The fake SBB ticket website stealing credit card and Twint data from travelers

Key Highlights
- 1
- 2
- 3
+2 more in the takeaways below
Swiss cybercrime police confirmed that a fake SBB ticket website is stealing credit card numbers and Twint payment details from travelers who find it through an ordinary Google search. It copies the real sbb.ch checkout closely, and only breaks character at the payment step.
That matters for any Swiss train booking this autumn, including the ride to the airport before a flight. Here's what the fake site does, and what to do if you already paid.
- What happened: Zurich cantonal police warned on 19 August 2026 about a fake SBB ticket site that copies the real one almost exactly.
- What it steals: Credit card number, expiry date and security code, plus Twint login details, entered at a fake payment page.
- How people land on it: A normal Google search for cheap SBB tickets, or a phishing link sent by email.
- What to do now: Book only at sbb.ch or in the official SBB app, and check the full address in your browser bar before you pay.
- If you already paid: Call your bank to block the card immediately, then file a report with your cantonal police.
What happened
Zurich cantonal police published a fraud alert on cybercrimepolice.ch on 19 August 2026 (still current as of September 2026): a fake site is copying SBB's ticket shop almost exactly. The web address is subtly different from the real sbb.ch, but everything else, including plausible departure times and platform numbers, is built to pass a quick glance.
The fake site even lets you pick first or second class, the same choice you'd get on the real one, and tickets are priced well under SBB's normal fares, which is the bait. 20 Minuten reported the same warning on the same day, and SwissCybersecurity.net and Beobachter both picked it up within days. The Local Switzerland covered it in English on 25 August 2026, so this isn't a one-source claim.
Who this is actually catching
Anyone who searches for SBB tickets on Google rather than typing sbb.ch directly is at risk, and so is anyone who clicks a ticket link in an unexpected email or text. Police say victims reach the site via a Google search or a phishing link sent by email, and nothing more than that.
That's the whole entry point. There's no malware to install and no app to download; the fake page just needs you to type your card and Twint details into a form that looks right.
This lands hardest on exactly the trip prep a lot of readers are doing right now. Think of a last-minute rail ticket to Zurich or Geneva airport, a connecting leg booked the night before, or a cheap-looking fare for a weekend trip abroad. A too-good fare is precisely what makes the fake site convincing, and it's precisely when people are least likely to double-check a URL. We'd treat any SBB fare that undercuts the normal price by a wide margin as the tell, not the deal.
Assuming a site is real because the ticket details look correct. Police confirmed the fake platform's departure times, platforms and routes match SBB's actual timetable, so a plausible schedule proves nothing about which site sold you the ticket.
What to do right now
Book your ticket only through a channel you opened yourself, never one you clicked into from a search ad, email or text. The real booking flow lives at sbb.ch and in the official SBB app, and nowhere else.
- Type sbb.ch directly into your browser, or open the official SBB app, instead of clicking a search result
- Check the full web address again at the payment step specifically, since that's where the fake site diverges
- Treat a fare well below SBB's normal price as a warning sign, not a deal
- Never enter card or Twint details after following a link from an email, SMS or ad
- If you already entered payment details on a suspicious site, call your bank immediately and ask them to block the card
- File a report with your cantonal police once your card is blocked, since the case is only tracked if it's reported
We'd add one more habit worth keeping: bookmark sbb.ch yourself rather than relying on search results for it every time. It removes the one moment, a Google search under time pressure, where this scam actually works.
| What you see | Real sbb.ch | The fake site |
|---|---|---|
| Web address | sbb.ch exactly | Similar but not identical to sbb.ch |
| Ticket price | Standard SBB fare | Noticeably below the standard fare |
| Class choice | First or second class | First or second class (copied) |
| Payment page | SBB's own checkout, Twint integrated | A separate page asking for card CVV and Twint login |
| How you got there | Direct visit or official app | Search ad, phishing email or text link |
How the scam actually works
Once you reach the fake checkout, the site asks for your credit card number, expiry date and security code, along with your Twint payment credentials. Police describe the goal plainly: the collected information lets criminals trigger unauthorized payments or commit further fraud.
Twint is Switzerland's own mobile payment app, tied directly to a bank account, so a stolen Twint login is at least as damaging as a stolen card number.
You never actually receive a working ticket. The transaction is the entire product being sold, and the fake timetable data exists only to keep you on the page long enough to pay. We'd call that the giveaway once you know to look for it: a real ticket shop wants you to finish a purchase, a fake one only needs your card details typed in once.
