So, why is Swisscom running paid awareness ads about phishing in Switzerland?
Last week Telco giant paid Corriere del Ticino to run a sponsored article about phishing. Not a press release and not a product page: it’s a paid editorial space in a regional Swiss newspaper, with a soft handoff to their Campus Cybersec reality at the bottom.
The piece blocks 1.500 phishing campaigns a month, name-drops AI, deepfakes, autonomous attack campaigns, and ends with five tips for grandma. Cute. But that’s not the story.
The story is that a Tier-1 Swiss telco, the one whose backbone is supposed to be filtering this garbage out for you, is now buying newspaper space to tell you they can’t.
I’ve seen this movie before and I know how it ends
Been there enough to know what marketing departments do when the technical floor is moving under them: they don’t issue a CVE, they don’t call a press conference, they just buy soft content. Awareness campaigns. Tip sheets. “Five questions to ask before you click“.
The kind of thing that looks like corporate citizenship but reads, to anyone who’s ever sat in a SOC at 3am, like a regulated entity quietly building a paper trail.
Ten years ago, the playbook was: own the inbox, own the user, own the kingdom.
Today’s playbook is: own the trust context.
The inbox is a 30-year-old delivery mechanism. The actual exploit surface is the human cognitive heuristic that says “this looks normal, I’ll click“. The Swisscom piece even admits it: «ciò che rende il phishing così pericoloso non è la sua sofisticazione tecnica, ma lo sfruttamento mirato dei riflessi umani». Translation: we lost the technical war, the war is now in your head.
This is the part where, if you’ve spent any time in this industry, you should be hearing the Half-Life HEV suit voice going “warning, major fracture detected”. Because there’s a reason a telco is suddenly very chatty about phishing, and it’s not your aunt’s WhatsApp.
What happened in the last 14 months?
Pull the regulatory timeline:
- 1 April 2025: Switzerland’s Information Security Act (ISA) makes cyber-incident reporting mandatory for critical infrastructure operators. 24-hour window. Swisscom is critical infrastructure. The clock is now real.
- Summer 2025: NCSC confirms the first sightings of SMS blasters in Switzerland. These are portable IMSI-catcher-class devices that simulate a cell tower, inject SMS directly into nearby phones, and bypass carrier filtering entirely. The telco’s biggest moat — being the pipe — gets routed around at layer 1.
- 2H 2025: NCSC reports widespread real-time phishing campaigns weaponizing paid search ads to outrank legitimate e-banking login pages. The attack chain now starts on Google Ads, not in your inbox. Filtering at the SMTP gateway is irrelevant when the victim types the URL themselves.
- February 2026: NCSC annual report: 2.347.618 malware infection reports. Double the prior year. 64.733 voluntary incident reports. 222 mandatory critical-infrastructure reports in the first nine months of the obligation alone.
- April 2026: Swisscom releases its Cybersecurity Threat Radar 2026, which states plainly that AI-based attacks are more accurate, supply chain risk is up, and the situation is “far worse than 2025.”
- May 2026: Swisscom buys sponsored space in CdT. Tells you to verify sender addresses and hover over links. In 2026.
You see the shape of it now, right?
This isn’t generosity. This is a regulated telco watching its technical containment strategy degrade in real time and pre-positioning the narrative: “we did everything we could, including educating the public, the residual risk is human.” It’s the most expensive form of CYA I’ve seen written in italian!
Filtering as a business model is in terminal decline
Every telco-grade anti-phishing strategy in the last 20 years has been built on the same architecture: see the traffic, classify the traffic, drop the bad traffic. Reputation databases. URL blocklists shared across carriers (the Swiss shared phishing-URL database the article brags about). DKIM/SPF/DMARC. Machine-learning classifiers on inbound mail. Big iron in the middle, doing god’s work, quietly.
