Almost every cyberattack that hits an SME starts the same way: an e-mail. Not a spectacular server intrusion, not some obscure technical flaw. An ordinary message, opened on a Tuesday morning by someone in a hurry.
That is what makes phishing both so mundane and so dangerous. It does not target your machines, it targets your employees. And the good news is that it can be recognised, provided you know what to look for.
What exactly is phishing?
The principle can be summed up in one sentence: an attacker pretends to be someone you trust, in order to get you to do something you would never otherwise do.
That “something” takes three main forms. Entering your credentials on a fake site that looks exactly like the real one. Opening an attachment that installs malicious software. Making a payment or handing over information to someone who is not who they claim to be.
In Switzerland, the phenomenon is massive. The National Cyber Security Centre (NCSC) received 64,733 voluntary cyber-incident reports in 2025, up from 62,954 the year before. In the second half of 2025 alone, phishing accounted for 6,299 reports, and fraud in the broad sense for 15,090 reports, or 52% of the total.
These figures only count reported cases. Most attempts are never reported. Our page on cybercrime in Switzerland in figures details what these reports cover and their limitations.
The six warning signs to know
No single signal on its own proves that a message is fraudulent. It is the accumulation that should alert you.
| Signal | What it looks like in practice |
|---|---|
| Urgency | ”Your account will be blocked in 24 hours”, “final reminder before suspension” |
| An unusual request | You are asked for a password, an urgent payment, a card number |
| A mismatched link | The text shows a familiar name, but the real address points elsewhere |
| An approximate sender address | A domain that is almost right, with an extra letter or a different extension |
| An unexpected attachment | An invoice, a delivery note or a quote you were not expecting |
| Bypassing the rules | ”Don’t tell anyone”, “deal with this directly with me” |
The most reliable signal remains the combination of urgency and an unusual request. An attacker needs you to act without thinking. Any pressure on time should therefore trigger exactly the opposite: a pause.
To check a link without risk, simply hover the cursor over it without clicking. The real address appears at the bottom of the window, or in a bubble on a phone. Read it from right to left up to the first slash: that is where the real domain is.
Four examples you will see in Switzerland
The campaigns that work here imitate players everyone knows. Here are the four most common scenarios.
The fake parcel notice from the Post. A message announces that a parcel could not be delivered and that customs clearance fees of a few francs must be paid. The amount is deliberately small, so as not to raise suspicion. The form then asks for the full card number. The tipping point: a carrier never asks for card details by e-mail for a parcel you were not expecting.
The fake Swisscom or telecom invoice. The e-mail imitates the real layout, with logo, customer number and a plausible amount. It announces an unpaid bill and threatens to cut off the line. The link leads to a copy of the customer portal. The tipping point: open your customer account by typing the address yourself into the browser, never from the link in the message.
The fake banking message. It refers to a suspicious transaction to confirm, or a new authentication procedure to activate. Some variants are followed by a phone call from a supposed advisor, who reassures and guides the victim. The tipping point: no Swiss bank asks for your access codes, or asks you to validate a transaction you did not initiate.
The fake internal IT department. This is the most effective one within a company. A message signed “IT Support” announces an e-mail migration and asks you to log in again to avoid losing your e-mails. The page looks like your usual webmail. The tipping point: your IT department will never ask for your password, neither by e-mail nor by phone.
The name that appears in your inbox is a free-form label, which the sender chooses themselves. An attacker can write "Swiss Post" or your manager's name there. Worse, the message may genuinely come from a partner's mailbox whose account has been compromised: in that case, every technical check passes. Only verification through another channel provides certainty.
The reflex that neutralises almost everything
A single habit is enough to defuse most attacks: verification through a second channel.
Does the message ask you for a transfer? Call the person. Does it announce a problem with your account? Log in by typing the address yourself. Does IT support write to you? Pop your head into their office, or phone them.
The absolute rule comes down to one nuance that changes everything: use a number you already know, never the one given in the message. Fake e-mails often contain a contact number, and the attacker is on the other end of the line.
This reflex also protects against more elaborate variants, such as CEO fraud, where a fake executive demands an urgent, confidential payment, or more broadly against social engineering.
What to do if someone has already clicked?
It happens, even to attentive people. What matters is how quickly you react.
Within minutes. Disconnect the machine from the network, by unplugging the cable or turning off Wi-Fi, without shutting it down. Notify your IT manager immediately.
Within the hour. Change the affected password from another device, along with any account where it was reused. Enable two-factor authentication wherever it is not already in place.
Within the day. Check the mailbox settings: attackers often create an automatic forwarding rule to keep reading messages after the password change. If a payment was made, contact the bank without delay, since a recent transfer can sometimes still be recalled. Finally, report the incident to the NCSC.
If personal data belonging to customers or employees is involved, a notification to the Federal Data Protection and Information Commissioner may be required. As a rule, this assessment must be made quickly: the detail of these obligations is covered in our article on your FADP obligations. For the full timeline of an incident response, see the first hours.
The worst-case scenario for an SME is not that an employee clicks, it is that they do not dare say so. A few hours of silence are enough to turn a manageable incident into a disaster. Tell your teams explicitly: reporting a mistake will never be punished, delaying it is the only real problem.
How to reduce the risk in the long run?
Individual vigilance is essential, but it has a limit: it depends on one person’s attention at a given moment. A few technical measures make up for moments of fatigue.
Enable two-factor authentication on e-mail and remote access. This is the measure with the best ratio between effort and protection: even if stolen, a password is no longer enough.
Properly configure the protections on your business e-mail, in particular the mechanisms that prevent your own domain name from being spoofed.
Maintain backups that follow the 3-2-1 backup rule, since an unfortunate click can also trigger a ransomware attack.
Finally, keep up the collective reflex, by running a short, regular awareness programme rather than an annual session. Well-run phishing simulations measure your team’s real level and give concrete opportunities to talk about it. However, they only work in a company where reporting a mistake carries no risk, which is built as explained in our article on a security culture without blame.
According to the SME Cybersecurity 2025 study, 42% of Swiss SMEs consider their protection sufficient, down from 55% a year earlier. This decline is not bad news: it reflects growing awareness. What remains is to turn it into concrete measures.
To gauge your company’s position, the cyber check-up devotes several questions to e-mail and verification reflexes. The other attacks targeting Swiss SMEs are detailed in the Threats pillar.