BERN. The Federal Office for Cybersecurity has warned of a skimming attack on Swiss food delivery services in which fraudsters replaced the familiar Twint payment option with a fake credit card form on a genuine, unmodified looking website. Customers who typed in their card details sent them straight to the criminals, and were then told, by way of cover, that card payment was in a test phase and they should use Twint after all.

The mechanics were elegant in the worst way. The attackers injected malicious code into the legitimate website of an affected provider rather than building a fake one. That is the distinction the office wants understood: phishing lures you to a counterfeit site, while skimming steals from inside the real one, and no amount of checking the web address would have saved these customers.

There was one visible tell, and almost nobody would catch it in the act of ordering dinner. The fake card form was labelled in English, on a page that was otherwise in German. The office, known by its acronym BACS, conceded that without specialist knowledge the manipulation is very difficult if not impossible to detect.

Without specialist knowledge it is very difficult, if not impossible, to spot such manipulation. The shop you trust can be the site that steals from you.

That admission carries the policy weight of the warning. If customers cannot reasonably protect themselves, the duty shifts upward: the office put the responsibility squarely on website and online shop operators to keep every system component patched, monitor the checkout’s behaviour, and restrict which sources may run code on their pages. Secure shopping, it said, is the merchant’s job to guarantee.

For anyone who has already paid the price, the advice is sequential. An unexplained credit card charge after an online purchase should raise the suspicion of skimming, even at a well known and trusted shop. Fraudulent transactions should be disputed immediately with the bank or card issuer, which can recover the money. Incidents should be reported to BACS and to the merchant, and where there is financial loss, a criminal complaint should be filed with the cantonal police, most easily via the Suisse ePolice platform.

The office did not name the affected delivery service or say how many cards were compromised. That discretion is standard while an investigation runs, but it leaves every customer of every delivery platform briefly unsure whether the warning applies to them, which is, officials privately concede, rather the point of issuing it.

E-commerce skimming of this kind, long associated with the loose collective of tactics known as Magecart, has been rising across Europe as attackers shift from phishing volume to quieter, higher yield intrusions into payment pages. Switzerland’s near universal adoption of Twint has an unexpected consequence: the fake card form works precisely because a card option feels like a service improvement.

The timing gives the warning an institutional echo. The reorganised Office of the Attorney General, which opened its new structure on 1 September with an explicit specialisation in cybercrime and crypto offences, is designed for exactly this class of case: cross border, technically intricate, and built on thousands of small thefts rather than one large one.

None of which helps tonight’s dinner order. The practical rule, until merchants prove their checkouts clean, is the one the fraudsters themselves enforced: pay with Twint. It is the option they could not fake.