Take our masterclass
Sealed steel bank door beside a small brass intercom

by Roman Balzan

Chief Marketing and Brand Officer at Alpian

Roman Balzan, Chief Marketing and Brand Officer at Alpian

The vault has never been harder to break into. Which is roughly why nobody bothers trying any more.

Last verified: July 2026

Key takeaways

  • Switzerland’s National Cyber Security Centre processed 64,733 voluntary incident reports in 2025, around 2,000 more than the year before. Volume is stabilising. Sophistication is not.
  • Payment fraud across the European Economic Area reached EUR 4.2 billion in 2024, up 17% year on year, with credit transfers the largest single category by value.
  • The direction of travel has flipped. Across a large European fraud dataset, phishing cases fell 8% in 2025 while social manipulation scams rose 33%.
  • For credit-transfer fraud in the EEA, payment service users bore around 85% of the losses, largely because they authorised the payments themselves.
  • The defence that scales is not a better firewall. It is a client who recognises the pattern before the transfer leaves.

How much banking fraud is there in Switzerland?

Switzerland’s National Cyber Security Centre processed 64,733 voluntary reports of cyber incidents in 2025, roughly 2,000 more than in 2024. That is a modest increase by recent standards, and it is the least interesting number in the dataset. What matters is the composition. Reports about calls purporting to come from the police still dominated the year, but the fastest-moving category was online investment fraud, which rose sharply through the second half.

The NCSC also recorded 970 cases of CEO fraud in 2025, up from 719 the year before, a 35% increase. Separately, its half-year analysis noted widespread voice phishing and real-time phishing campaigns, often combined with paid search advertisements that steered victims towards convincing fake websites. From the summer of 2025, so-called SMS blasters appeared in Switzerland for the first time: devices that imitate a mobile network antenna and push messages straight to nearby phones, bypassing the filters telecommunications providers use to catch them.

None of this describes an attack on a bank’s infrastructure. All of it describes an attack on the person holding the phone.

What is authorised push payment fraud?

Authorised push payment fraud is a scam in which the victim is manipulated into transferring their own money to a criminal, using their own credentials and their own consent. There is no hacking, no stolen card, no breached login. The payment is genuine in every technical sense. Only the reason for it is fabricated.

This is why it has become the most damaging category in European payments. The joint EBA and ECB report on payment fraud put total fraud across the European Economic Area at EUR 4.2 billion in 2024, a 17% increase on the previous year, of which credit transfers accounted for the largest share by value. The distribution of the loss is the part worth reading twice: for credit transfers, payment service users bore roughly 85% of the total. When you authorise the payment, you generally carry the loss.

Instant payment rails compress the window further. Where a multi-day clearing period once gave banks and clients time to notice something was wrong, funds can now cross borders in seconds and enter a chain of accounts designed to break the trail.

Why has fraud moved from hacking to manipulation?

Because the technical route stopped paying. Strong customer authentication, introduced across the EU under PSD2 and mirrored in Swiss practice, measurably reduced the return on classic card and credential fraud. Criminal economics did what criminal economics does: it moved to the cheaper target.

The data shows the handover clearly. One European fraud dataset covering 4.9 billion transactions recorded phishing cases falling 8% in 2025 while social manipulation scams rose 33%. The year before, the same programme had recorded a 43% jump in attempted fraud, with social manipulation up 156% and phishing up 77%. Read together, those two years tell a single story: the technical attack surface is shrinking, and the human one is being worked harder.

Artificial intelligence sits on both sides of the trade. It generates synthetic voices, cloned websites and phishing messages that no longer betray themselves through bad grammar. It also powers the detection models that flag anomalous behaviour in real time. The advantage goes to whichever side adopts faster and shares data better, which is a very different contest from the one banks were preparing for a decade ago.

Are digital banks more exposed to fraud?

Digital banks are not less secure than traditional ones, and in several respects their systems are newer and more tightly instrumented. What differs is the shape of the exposure, and it comes in three parts.

Pressure pointWhy it applies to digital banksWhat it does not mean
SpeedInstant, frictionless transfers are the product. In fraud, the same speed compresses the window for intervention.That the transfers are less protected. Authentication standards are the same or higher.
OnboardingRemote identity checks are probed continuously with altered documents and synthetic biometrics, often to open mule accounts rather than to steal directly.That remote onboarding is inherently weaker. It is simply the door that gets tried most often.
Mobile fluencyClients are comfortable acting on a phone notification, which is exactly the channel impersonation attacks now favour.That mobile banking is unsafe. It means the message, not the app, is the weak link.

The conclusion is not that one banking model is safer than another. It is that in every model the decisive layer has moved outward, from the institution’s systems to the client’s judgement. Swiss banks, including FINMA-licensed digital institutions such as Alpian, invest continuously in authentication and transaction monitoring. If the deception is complete before the app is ever opened, those systems arrive late.

