Organised crime players are considered to pose a similar threat, as they usually also have
professional organisations, major financial resources and specific capabilities at their
disposal. Their intention to achieve personal gain and their massive, sustained and
organised cyber attacks on the economy (e.g. the financial system) and individuals can
cause considerable economic damage and jeopardise the credibility of the rule of law.
Among others, the ZeuS Trojan 6 has been used against online banking clients for
many years. The malware is introduced into the IT infrastructure of private persons via
forged or manipulated websites. The attackers can subsequently pirate telebanking
services and thereby divert money from accounts.
Attacks on public and private sector websites by so-called "hactivists" have been becoming
increasingly important recently. These non-governmental, individual or loosely organised
groups which can potentially attack on a massive scale have good technical skills. The
potential for damage resulting from massive attacks by these players is considered to be
medium to high. "Hactivists" seek to interrupt services, cause financial damage and destroy
reputations in order to mobilise public attention for their concerns.
In December 2010, the hacker group "Anonymous" called for an attack on
PostFinance. As a result, its Internet services were interrupted for an entire day. This
was triggered by the closure of the postal giro account of WikiLeaks founder Julian
Assange. In 2007, Russian activists launched a massive attack on Estonian information
and communication infrastructure because of the relocation of a Soviet military
monument in Tallinn. For several days, the e-government offering and online services
of numerous companies could no longer be used. Furthermore, websites of
government offices and firms were defaced with pro-Russian slogans.
Terrorists use cyberspace to spread propaganda, radicalise followers, recruit and train
members, raise funds, plan campaigns and provide information on them. Up to now, the
focus has been on using information and communication infrastructure, but not on attacking
it: terrorists still aim mainly at carrying out serious physical attacks against life and limb as
well as infrastructure by conventional means. Cyber attacks motivated by terrorism with very
high consequential physical damage appear unlikely from today's perspective. However, it
cannot be excluded that terrorists could try to launch cyber attacks on a country's critical
infrastructure in the future. Even if Switzerland was not a direct target, the cross-border
implications (e.g. electric power failure or financial market disruptions) could affect
Switzerland.
There has been no concrete example of cyber terrorist attacks to date. However, the
websites of terrorist organisations and of organisations associated with terrorism are
continually being monitored for calls for violence and indications of imminent attacks
(e.g. Jihad websites).
Moreover, unforeseeable events or accidents such as system breakdowns due to premature
wear and tear, overloading, faulty construction, poor maintenance or the consequences of
natural disasters can also lead to infrastructure breakdowns or disruptions with similarly
serious effects.
6
Software with malicious functions (also called malware or malicious software).
11/42