cybersecurity
How a fake food-delivery payment page stole Swiss customers’ card details
The Federal Office for Cybersecurity has warned that fraudsters altered a food-delivery payment page to harvest credit-card details through a fake payment option. This practical consumer guide should explain how the skimming attack worked, how to spot warning signs and what victims should do after entering their details.

A Real Food Site, A Fake Payment Trap
A familiar food order became a card-theft trap on September 1, 2026. Switzerland’s Federal Office for Cybersecurity warned that criminals had altered the payment page of a food-delivery service, allowing them to collect customers’ credit-card details while the site itself remained genuine.
The attack matters because customers did not necessarily visit an obviously fake website. They reached a legitimate provider, selected a payment option and followed a familiar checkout process. The malicious code had been inserted into the provider’s website and changed what customers saw at the point of payment.
The agency described the method as e-commerce skimming. Unlike a conventional phishing scam, the attackers did not need to lure every victim to a separate imitation site. They compromised part of the real shopping experience and used it to capture payment data.
The warning does not identify the affected food-delivery provider in the supplied information, and it gives no figure for the number of exposed customers. Anyone who used the affected checkout should review recent and pending card transactions, including small authorisation charges that might precede larger fraudulent payments.
How the Fake Card Option Worked
The attackers replaced Twint with a counterfeit credit-card option. According to the Federal Office for Cybersecurity, malicious code injected into the website removed or displaced the provider’s original Twint payment method and presented customers with a fake option labelled for credit-card payments.
Selecting that option opened a pop-up window requesting card information. The details entered there were transmitted directly to the fraudsters. The page then tried to cover its tracks with an error message saying that credit-card payments were still in a test phase and directing customers back to Twint.
One detail should have raised suspicion: the pop-up’s text was in English, while the rest of the food-delivery page was in German. Language inconsistencies can indicate that a payment component has come from an unauthorised source, particularly when a Swiss service normally presents its checkout in one language.
Customers should pause when a familiar payment flow suddenly changes. A new card option, an unexpected pop-up, a request to re-enter information or a message about a payment being tested all warrant a fresh check through the company’s official support channels. Do not use contact details supplied inside a suspicious window.
Why the Padlock Cannot Protect You
Skimming happens inside a genuine website, which makes it difficult for ordinary shoppers to detect. Phishing usually sends a victim to a fake website designed to imitate a bank, retailer or public service. In this case, the payment page of a real food-delivery provider had been manipulated.
That distinction changes what customers should look for. The padlock symbol and correct web address may still appear because the underlying site is authentic. A customer can therefore complete the order on a legitimate domain and still hand card data to criminals through a compromised checkout element.
The Federal Office for Cybersecurity says it can be “very difficult, if not impossible” for people without specialist knowledge to identify this type of manipulation. That places a substantial responsibility on operators, not only on consumers. Food-delivery platforms and online shops need to monitor checkout behaviour, keep software and plugins updated, apply security patches and protect administrative accounts with strong, unique passwords and two-factor authentication.
Operators should also restrict third-party scripts through a Content Security Policy. Such a policy can control which sources are allowed to run JavaScript and where data may be sent. Automated checkout tests and monitoring can help detect an unexpected payment flow before more customers encounter it.
Block, Dispute and Report
Act quickly if you entered card details or see a charge you cannot explain. The federal guidance says customers should dispute fraudulent transactions immediately with their bank or credit-card provider. Use the emergency or fraud number on the back of the card, or the provider’s official app, rather than a link in an email or suspicious payment message.
Ask the issuer whether the card should be blocked and replaced. Preserve evidence before closing the page or deleting messages: record the website address, time of the order, payment screen, error message and any transaction notifications. Do not send the card number or security code to the food-delivery company by email or chat.
Report the suspected skimming incident to the Federal Office for Cybersecurity and notify the affected shop operator. The operator needs the information to investigate its checkout and warn other customers. If money has been lost, the agency recommends filing a report with the relevant cantonal police force. Suisse ePolice can help identify the appropriate station.
Keep checking the account after the first disputed transaction. Stolen card data can be tested or used later, so review pending as well as completed payments and respond promptly to alerts from the issuer.
The Fix Starts Behind the Checkout
The incident shows why payment security is a shared responsibility across Switzerland’s digital economy. Customers can reduce risk by checking unexpected changes, preferring established payment methods and acting quickly when something looks wrong. They cannot independently inspect the scripts running behind a checkout page.
For operators, the federal advice is concrete. Apply security patches regularly, keep every system component up to date, test payment functionality for irregularities and use automated monitoring where possible. Administrative accounts should have unique passwords and two-factor authentication. A restrictive Content Security Policy can limit unauthorised third-party code and prevent data from being transferred to unknown destinations.
The food-delivery case also underlines the importance of localised user experience. An English pop-up on an otherwise German-language Swiss service was a useful clue, although many customers would reasonably assume that a payment window appearing inside a familiar site was safe.
Swiss consumers should treat card security as an ongoing process. Monitor accounts, enable transaction notifications where available and verify unusual payment requests through an official app or website. If a genuine shop reports a compromise, follow its instructions while relying on the bank for card protection and the cantonal police for any financial-crime report.