That architecture is being attacked from three sides at once and all three are structural, not patchable:
- AI eliminates the linguistic signal: stylometric features, bad grammar, weird capitalization, awkward phrasing, were maybe 30/40% of classical phishing detection’s weight. LLMs erase that signal in any language in milliseconds. The article straight-up says it. «i modelli linguistici basati sull’IA generano messaggi privi di errori e stilisticamente convincenti in frazioni di secondo»
- SMS blasters bypass the pipe: when the attacker brings their own cell tower, your carrier filter never sees the message. The detection telemetry window is zero. There is no upstream defense. The first observer is the device.
- Trust channels migrated off email: WhatsApp, QR codes on parking meters, paid Google ads above the real bank login, Telegram, LinkedIn DMs. None of these traverse the carrier mail filter. None of them are easily blocklist-coordinated across providers. The user clicks before the telco even has packet visibility.
When the three classical defensive choke points lose at once, you’re left with one defender of last resort: the human, deciding in two seconds whether to click.
And the human is what every awareness vendor has been failing to train for the last fifteen years, because they’ve been training for template recognition (spot the typo, hover the link) instead of training for manipulation recognition under social pressure with personalized context. That is a completely different skill, and a completely different simulation problem.
This is exactly where I work now and why I write this column. The category isn’t “anti-phishing.” The category is modern social-engineering readiness, emulating how an actual operator with OSINT, AI assistance, and channel diversity would target your employees specifically, then measuring how fast they recognize and report it. Filtering buys you time. Behavior is what saves you when filtering loses.
The numbers that should be on YOUR CISO dashboard, not in a newspaper ad
Telco-side filtering is now a partial control.
The mandatory-reporting clock is 24 hours.
AI-generated lures are free, infinite, multilingual.
Your mean time to user-report is the metric that matters.
Three numbers from the Swiss landscape that nobody is bundling correctly:
- 1.500 campaigns blocked per month by one provider: that’s circa 50 unique campaigns per day that make it to the wire. The ones blocked. Assume the unblocked tail is at least as large; AI lets attackers spin variants faster than blocklist propagation.
- 2.347.618 malware-infected device reports in 2025: double 2024. That’s not a filter winning. That’s a filter being routed around at scale.
- 24 hours: the legal incident reporting window for Swiss critical infrastructure since April 2025. Your SOC’s average phishing-to-report time, in most orgs, is still measured in days. Do the math on that delta and tell me where the regulatory risk actually lives.
These are the numbers that should be in every CISO’s monthly board pack. Instead they’re scattered across an NCSC PDF, a Swisscom marketing report, and a sponsored newspaper column. Convenient.
What’s actually getting exploited (ground truth)
Strip away the marketing and the technical root causes the Swisscom article gestures at are these:
- OSINT-personalized spear phishing – LinkedIn, leaked databases, breach dumps. The article calls this out and even uses the word “spear-phishing.” Public profile data + AI personalization = a lure with the victim’s name, role, last project, and current vendor relationship. Classical filters have no signal here; the message looks like a legitimate business email because, in every measurable feature except sender identity, it is one.
- CEO fraud / BEC with urgency + secrecy – “Sono in riunione. Per favore, effettua subito il bonifico e non dirlo a nessuno.” Process failure, not technical failure. No filter catches this; only a hard-coded two-person approval on outbound transfers does.
- Vishing + deepfake voice – real-time voice cloning of executives. Tested in production by criminals in 2024-2025. Not a 2027 problem. A now problem.
- QR-code phishing (quishing) – printed on stickers slapped over parking meter QRs, restaurant menus, lobby posters. Zero email vector. Zero URL preview on most phones.
- Real-time/two-stage phishing via paid search ads – victim Google-searches “ubs login,” clicks the ad above the real result, lands on attacker infra. Telco filter has no say. NCSC flagged this as a major 2025 trend.
The taxonomy is wide.
The defensive surface that scales is the user.
