Menu
Browse

Cyber Incident Victim: Swisscom

Date:

Aug 2024

Location:

Switzerland

Summary

A major DDoS attack disrupted Swisscom's payment services, including Twint and E-Banking, causing temporary outages during midday operations before being successfully mitigated later that afternoon. While the company's internet, TV, and telephone services for private customers remained unaffected throughout the incident, technicians worked intensively to repel the unusually large-scale bombardment of server requests. All impacted digital payment functionalities resumed normal operations following the defense, though the perpetrator remained unidentified despite the telecommunications provider routinely deflecting daily cyberattacks.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On August 23, 2024, Swisscom experienced a significant distributed denial-of-service (DDoS) attack beginning at approximately 11:30 AM local time. The cyberattack targeted the telecommunications provider's infrastructure, specifically disrupting payment services including Twint mobile payments and various E-Banking platforms. Swisscom technicians immediately initiated defensive measures while working under high pressure to restore functionality. During the attack period, customers experienced service interruptions affecting financial transactions, though Swisscom's core residential services—internet access, television broadcasting, and landline/mobile telephony—remained fully operational throughout the incident. By 4:00 PM the same day, Swisscom successfully mitigated the attack and restored all affected payment systems to normal operation. Company spokesperson Annina Merk confirmed the resolution to Keystone-SDA news agency, noting that E-Banking and mobile payment services resumed functionality following the defensive actions.

Cyber Incident Image

The incident involved attackers bombarding Swisscom's servers with excessive traffic volumes, overwhelming systems responsible for processing financial transactions. While Swisscom routinely defends against daily cyber threats, company representatives characterized this midday Friday attack as unusually large in scale. Technical teams maintained continuous intensive monitoring of network systems even after mitigating the primary attack vectors as a precautionary measure. Swisscom publicly acknowledged the attack through communications with media outlet 20 Minuten, which first reported the incident, but disclosed no identifying information about potential perpetrators or their motivations. The company's infrastructure successfully isolated the attack's impact to payment processing systems, preventing collateral damage to other customer-facing services during the nearly five-hour disruption window.

Sources
Sources available to members
1 source