Swiss Government SharePoint Servers Breached, 200 Accounts Compromised
A major cybersecurity incident has hit the Swiss government’s IT systems, with hackers exploiting vulnerabilities in Microsoft’s SharePoint platform to breach approximately 200 accounts. The Federal Office for Information Technology and Telecommunication (BIT) detected the attack on July 28 after security specialists noticed unusual activity on its SharePoint servers.
The compromised accounts likely held sensitive information, including login credentials, which were stolen by the attackers. Fortunately, BIT quickly responded to the incident by blocking external internet access to SharePoint, patching the suspected vulnerabilities, and resetting the passwords for the affected accounts. However, it remains unclear whether any data was stolen beyond the compromised login credentials.
According to BIT, the attackers likely exploited a vulnerability in SharePoint that was disclosed by Microsoft in mid-July and fixed in the July Patch Tuesday updates. While the exact vulnerability used is still unknown, security experts believe that it could have been either CVE-2026-56164 or CVE-2026-50522, two critical vulnerabilities that were actively being exploited at the time.
Both of these flaws allowed attackers to execute remote code on affected servers and potentially steal SharePoint machine keys, giving them persistent access even after patches were applied. BIT is currently investigating the incident with assistance from the Swiss Federal Office for Cyber Security and Microsoft, but so far, no evidence has been found of data theft or ransomware demands.
The breach highlights the importance of regular patching and maintenance of IT systems, as well as the need for robust security measures to prevent such incidents. The fact that BIT was able to respond quickly and effectively to contain the damage is a testament to their cybersecurity expertise and preparedness.
For individuals and organizations, this incident serves as a reminder to regularly test their security defenses and ensure they are up-to-date with the latest patches and updates. While the exact vulnerability used in this breach may never be known, one thing is clear: attackers will continue to exploit weaknesses in systems if left unpatched or unprotected.
In light of this incident, we recommend that organizations prioritize regular patching and security testing to prevent similar breaches from occurring in the future. By doing so, they can significantly reduce their risk exposure and protect sensitive information from falling into the wrong hands.
Source: Bleeping Computer — 2026-08-06