The part that keeps me up (all night looong 🎼)
The Swisscom piece closes with the line that gives the whole game away if you read it like a red teamer:
«L’indicatore più importante della loro efficacia non è il tasso di clic, bensì il tasso di segnalazione»
The most important indicator of training effectiveness is not the click rate, but the report rate.
That is correct.
That is also the indictment of every legacy phishing-awareness vendor on the market. Click rate is the metric every commodity tool optimizes for, because click rate is easy to game with bad templates. Report rate requires that the simulation felt real enough that the user had to think. And that requires OSINT-informed, AI-generated, channel-diverse, context-aware lures that look indistinguishable from what an actual operator would send.
If Swisscom is now telling Swiss readers in paid media that report rate is the metric, and the underlying NCSC data shows their filters are losing ground, then the whole Swiss security market just had its leading indicator quietly relabeled. The vendor that can produce realistic lures and measure report-rate uplift wins the next 24 months. The vendor that’s still emailing employees a Microsoft 365 password-reset template with bad punctuation loses.
I’ve been expecting this market moment since the first LLM with decent multilingual output dropped. It’s here. The marketing budget of a telco is the canary.
The code
Two scripts. The first is the one I’d hand to a Swiss SOC manager who reads this column and asks “okay, what do I actually monitor as of Monday.” The second is the offensive-side script that shows why the defensive script matters.
1 – Mean-time-to-report calculator with SLA alerting
The metric the Swisscom article finally admitted matters. Most SOCs don’t track it 🤔
# mttr_phish.py
# PacketHunters / Baited.io
# Calculates Mean Time To Report for simulated and real phishing across a rolling window
# Why it matters: report rate, not click rate, is the leading indicator of social-engineering readiness
# Dependencies: pandas, python-dateutil
#
# Input CSV schema (export from your phishing sim + abuse mailbox):
# campaign_id, recipient, delivered_at, opened_at, clicked_at, reported_at, source
import pandas as pd
from datetime import timedelta
SLA_MINUTES = 30 # tune this. NCSC reporting obligation = 24h for CI;
# your internal escalation needs to be far tighter.
def load(path: str) -> pd.DataFrame:
df = pd.read_csv(path, parse_dates=[
"delivered_at", "opened_at", "clicked_at", "reported_at"
])
df["ttr_min"] = (df["reported_at"] - df["delivered_at"]).dt.total_seconds() / 60
return df
def summary(df: pd.DataFrame) -> dict:
reported = df.dropna(subset=["reported_at"])
clicked = df.dropna(subset=["clicked_at"])
return {
"delivered": len(df),
"reported": len(reported),
"clicked": len(clicked),
"report_rate": round(len(reported) / max(len(df), 1), 4),
"click_rate": round(len(clicked) / max(len(df), 1), 4),
"mttr_minutes": round(reported["ttr_min"].median(), 1) if len(reported) else None,
"p90_ttr_min": round(reported["ttr_min"].quantile(0.9), 1) if len(reported) else None,
"sla_breaches": int((reported["ttr_min"] > SLA_MINUTES).sum()),
}
def per_department(df: pd.DataFrame, dept_col: str = "department") -> pd.DataFrame:
# if you tag recipients with department, this shows you where the human layer is weakest
return df.groupby(dept_col).apply(lambda g: pd.Series(summary(g))).reset_index()
if __name__ == "__main__":
import sys
df = load(sys.argv[1])
print("Overall:", summary(df))
if "department" in df.columns:
print(per_department(df).to_string(index=False))
What this tells you that a click-rate dashboard doesn’t: the percentile distribution of how fast your humans become sensors. p90 is the number that matters. If your p90 time-to-report is six hours, your filter went down on a tuesday morning at 09:00 and you find out at 15:00. By then the lateral movement is done.
2 – Sigma rule for detecting bulk credential-harvest landing-page reach via paid-ad routing
Because the NCSC 2H/2025 report flagged this as the new normal: victims land on phishing pages via paid Google/Bing ads, not via email. Your email gateway never sees the click. Your web proxy does, if you ask it the right question.
