Federal Office for Information Technology and Systems and Telecommunication: Swiss federal IT office hit by cyberattack

Federal Office for Information Technology and Systems and Telecommunication: Swiss federal IT office hit by cyberattack

Swiss Federal IT Office Hit by SharePoint Cyberattack

The Federal Office for Information Technology, Systems and Telecommunication (FOITT) in Switzerland disclosed a cyberattack targeting its SharePoint servers, prompting the immediate restriction of external internet access. The incident, detected on July 31, involved the compromise of approximately 200 user and technical accounts, though no evidence of additional data breaches has been found.

Investigators suspect the attackers exploited known vulnerabilities in Microsoft SharePoint, which the FOITT had begun patching following security advisories issued in mid-July. The agency, supported by the National Cybersecurity Centre (NCSC) and Microsoft, confirmed that compromised passwords were reset and that no confidential or sensitive personal data was stored on the affected platform. As a precaution, the FOITT is reinstalling the impacted servers, with external access remaining blocked until completion.

The attack adds to a growing trend of cyber threats against Swiss critical infrastructure. In 2023, the NCSC recorded 325 reported incidents, with nearly a quarter targeting public administration bodies. Notably, the federally owned defense contractor Ruag faced a ransomware attack in late 2025, where the Akira group stole and threatened to leak data unless a ransom was paid. Ruag ultimately complied with the demands.

Source: https://www.swissinfo.ch/eng/various/cyberattack-on-the-federal-office-for-information-technologys-sharepoint-server/91843136

Federal Home Loan Bank of Pittsburgh cybersecurity rating report: https://www.rankiteo.com/company/federal-home-loan-bank-of-pittsburgh

"id": "FED1785882407",
"linkid": "federal-home-loan-bank-of-pittsburgh",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Public Administration',
                        'location': 'Switzerland',
                        'name': 'Federal Office for Information Technology, '
                                'Systems and Telecommunication (FOITT)',
                        'type': 'Government Agency'}],
 'attack_vector': 'Exploitation of known vulnerabilities in Microsoft '
                  'SharePoint',
 'data_breach': {'number_of_records_exposed': '200',
                 'sensitivity_of_data': 'No confidential or sensitive personal '
                                        'data stored on the affected platform',
                 'type_of_data_compromised': 'User and technical accounts'},
 'date_detected': '2024-07-31',
 'description': 'The Federal Office for Information Technology, Systems and '
                'Telecommunication (FOITT) in Switzerland disclosed a '
                'cyberattack targeting its SharePoint servers, prompting the '
                'immediate restriction of external internet access. The '
                'incident involved the compromise of approximately 200 user '
                'and technical accounts, though no evidence of additional data '
                'breaches has been found.',
 'impact': {'data_compromised': '200 user and technical accounts compromised',
            'operational_impact': 'Restriction of external internet access, '
                                  'reinstallation of impacted servers',
            'systems_affected': 'SharePoint servers'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'corrective_actions': 'Patching of '
                                                  'vulnerabilities, '
                                                  'reinstallation of impacted '
                                                  'servers, reset of '
                                                  'compromised passwords',
                            'root_causes': 'Exploitation of known '
                                           'vulnerabilities in Microsoft '
                                           'SharePoint'},
 'references': [{'source': 'Cyber Incident Description'}],
 'response': {'containment_measures': 'Restriction of external internet '
                                      'access, reset of compromised passwords',
              'remediation_measures': 'Reinstallation of impacted servers, '
                                      'patching of known vulnerabilities',
              'third_party_assistance': 'National Cybersecurity Centre (NCSC), '
                                        'Microsoft'},
 'title': 'Swiss Federal IT Office Hit by SharePoint Cyberattack',
 'type': 'Cyberattack',
 'vulnerability_exploited': 'Known vulnerabilities in Microsoft SharePoint'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.