Those numbers come from a 2025 survey of 1,706 people across German and French-speaking Switzerland, run by the research institute Sotomo for insurer AXA and published on 12 May 2025. The pattern they describe, real money lost and most of it never reported, is exactly what makes a convincing fake ticket site worth building in the first place.
This isn't a one-off pattern
A fake site standing in for a real, trusted booking flow is the same trick behind two other scams we've covered. Fake UK ETA sites are now charging Austrian travelers up to €900 for a form the real government portal issues for far less, and fake road-toll vignette sites are targeting drivers across eight European countries.
None of these need you to be careless. They need you to be in a hurry, searching for something official, on a page that looks close enough not to trigger a second look.
Skip the "how did people fall for this" reaction. The whole design goal of a copy this close is that a careful person, moving at normal speed, doesn't catch it either.
What to watch next
Copycat versions on new addresses are the normal pattern once a fake site gets shut down, and police haven't said this one is gone. Treat it as an ongoing risk through the rest of 2026, not a single fixed website to avoid.
Switzerland's National Cyber Security Centre tracks patterns like this at a federal level, alongside the cantonal police reports. If you're booking documents or tickets for a bigger trip abroad, our travel document checklist covers what else is worth locking down. Keeping confirmations and receipts in one place, the way apps like TripProf do, at least means you're not hunting through email for proof of what you booked if a dispute comes up later.
Frequently Asked Questions
How do I know if I'm on the real sbb.ch?
Type sbb.ch directly into your browser, or use the official SBB app, rather than clicking a search result. Check the full address bar again at the payment step specifically, since that's where the fake site's address differs from the real one.
What exactly does the fake site steal?
Your credit card number, its expiry date and security code, plus your Twint login credentials, all entered at a fake payment page that appears after you've picked a route and class.
What do I do if I already paid on a site I'm now not sure about?
Call your bank immediately and ask them to block the card, then file a report with your cantonal police. Reporting matters even without a financial loss, since police use these reports to track and take down the fake domains.
Does this affect the official SBB app?
No. The warning is specifically about a fake website reached through search results or phishing links, not the official SBB app or sbb.ch itself.
Why would scammers want Twint details specifically, not just a card number?
Twint is linked directly to a Swiss bank account, so working login credentials enable further unauthorized transactions, the same way a stolen card number does. That's why police list it as a separate target alongside card data.
Is this the same as the fake Swiss police phone scam?
No, that's a separate, unrelated scam involving phone calls from people claiming to be police. This one is a website impersonating SBB's ticket shop, reached through search or email.
Key takeaways
- The warning is real and recent. Zurich cantonal police posted it 19 August 2026, and three independent Swiss outlets covered it within a week.
- It steals card details and Twint login credentials at a fake payment page, after copying SBB's real booking flow almost exactly.
- The entry point is a normal Google search or a phishing link, not a suspicious download or an app.
- Type sbb.ch yourself, or use the official app, and double-check the address at checkout specifically.
- If you already paid, block the card first, then report it. Only about a third of Swiss fraud victims report to police at all, per the 2025 AXA survey, which is part of why these sites keep working.
Sources
- cybercrimepolice.ch: official Swiss police fraud alert, published 19 August 2026
- 20 Minuten: independent report on the same warning, 19 August 2026
- The Local Switzerland: English-language coverage, 25 August 2026
- SwissCybersecurity.net: technical writeup of the phishing pattern, 21 August 2026
- Beobachter: Swiss consumer-affairs coverage of the fake ticket portal
- AXA: Cybersorgenmonitor 2025 press release, Sotomo survey of 1,706 people, published 12 May 2025
- Switzerland's National Cyber Security Centre: official channel for reporting phishing and fraud
Keep Reading
More travel tips and guides picked for you

UK ETA scam warning: fake websites are charging Austrians up to €900
Fake UK ETA websites are charging Austrian and EU travellers hundreds of euros for a form that costs £20. Here's how the real one works, and how to spot a scam before you pay it.

The vignette scam targeting eight European countries this autumn
Fake toll-sticker sites just got a fresh warning from consumer-protection agencies in Germany and Switzerland. Here is who is being targeted, what the scam looks like, and the eight official links to bookmark before your next road trip.

Austria's official fraud watchlist just added two more fake booking sites
Austria's official fraud watchlist added two more fake vacation-booking sites this month, one copying a real Tyrolean alpine hut. Here's the two-minute check to run before you pay for a stay this winter.