 2026-06-01). Although the summit sits on French soil, most delegations land at Geneva airport and stay on the Swiss side (ZENDATA Cybersecurity, 2026-05-03). In analyst judgement that puts Swiss federal and cantonal administrations, conference-linked suppliers and Swiss telecom operators in the blast radius. An independently published threat map for the event frames the expected activity against the template of the 2024 Bürgenstock summit, when the pro-Russia hacktivist collective NoName057(16) ran DDoS waves against Swiss federal sites and conference-linked organisations on each summit day; the same map additionally flags state intelligence collection against hotel and telecom infrastructure, rogue-base-station cellular interception, and social engineering of hotel help desks as plausible vectors (ZENDATA Cybersecurity, 2026-05-03). The NCSC advisory itself recommends generic protective measures and DDoS preparedness for organisations linked to the event.

Why it matters to us: Organisations operating in the Geneva–Vaud corridor and Swiss federal/cantonal SOCs should pre-stage DDoS mitigation playbooks now, review MFA on customer-facing identity providers, rotate administrative credentials before the event window, and brief travelling staff on mobile-device physical security. By inference, hunt for anomalous authentication spikes from the summit region around 15–17 June.

Correctionrun 2026-09-30T0634Z-auditsourcestechniquesclassificationsummaryentitiesbody

ZENDATA's risk map for the summit names social engineering of hotel help desks among the plausible vectors, not social engineering of event staff, and the analysis now says so (ZENDATA Cybersecurity, 2026-05-03). The observation that most delegations arrive through Geneva and stay on the Swiss side comes from the same map and now cites it. NCSC Switzerland's advisory warns that large events and conferences are "often used as an opportunity to stage a cyberattack", not that the summit is a high-value target, and the analysis now quotes it. Neither source says that the Swiss administrations, suppliers and telecom operators the analysis places in the blast radius will be targeted at Évian, so that exposure is now marked as analyst judgement. The advisory is cited at its new address on bacs.admin.ch (NCSC Switzerland, 2026-06-01).

threat03 Jun 05:00Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • bacs.admin.ch1 (50%)
  • zendata.security1 (50%)