cybersecurity
Cybersecurity office warns of fake card-payment trap on food-delivery site
The Federal Office for Cybersecurity has warned that fraudsters injected malicious code into a food-delivery website, replacing Twint with a fake credit-card payment option. Customers who entered their details may have sent them directly to criminals, underscoring the risks of compromised legitimate websites.

Criminals Hijack a Trusted Checkout
A familiar food order became a route to payment data. The Federal Office for Cybersecurity has warned that criminals tampered with the payment page of a food delivery service in Switzerland, placing customers at risk while they used a legitimate website. The agency said attackers injected malicious code into the site and replaced the provider’s original Twint option with a fraudulent credit card payment choice.
Customers who selected the fake option saw a pop-up asking for their card details. The information went directly to the attackers. A subsequent error message claimed that credit card payments were still in a testing phase and told customers to use Twint instead. That message may have allowed the compromised checkout to appear routine after the data had already been stolen.
The warning, published on September 1, 2026, highlights a difficult problem for Swiss consumers. A familiar domain, a normal ordering process and a genuine business do not guarantee that every element of a web page remains safe. The compromise occurred inside the trusted service itself, at the point where customers expected to complete payment.
How Skimming Evades the Usual Checks
The fake form carried a clue that customers could have noticed. The payment pop-up was written in English, while the rest of the affected page was in German. That language mismatch did not prevent the form from collecting details, but it offered a warning sign for users familiar with the site’s normal Swiss payment flow.
The Federal Office for Cybersecurity classifies the method as skimming. In e-commerce skimming, criminals insert code into a genuine online shop and capture payment information as customers enter it. Phishing follows a different route, sending people to an imitation website designed to look like the real one. The distinction matters because standard advice to check the web address may not expose a skimming attack on a legitimate domain.
Consumers should treat unexpected payment choices, unfamiliar wording and sudden changes in a checkout process as reasons to stop. They should avoid entering card numbers into a newly appearing form and contact the retailer through an independent channel. The source did not identify the affected provider or state how many customers entered their details, so the scale of the incident remains unclear.
Move Fast When a Charge Looks Wrong
An unexplained card charge can be the first sign that a trusted shop was compromised. The Federal Office for Cybersecurity advises customers to consider e-commerce skimming when a suspicious transaction follows an online purchase, even if the purchase took place on a well-known website.
The first response should be to contact the bank or credit card provider and dispute fraudulent transactions immediately. Customers should also notify the affected shop and report the incident to the Federal Office for Cybersecurity. Where money has been lost, the agency recommends filing a report with the relevant cantonal police force. Switzerland’s Suisse ePolice platform can help users find the appropriate police station.
Consumers should preserve useful evidence, including order confirmations, dates, payment alerts, screenshots and correspondence with the retailer or bank. They should monitor statements for further unauthorised transactions and follow their card provider’s instructions on blocking or replacing the card. The agency’s advice focuses on speed because a prompt dispute gives the financial institution and investigators relevant information while the transaction and associated account activity remain traceable.
Retailers Must Lock Down the Checkout
Website operators carry the main defensive burden because customers may not see the manipulation. The Federal Office for Cybersecurity said it can be “very difficult, if not impossible” for people without specialist knowledge to detect this kind of attack. That places responsibility on food delivery companies and other online retailers to secure the systems behind the checkout page.
The agency recommends applying all security patches regularly and keeping every system component up to date. Operators should check payment functionality periodically for irregularities and, where possible, use automated tests or monitoring tools. A sudden change in available payment methods, unfamiliar scripts or unexpected data transfers should trigger investigation.
Administrative accounts should use strong, unique passwords, with two factor authentication enabled wherever possible. The agency also recommends a restrictive Content Security Policy. A CSP lets operators control which sources a browser may use to execute JavaScript and where information may be sent. That measure can limit the ability of unauthorised third-party scripts to capture payment data, although it must form part of broader software, access and monitoring controls.
A Swiss Warning for Every Online Shopper
The warning reaches beyond one food delivery service. Swiss consumers increasingly rely on online shops and app-based services for everyday purchases, while payment pages depend on layers of software, external scripts and administrative access. A compromise in any of those layers can affect the moment when a customer believes the transaction is almost complete.
The case also shows why a secure connection symbol or a familiar website address cannot settle the question of safety. Those checks can help identify fake sites, but they do not reveal malicious code inserted into a genuine service. Users need to notice changes in language, payment methods and checkout behaviour, while companies need continuous testing rather than one-time security checks.
The Federal Office for Cybersecurity has not published figures for the number of affected customers in this case. Its practical guidance is therefore the clearest measure of what comes next: retailers should patch, monitor and restrict access, while customers should question unexpected forms and report suspicious charges quickly. For people ordering dinner in Switzerland, digital safety now depends on both sides of the payment screen.