Cyber Attack Hits Swiss Government’s SharePoint Servers, Compromising 200 Accounts
A recent cyber attack has compromised approximately 200 accounts on the Swiss government’s Microsoft SharePoint servers. The breach was detected by security specialists who noticed unusual activity on the servers on July 28. After confirming the incident, the Federal Office for Information Technology and Telecommunication (BIT) took swift action to contain the damage.
According to BIT, hackers exploited vulnerabilities in SharePoint to gain access to sensitive information. Specifically, the attackers are believed to have targeted flaws disclosed by Microsoft in mid-July and fixed in the July Patch Tuesday updates. However, it’s still unclear which specific vulnerability was used in the attack.
The affected accounts were reset, and external internet access to SharePoint was blocked as a precautionary measure. Fortunately, there is no evidence that sensitive data or confidential information was stolen beyond login credentials. The investigation into the breach is ongoing, with assistance from the Swiss Federal Office for Cyber Security and Microsoft.
SharePoint vulnerabilities are often exploited by attackers due to their widespread use in organizations across various industries. In this case, it’s likely that the hackers targeted a vulnerability that allowed them to gain elevated privileges or execute malicious code on the servers. Two possible vulnerabilities that were fixed in the July Patch Tuesday updates include CVE-2026-56164 and CVE-2026-50522.
While the investigation is still underway, it’s essential for organizations to take this incident as a warning sign. SharePoint security should be taken seriously, especially considering the sensitive nature of the data stored on these platforms. By keeping software up-to-date and regularly conducting security audits, organizations can minimize their risk of falling victim to similar attacks.
It’s also worth noting that no ransomware or data extortion group has claimed responsibility for this breach, which is unusual in today’s cyber landscape. This incident serves as a reminder that even with robust security measures in place, attackers can still find ways to compromise sensitive information.
As the investigation continues, BIT will work closely with cybersecurity experts and Microsoft to identify the root cause of the attack and implement additional safeguards to prevent similar incidents in the future. For organizations using SharePoint, this breach should serve as a wake-up call to review their security protocols and ensure that all vulnerabilities are addressed promptly.
In light of this incident, it’s essential for individuals and organizations to prioritize cybersecurity by regularly updating software, conducting security audits, and staying informed about potential vulnerabilities. By doing so, we can reduce the risk of falling victim to similar attacks and protect our sensitive information from being compromised.
Source: Bleeping Computer — 2026-08-06