What is the Swiss financial sector doing about it?

The Swiss response is deliberately collective rather than institutional. The Swiss Bankers Association’s preliminary study on collaborative fraud prevention, carried out with a group of banks including UBS, PostFinance, Raiffeisen, Julius Baer, Migros Bank, BCV, ZKB, Entris Banking and SIX, recommended three measures: joint public awareness campaigns, a network-level risk scoring service, and structured exchange across industries.

All three are now moving. The awareness work runs under a shared prevention brand rather than a dozen competing bank campaigns. The risk scoring concept would give a sending bank a real-time signal about the receiving side of an account-to-account payment, computed across the network rather than inside one institution. And in mid-2026 the Swiss Anti-Fraud Summit, convened by the Swiss Bankers Association and SIX, produced a collaborative platform intended to connect banks, telecommunications providers, online marketplaces, platforms and law enforcement along the whole fraud chain.

The logic behind all of it is that fraud does not begin inside a bank. It usually begins on a social platform, a marketplace listing or a phone call, and only arrives at the payment system at the very end. A defence that starts at the payment system starts too late.

Why not simply block more transactions?

Because the cost of false positives is real and falls on legitimate clients. Blanket restrictions would stop a share of fraudulent payments and a much larger share of ordinary ones: the rent transfer, the invoice, the deposit on a flat, the money sent to a relative. Fraud prevention has to hold three things at once, namely security, the rule of law and proportionality, and a system that fails the third loses the trust it was built to protect.

This is the honest version of the trade-off, and it is why the sector keeps returning to information rather than restriction. A client who recognises a manipulation attempt at the moment it happens costs nothing, blocks nothing legitimate, and is the only control that works before the payment exists.

How to check that a contact really came from your bank

Alpian publishes the domains circulating under its name, the red flags to watch, and where to report an approach.

See Alpian’s security page

Frequently asked questions

How common is bank fraud in Switzerland?

Switzerland’s National Cyber Security Centre processed 64,733 voluntary cyber incident reports in 2025, around 2,000 more than in 2024. Fraud is consistently among the most frequently reported categories. Online investment fraud grew notably through the second half of the year, and CEO fraud rose 35% to 970 reported cases.

What is the most common type of banking fraud today?

Social engineering, in which the account holder is manipulated into authorising a payment themselves. Across a large European dataset, social manipulation scam cases rose 33% in 2025 while phishing cases fell 8%. In the EEA, users bore roughly 85% of credit-transfer fraud losses, precisely because they authorised the transfers.

Are digital banks in Switzerland safe?

Swiss digital banks operate under the same FINMA licensing regime and the same authentication requirements as traditional banks, and their deposits are protected under the Swiss depositor protection scheme up to CHF 100,000 per client. The exposure that differs is speed and mobile-first communication, which affects how fraud reaches clients rather than how well the bank is regulated.

Can money lost to an authorised transfer be recovered?

Often not. Because the client authorised the payment with valid credentials, it is technically a legitimate transaction, and instant payment rails can move funds across borders within seconds. Recovery depends on how quickly the receiving institution can be reached. Prevention is far more reliable than recovery.

Who should I contact if I suspect a scam using a Swiss bank’s name?

Contact the bank directly through a channel you have verified yourself, never through a number or link supplied by the person who contacted you. FINMA publishes a warning list of unauthorised providers, and Switzerland’s National Cyber Security Centre accepts reports of cyber incidents from the public. Alpian asks clients to forward suspicious approaches to fraud-report@alpian.com.

Swiss banking security is not a fixed state, and the sector’s own framing is not that fraud will be eliminated but that the defenders should stay faster and better connected than the networks working against them. The infrastructure holds. Deposits at FINMA-licensed Swiss banks, including digital institutions backed by groups such as Intesa Sanpaolo, sit inside a supervised and insured framework. The variable is no longer the vault. It is the conversation that happens just before someone decides to open it.

Sources

About the author

Roman Balzan

Roman is Chief Marketing and Brand Officer at Alpian, Switzerland’s first FINMA-licensed premium digital bank with private banking services, where he also leads the company-wide AI adoption programme.

He holds a Master’s degree in economics from the University of St. Gallen HSG and built his career across entrepreneurship and brand leadership: co-founding Suxedoo.ch, leading employer brand marketing programs at Google in EMEA, and launching Lime’s first European market, Switzerland, before heading the company’s EMEA marketing and brand efforts. He once walked 2,300 km on the Camino de Santiago with his dog Nelson, from St. Gallen to Santiago de Compostela.

He writes the AI stream of Alpian’s weekly editorial, on the human side of AI in banking.

Connect with Roman on LinkedIn →

This website uses cookies to improve your experience.