Translated by an automated translation plugin.
At the end of March, two sources of data on cyber threats in Switzerland were published in parallel: the police crime statistics and the semi-annual report of the Federal Office for Cyber Security (BACS). Although both sources deal with cyber incidents at first glance, they cover different areas and are not directly comparable. However, this is precisely why it is interesting to look at the two statistics together.
Police crime statistics use the collective term cybercrime to cover offences committed in the digital space - i.e. involving telecommunications networks or the internet. These offences are broken down into the following categories depending on how they were committed:
A look at the figures (see interactive graphic below) makes it clear that the vast majority of incidents can be attributed to cyber economic crime. It is also this category that is responsible for the continued steep rise in cybercrime cases up to 2024, which has levelled off at a high level since then. The number of cases in the remaining categories has either remained constant over time (cyber sexual offences), declined slightly (cyber defamation of character and dishonest behaviour) or remained volatile at a very low level (illegal trading on the darknet and data leaking). Regardless of the category, it is likely that not all actual offences were reported, with the number of unreported cases varying greatly depending on the category(FSO 2026).
The interactive chart on cybercrime statistics allows you to browse the data according to your interests. This is how it works:
When analysing the figures for economic cybercrime, it is noticeable that "hacking" - a term that is often still used colloquially as a synonym for many cybercrimes - is ultimately much less significant than phishing, for example. The latter category, which encompasses strategies for acquiring personal or confidential data in an unauthorised manner, also shows the most significant increase across all offences. The number of cases has increased fivefold since 2021 to over 7,400 cases in 2025.
In terms of volume, however, another subcategory of cyber white-collar crime outstrips all other offences: cyber fraud. The almost 40,000 offences recorded in this category in 2025 include offences as diverse as the misuse of online payment systems or foreign identities, fraud with classified ads or fake real estate ads, romance scams and the currently rampant CEO fraud (see box).
The BACS also regularly warns against this scam. To prevent an incident as far as possible, BACS recommends setting up the following technical and organisational hurdles:
A comparison of the figures in the cybercrime statistics with the voluntary reports of cyberthreats by the public and businesses contained in the BACS semi-annual report reveals similar trends. Here too, cyber fraud and phishing are responsible for the majority of cases.
However, the BACS figures are particularly interesting when looking at the first reportable cyber incidents. Since 1 April 2025, operators of critical infrastructures such as energy or drinking water supply organisations, transport companies and cantonal and municipal administrations have been obliged to report cyber attacks to the BACS within 24 hours of their discovery.
This shows that hacking is the most common type of attack on critical infrastructure (20%). In addition, the theft of access data (14%), DDoS attacks (13%), i.e. attacks on the availability of an infrastructure, and the use of malware (11%) also play important roles.
Finally, it is interesting to see the distribution of the 145 reportable cyber incidents in the second half of 2025. The most affected were public administrations (25%), IT and telecommunications providers (18%), the financial and insurance sector (16%) and energy providers (12%).
This brief data analysis makes it clear that SMEs and private individuals are not affected by the same types of attack as operators of critical infrastructures. What they all have in common is that they should inform themselves about possible threats and be aware of the current methods used by cyber criminals. This is the only way to take the necessary security precautions. A reliable source of information in this regard is the BACS, which provides specific information for private individuals, companies and authorities.
| Role | Title + Name |
|---|---|
| Text by | Tobias Schlegel |