Liechtenstein Trust Register Hacked: 31,000 Records Stolen

Liechtenstein Trust Register Hacked: 31,000 Records Stolen

Liechtenstein has roughly 40,000 residents and about 31,000 registered legal entities – companies, foundations, and trusts that manage billions in assets. On the night of July 29, 2026, unknown attackers breached the government register that records who actually owns those entities. By morning, they had everything. Names, birth dates, nationalities, countries of residence. All 31,000 … Read more

AI Guardrails vs. Pentesting: When Safety Measures Block the Wrong People

Let’s be honest: if you develop offensive security tools with AI today, you know this moment intimately. You describe a perfectly legitimate pentesting task to a model – and get refused. “I can’t help with that.” Or the classic: “This request could be used for malicious purposes.” Yes. We know. That’s literally the job. The … Read more

Crypto Wallet Phishing by Mail: When Cybercriminals Use the Postal Service

At the end of July, Switzerland’s BACS issued a warning about an attack method that feels almost retro: criminals sending physical letters through the post. Actual paper letters with a QR code, telling recipients to install a supposed security update for their crypto wallet. Anyone who follows those instructions loses their cryptocurrency. Every last coin. … Read more

AI Deepfakes: What Swiss SMEs Need to Know Now

Switzerland’s Federal Office of Cybersecurity (BACS) dedicated three consecutive weekly reviews in July to AI-generated content. Images, text, video – all manipulated, all disturbingly convincing. Three weeks straight on the same topic. That alone tells you something about how urgent this has become. We went through the BACS publications, cross-referenced them with international studies, and … Read more

Fake Voicemail Notifications: Microsoft as Bait

In late June, BACS flagged a wave of fake voicemail notifications landing in inboxes via email. The message looks like an automatic notification from Microsoft 365 or another phone system: “You have received a new voice message. Click here to listen.” Click the link, and you land on a fake login page. The goal: your … Read more

Hotel Phishing via WhatsApp: When the Booking Confirmation Becomes a Trap

Picture this: you’ve just booked a hotel in Barcelona. Confirmation email received, trip sorted, looking forward to it. Then a WhatsApp message arrives – with the right hotel name, the right dates, the right price. “Your payment could not be processed. Please confirm your credit card details via the following link, otherwise your booking will … Read more

Cyber Resilience: What CISA’s CI Fortify Initiative Means for Swiss SMEs

On 5 May, the US Cybersecurity and Infrastructure Security Agency CISA launched an initiative that, on the surface, seems relevant only for operators of critical infrastructure: CI Fortify. The core message: organisations should prepare to keep their essential processes running even when IT systems are compromised, telecommunications fail, and internet connections go wobbly. All at … Read more

Double Phishing: When the Text Message Is Followed by a Call

In early May, Switzerland’s BACS described an attack pattern we keep running into during client engagements – yet most people still underestimate it: double phishing. Sounds like a marketing buzzword. It’s not. It’s exactly what happens. First comes an SMS. Classic setup: “Your package could not be delivered.” Click the link, enter your details – … Read more

Password Recycling: The Most Expensive Habit in Your Company

BACS dedicated a weekly review in late April to password reuse. Their message: anyone who uses the same password across multiple services risks having a single data theft compromise all their accounts. Sounds obvious, right? And yet – look at the numbers and you realise most organisations still haven’t got the memo. Credential stuffing – … Read more