Skip to main content
Emerging ThreatsData Breaches

Swiss Government SharePoint Breach Exposes 200 Accounts

Security personnel investigate a server room with a slightly ajar door, surrounded by computer workstations and a large…

"During the analysis, security specialists discovered on Friday, July 31, that the login credentials for several accounts had been compromised," the Federal Office for Information Technology and Telecommunication (BIT) said.

How the breach was detected and the immediate timeline

BIT says its security specialists noticed unusual activity on the agency’s Microsoft SharePoint servers on July 28 and, after confirming a breach, began containment and remediation steps. By July 31 analysts had determined that login credentials for multiple accounts had been compromised; overall the agency says approximately 200 accounts were affected.

BIT's containment and remediation steps

BIT blocked external internet access to its SharePoint environment, applied patches to the suspected vulnerabilities, and reset passwords for affected accounts. As a further precaution the agency is reinstalling the compromised servers and will keep external access blocked until that work is complete. Federal employees are being permitted to continue accessing and sharing documents with external personnel through alternative methods while the SharePoint environment remains offline to outsiders.

The vulnerabilities being investigated

BIT believes the attackers exploited Microsoft SharePoint vulnerabilities that were disclosed in mid‑July and fixed in the July Patch Tuesday updates, but the office has not named a specific flaw used in the intrusion. The agency notes two possibilities named in publicly available advisories: CVE-2026-56164, described as an actively exploited SharePoint privilege escalation vulnerability, and CVE-2026-50522, a critical remote code execution flaw that was later exploited to steal SharePoint machine keys and maintain access after servers were patched. Both of those flaws were fixed in the July 2026 Patch Tuesday updates. BIT has not confirmed whether either of those CVEs was used in this incident or whether the attackers exploited a different vulnerability that was also fixed in the same updates.

Scope of data exposure and current findings

So far BIT reports finding no evidence that data was stolen beyond the compromised login credentials. The agency reiterated that confidential information and particularly sensitive personal data are not permitted to be stored on the affected SharePoint platform. At this time no ransomware or data‑extortion group has claimed responsibility for the breach.

Investigation partners and public follow-up

BIT is conducting the investigation with assistance from the Swiss Federal Office for Cyber Security and Microsoft. BleepingComputer reached out to BIT to ask which vulnerability was exploited and whether the investigation had uncovered evidence of data theft, but the agency did not provide an immediate response.

What this means for federal employees, security teams, and external partners

  • Federal employees: BIT has provided alternative ways to access and share documents while external access to SharePoint is blocked; employees are affected operationally but are not being asked to use the compromised SharePoint instance for external collaboration.
  • Security teams: BIT’s response includes blocking external access, patching, resetting passwords and reinstalling servers—steps that reflect an effort to remove persistence and eliminate any remaining footholds while the technical details of the intrusion are established.
  • External partners and third parties: until BIT completes server reinstalls and reopens external connectivity, collaborators who normally rely on the affected SharePoint instance must use the alternate document-sharing methods BIT has authorized.

The record BIT has released makes clear what has been done and what remains uncertain: containment steps are complete, assistance from national cyber authorities and Microsoft is in place, and investigators have not yet determined exactly which patched SharePoint flaw — if any of the two named CVEs — was exploited. The central technical question the public and affected users are left with is the same as the agency’s: which vulnerability allowed access, and whether any activity beyond credential compromise can be shown once forensic work on the reinstalled servers is finished.

Original story at BleepingComputer