CSIDB logo
Incident

Swiss Federal Department of Defence, Civil Protection and Sports

Incident posture

Attack window
Jul 2017
Location
Switzerland
Status
Historical
CIA posture
Available to members
Updated
2026-07-11 08:56

Linked entities

Victim
Swiss Federal Department of Defence, Civil Protection and Sports
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Switzerland's defence ministry successfully thwarted a cyber attack employing malware resembling the Turla spyware family, detected during routine monitoring. The intrusion attempt triggered immediate countermeasures by government specialists, though authorities withheld details regarding the attack's origin or potential impacts such as data compromise, citing security protocols. An ongoing investigation was initiated alongside criminal charges filed against unidentified perpetrators. The Turla malware, previously linked to widespread infections targeting government and military systems across multiple regions, was suspected in this incident but no operational damage was confirmed.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Swiss Federal Department of Defense, Civil Protection and Sports detected a cyber attack targeting its systems in July 2017. Government specialists identified malware exhibiting operational characteristics consistent with the Turla malware family, which had been previously documented in global cyber espionage campaigns. The attack was discovered through defensive monitoring systems, though specific technical details about the intrusion vector or compromised systems were not disclosed. Swiss authorities implemented immediate countermeasures to neutralize the threat and secure affected infrastructure. No official statements confirmed whether data exfiltration or operational disruptions occurred during the incident. The government declined to attribute the attack to any specific threat actor or nation-state, citing ongoing security considerations. Federal prosecutors initiated criminal proceedings against unidentified perpetrators following standard legal protocols for cyber incidents.

Security researchers noted that Turla malware had been associated with sophisticated espionage operations since at least 2014, with historical attacks targeting government and military entities across Europe and the Middle East. Multiple independent analyses by cybersecurity firms and Western intelligence agencies had previously suggested potential links between Turla operations and Russian state-sponsored actors, though Swiss authorities did not endorse these assessments in their public communications. The incident prompted an ongoing internal investigation to determine the full scope of compromise and enhance defensive capabilities. No collateral damage to civilian infrastructure or allied systems was reported in connection with this event. The ministry maintained standard operational continuity throughout the response period while restricting public disclosure to minimal factual updates.

Sources

Sources available to members: 1 source.

CSIDB