Switzerland’s Federal Office for Information Technology and Telecommunication: Swiss government SharePoint breach compromised 200 accounts

Switzerland’s Federal Office for Information Technology and Telecommunication: Swiss government SharePoint breach compromised 200 accounts

Swiss Government SharePoint Servers Breached in Cyberattack

Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) confirmed a cyberattack on its Microsoft SharePoint servers, compromising around 200 accounts. The breach was detected on July 28 after security teams observed unusual activity, prompting an immediate response.

Following the discovery, BIT blocked external internet access to the affected servers, applied security patches, and reset passwords for the compromised accounts. On July 31, investigators found that attackers had exfiltrated login credentials but uncovered no evidence of additional data theft. The agency clarified that confidential or sensitive personal data was not stored on the breached platform.

The attack likely exploited SharePoint vulnerabilities patched in Microsoft’s July 2026 Patch Tuesday updates, though the exact flaw remains unconfirmed. Possible candidates include CVE-2026-56164 (a privilege escalation bug) or CVE-2026-50522 (a critical remote code execution flaw), both of which were actively exploited in other attacks. BIT is working with the Swiss Federal Office for Cyber Security and Microsoft to determine the full scope of the incident.

As a precaution, the agency is reinstalling compromised servers, with external access remaining restricted until completion. Federal employees can still access and share documents through alternative methods. No ransomware or data extortion group has claimed responsibility, and the investigation is ongoing.

Source: https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/

Swiss Federal Administration cybersecurity rating report: https://www.rankiteo.com/company/bundesverwaltung

"id": "BUN1786047833",
"linkid": "bundesverwaltung",
"type": "Breach",
"date": "7/2026",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': '200 accounts',
                        'industry': 'Information Technology',
                        'location': 'Switzerland',
                        'name': 'Federal Office for Information Technology and '
                                'Telecommunication (BIT)',
                        'type': 'Government Agency'}],
 'attack_vector': 'Exploited SharePoint vulnerabilities',
 'data_breach': {'data_exfiltration': True,
                 'number_of_records_exposed': '200 accounts',
                 'sensitivity_of_data': 'Low (no confidential or sensitive '
                                        'personal data)',
                 'type_of_data_compromised': 'Login credentials'},
 'date_detected': '2026-07-28',
 'description': 'Switzerland’s Federal Office for Information Technology and '
                'Telecommunication (BIT) confirmed a cyberattack on its '
                'Microsoft SharePoint servers, compromising around 200 '
                'accounts. The breach was detected on July 28 after security '
                'teams observed unusual activity, prompting an immediate '
                'response. Attackers exfiltrated login credentials but no '
                'evidence of additional data theft was found. Confidential or '
                'sensitive personal data was not stored on the breached '
                'platform.',
 'impact': {'data_compromised': 'Login credentials',
            'operational_impact': 'External internet access blocked, '
                                  'alternative document access methods '
                                  'provided',
            'systems_affected': 'Microsoft SharePoint servers'},
 'investigation_status': 'Ongoing',
 'references': [{'source': 'Cyber Incident Description'}],
 'response': {'containment_measures': 'Blocked external internet access to '
                                      'affected servers, reset passwords for '
                                      'compromised accounts',
              'incident_response_plan_activated': True,
              'recovery_measures': 'External access restricted until '
                                   'completion, alternative document access '
                                   'methods provided',
              'remediation_measures': 'Applied security patches, reinstalled '
                                      'compromised servers',
              'third_party_assistance': ['Swiss Federal Office for Cyber '
                                         'Security',
                                         'Microsoft']},
 'title': 'Swiss Government SharePoint Servers Breached in Cyberattack',
 'type': 'Data Breach',
 'vulnerability_exploited': ['CVE-2026-56164', 'CVE-2026-50522']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.