CTIPilot
← Back to Daily brief 2026-08-28
NOTABLENATOC2incident

Martigny-Combe (Valais) municipal email account compromised and used to send a fraudulent message to administration contacts, second Valais municipality hit in 2026

A Swiss communal administration's business mailbox is compromised and weaponised against its own contact list

Analysis

The municipality of Martigny-Combe (canton Valais) detected unauthorised access to its administrative secretariat's business email system on 2026-08-18: "the municipality of Martigny-Combe in Valais detected unauthorised access to the business email system of its municipal secretariat on 18 August" (translated from German) (Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net, 2026-08-24). Per the municipality's own statement, the access was used to send a fraudulent message to contacts of the administration, and personal data contained in that email may have been passed to an unauthorised third party: "the attack made it possible to send a fraudulent message, which was distributed among others to contacts of the administration" (translated from German) (Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net, 2026-08-24), the municipality specifically flags phishing and identity-theft risk for recipients of the fraudulent message.

The compromised access was blocked immediately on discovery, technical security measures were applied, and external specialists are now conducting a scoping analysis. The incident was reported to Switzerland's Bundesamt für Cybersicherheit (BACS) and to the cantonal data-protection and transparency commissioner: "Martigny-Combe has additionally reported the incident to the Federal Office for Cybersecurity (BACS) and to the cantonal commissioner for data protection and transparency" (translated from German) (SwissCybersecurity.net, 2026-08-24), and a criminal complaint has been filed with the Valais cantonal police. This is the second Valais municipality reported hit by a cyberattack in 2026; Vétroz was disabled by a cyberattack in April, a separate, already-dated incident of an undisclosed type not otherwise covered here.

No source states how the mailbox was accessed (only the unauthorised use of a valid account is established) and nothing is disclosed about the onward fraudulent message's recipients or content.

Cited evidence

The municipality of Martigny-Combe in Valais detected unauthorised access to the business email system of its municipal secretariat on 18 August. (translated from German)

the attack made it possible to send a fraudulent message, which was distributed among others to contacts of the administration. (translated from German)

Gemeinde Martigny-Combe statement, quoted by SwissCybersecurity.net

Martigny-Combe has additionally reported the incident to the Federal Office for Cybersecurity (BACS) and to the cantonal commissioner for data protection and transparency. (translated from German)

SwissCybersecurity.net 2026-08-24

Sources1

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.