Lyce · Hybrid Watch

hw_0d904f6d4f5de56b

DDoS attacks hit multiple Swiss municipal, bank and canton websites during the World Economic Forum summit in Davos.

Swiss media reported that a wave of distributed-denial-of-service (DDoS) attacks — believed to be carried out by a pro-Russian hacker group — temporarily disrupted the websites of several Swiss cantons (Schaffhausen, Geneva, Sierre) and some banking entities. The Swiss National Cyber Security Centre (NCSC) had earlier issued a warning that such attacks would likely coincide with the WEF summit, and identified the group NoName057(16) as a likely actor. Although the impact did not extend to confirmed physical damage or network penetration, the incident demonstrates how Switzerland’s governmental and financial infrastructure can be targeted via cyber means in a hybrid-warfare context. The fact that attacks were launched during a high-profile event in Switzerland shows that hybrid threats may exploit timing and symbolic targets rather than frontier zones. The dynamics reveal how adversaries may shift from intelligence-gathering to active disruption of service, increasing uncertainty and forcing resource allocation to defence rather than purely operations.

Occurrence
2025-01-21
Publication
2025-01-20T23:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
CH
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2025-01-20T23:00:00Z

    Swiss media reported that a wave of distributed-denial-of-service (DDoS) attacks — believed to be carried out by a pro-Russian hacker group — temporarily disrupted the websites of several Swiss cantons (Schaffhausen, Geneva, Sierre) and some banking entities. The Swiss National Cyber Security Centre (NCSC) had earlier issued a warning that such attacks would likely coincide with the WEF summit, and identified the group NoName057(16) as a likely actor. Although the impact did not extend to confirmed physical damage or network penetration, the incident demonstrates how Switzerland’s governmental and financial infrastructure can be targeted via cyber means in a hybrid-warfare context. The fact that attacks were launched during a high-profile event in Switzerland shows that hybrid threats may exploit timing and symbolic targets rather than frontier zones. The dynamics reveal how adversaries may shift from intelligence-gathering to active disruption of service, increasing uncertainty and forcing resource allocation to defence rather than purely operations.