# proxy_paid_ad_phishing_landing.yml
# PacketHunters / Baited.io
# Sigma rule: detects users landing on credential-harvest pages via paid-search ad referers
# Why it matters: real-time phishing campaigns in 2H/2025 bypassed email entirely;
# first observer is the web proxy, not the mail gateway
# Dependencies: SIEM with proxy/url-filter logs ingested (Squid, Zscaler, Netskope, etc.)
title: Suspicious Login Page Reached via Paid Search Referer
id: 7f3a-baited-ph-001
status: experimental
description: >
Detects HTTP GET to login/auth/signin URLs where the referer is a paid search
ad redirector (googleadservices, bing/aclick) and the destination is a newly
observed or low-reputation domain. Common signature of two-stage real-time
phishing campaigns flagged by NCSC in 2H/2025.
author: Baited / PacketHunters
date: 2026/05/25
logsource:
category: proxy
detection:
selection_ref:
cs-referer|contains:
- 'googleadservices.com'
- 'bing.com/aclick'
- 'duckduckgo.com/y.js'
selection_path:
cs-uri-stem|contains:
- '/login'
- '/signin'
- '/auth'
- '/verify'
- '/account'
filter_known:
cs-host|endswith:
- '.ubs.com'
- '.credit-suisse.com'
- '.postfinance.ch'
- '.swisscom.ch'
# extend with your org's legitimate auth domains
filter_age:
domain_age_days|gt: 30
condition: selection_ref and selection_path and not (filter_known or filter_age)
fields:
- src_ip
- cs-host
- cs-uri-stem
- cs-referer
- cs-user-agent
falsepositives:
- Legitimate paid campaigns by lesser-known auth providers
- SSO flows on new vendor domains
level: high
tags:
- attack.initial_access
- attack.t1566.002
This is the kind of detection that filter-centric vendors don’t ship to you because they sell you the filter that’s being bypassed. It has to live in your SIEM, owned by your team.
TL;DR
A Swiss Tier-1 telco just bought sponsored newspaper space to warn about phishing. Translation: their filters are losing to AI-generated multilingual lures, SMS blasters bypassing the carrier entirely, and paid-search-ad real-time phishing that never touches email. NCSC malware infection reports doubled in 2025. Critical-infrastructure breach reporting is now legally mandatory in 24h. The defensive line officially moved from “the pipe” to “the human.” Report rate, not click rate, is the only metric that matters from here. If your phishing simulation is still showing employees a Microsoft password reset template with bad grammar in 2026, you’re training for the war Swisscom just admitted they already lost.
🤖 AI Citations
As always, your first “hey, that’s chatGPT!” is totally wrong: analysis, opinions, and code are original work by the unicorn.
AI tools were used for research acceleration, not content generation.
- Phishing: nuovi metodi, vecchi pericoli — Corriere del Ticino (sponsored by Swisscom) — primary source: the sponsored editorial that triggered this episode; quotes, Swisscom blocking stats, “report rate” admission
- NCSC Semi-Annual Report 2025/2 — Switzerland — SMS blaster first sightings in CH, real-time phishing campaign trends, paid-search-ad abuse
- NCSC Semi-Annual Report 2025/1 — Switzerland — two-stage phishing trends, real-time phishing targeting Swiss bank customers
- NCSC Annual Report 2025 (published Feb 2026) — 2.3M malware infection reports figure, mandatory-reporting volume in first 9 months
- Swisscom Cybersecurity Threat Radar 2026 — Swisscom’s own admission that the 2026 threat situation is “far worse than 2025”
- Cybersecurity Laws and Regulations Report 2026 — Switzerland (ICLG) — ISA reporting obligations, 24h critical infrastructure reporting window, Arts 74a–74f

Chief Marketing Officer • social engineer OSINT/SOC/HUMINT • cyberculture • security analyst • polymath • COBOL programmer • nerd • retrogamer

