Security alerts: fraudulent emails impersonating the Swiss Biotech Association Verified listing Verified listing

  • Monday, September 7, 2026 @ 10:40 am

We track and escalate fraud campaigns that target Swiss Biotech Association members and Swiss Biotech Day participants. Current campaigns are listed in the box above and updated as new ones appear. The guidance below applies to all of them. Please read it carefully and share it within your organization.

What is happening

Two kinds of fraud recur against our community.

Impersonation of our staff and events. Senders pose as Swiss Biotech Day staff or Swiss Biotech Association representatives and offer attendee lists, sponsor or exhibitor databases, sponsorship slots, hotel bookings or similar services. These offers are fraudulent. We never sell, rent or share participant data from our events, and we have no commercial partners doing so on our behalf. Anyone offering attendee lists is running a scam.

Impersonation of our online platform. Messages claim that your account on swissbiotech.org needs to be verified, reactivated or confirmed, and link to a login page that imitates ours. The page captures whatever credentials are entered. We only send an account email when you register yourself, and its link always points to www.swissbiotech.org.

Both kinds are refined continually. Sender addresses, lookalike domains and pretexts change from campaign to campaign, which is why the specifics are kept in the alert box above rather than in this text.

How to spot a fake email

  • The sender's address does not end in @swissbiotech.org or @swissbiotechday.ch. Check it character by character — lookalike domains often swap visually similar letters.
  • The email offers data, attendee lists or services we never provide.
  • You receive an account or verification email you did not trigger yourself.
  • A link's visible text and its actual destination do not match, or the link passes through a domain you do not recognize. Hover over the link and read the first domain after https://.
  • You are pressured to respond quickly, to act before a deadline, or to choose from numbered options.
  • The Swiss Biotech Association will never ask for your password or login credentials.

Be aware that several of these signals can be absent from a well-made attack. A message can pass technical authentication checks, contain no spelling errors and carry our branding accurately, and still be fraudulent. When something feels off, verify through a channel you already trust rather than through the message itself.

What to do

  • Do not reply, click links, or open attachments.
  • To check anything about your account, type www.swissbiotech.org into your browser and sign in there. Never use a link from an email for this.
  • Report the suspicious email to us, ideally with the full email headers. The reporting page explains how to forward a message so the headers are preserved.
  • Report phishing to the Swiss National Cyber Security Centre (NCSC).
  • Forward the warning within your organization. These campaigns are sent to many recipients at once, and colleagues who have not seen this page are the ones most at risk.

If you already clicked or entered credentials

  • Change that password immediately, and change it anywhere else the same password is used.
  • Enable multi-factor authentication wherever your organization's systems allow it. It is the single most effective protection once credentials have been captured.
  • Tell your IT contact, even if you are unsure whether anything was submitted. An early notice costs little; a late one can cost a great deal.
  • Let us know, so we can warn others and pursue a takedown.

How the Swiss Biotech Association communicates

As a rule, the Swiss Biotech Association always uses web and email addresses ending with "swissbiotech.org" or "swissbiotechday.ch", and will never ask you for your login information or passwords to our platforms.

If you are ever unsure whether a message is genuine, contact us directly using a known, verified @swissbiotech.org address, or through the contact details on our website. We would much rather answer a question about a legitimate email than deal with the consequences of a fraudulent one.

 

Report a suspicious email

You may also be interested in