Martigny-Combe (Valais) municipal email account compromised and used to send a fraudulent message to administration contacts — second Valais municipality hit in 2026
The municipality of Martigny-Combe (canton Valais) detected unauthorised access to its administrative secretariat's business email system on 2026-08-18: "die Gemeinde Martigny-Combe im Wallis hat am 18. August einen unbefugten Zugriff auf das geschäftliche E-Mail-System ihres Gemeindesekretariats festgestellt" (Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net, 2026-08-24). Per the municipality's own statement, the access was used to send a fraudulent message to contacts of the administration, and personal data contained in that email may have been passed to an unauthorised third party: "konnte durch den Angriff eine betrügerische Nachricht versendet werden. Diese sei unter anderem an Kontakte der Verwaltung verschickt worden" (Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net, 2026-08-24) — the municipality specifically flags phishing and identity-theft risk for recipients of the fraudulent message.
The compromised access was blocked immediately on discovery, technical security measures were applied, and external specialists are now conducting a scoping analysis. The incident was reported to Switzerland's Bundesamt für Cybersicherheit (BACS) and to the cantonal data-protection and transparency commissioner: "Martigny-Combe hat den Vorfall zudem dem Bundesamt für Cybersicherheit (BACS) sowie dem kantonalen Beauftragten für Datenschutz und Transparenz gemeldet" (SwissCybersecurity.net, 2026-08-24), and a criminal complaint has been filed with the Valais cantonal police. This is the second Valais municipality reported hit by a cyberattack in 2026 — Vétroz was disabled by a cyberattack in April, a separate, already-dated incident of an undisclosed type not otherwise covered here — a pattern this pipeline has not previously tracked as a recurring theme for the canton.
No access vector is stated by any source, hence techniques[] carries only T1078 (Valid Accounts) for the unauthorised mailbox access itself; no technique is mapped for the onward fraudulent message, since the source does not state whether recipients were internal or external, or what the message contained. actions[] is empty: small-scale, single-municipality incident with no transferable technical detail beyond the standard business-email-compromise response already known to this audience.
Die Gemeinde Martigny-Combe im Wallis hat am 18. August einen unbefugten Zugriff auf das geschäftliche E-Mail-System ihres Gemeindesekretariats festgestellt.
konnte durch den Angriff eine betrügerische Nachricht versendet werden. Diese sei unter anderem an Kontakte der Verwaltung verschickt worden.
Martigny-Combe hat den Vorfall zudem dem Bundesamt für Cybersicherheit (BACS) sowie dem kantonalen Beauftragten für Datenschutz und Transparenz gemeldet.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Persistence TA0003
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Privilege Escalation TA0004
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Stealth TA0005
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.