Microsoft and Federal Office for Information Technology and Telecommunication: Hackers Breach Swiss Government SharePoint Servers, Compromise 200 Accounts

Microsoft and Federal Office for Information Technology and Telecommunication: Hackers Breach Swiss Government SharePoint Servers, Compromise 200 Accounts

Swiss Federal SharePoint Servers Hit by Cyberattack, Credentials Compromised

Swiss authorities confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and Telecommunication (BIT), resulting in the compromise of approximately 200 user and technical accounts. The incident was detected on July 28 after security teams observed unusual activity in the agency’s SharePoint environment.

Investigators suspect the breach exploited recently disclosed Microsoft SharePoint vulnerabilities, which were patched in mid-July. While BIT had begun applying security updates, threat actors may have struck before defenses were fully deployed. The attackers’ identity, origin, and motives remain unknown.

On July 31, forensic analysis revealed that login credentials including both standard user accounts and system-level technical accounts had been accessed. BIT responded by resetting all affected passwords. Authorities stated there is no evidence of data exfiltration, and the compromised SharePoint environment does not store highly sensitive government or personal information.

As a precaution, BIT has blocked external internet access to the affected servers and is reinstalling the systems. Internal document access remains available, with alternative methods in place for external collaboration. The agency is working with the Federal Office for Cyber Security (BACS) and Microsoft to assess the full scope of the intrusion.

The incident underscores the risks of internet-facing collaboration platforms like SharePoint, which are frequent targets due to their role in document storage and internal workflows. BIT reported the breach to BACS and the State Secretariat for Security Policy (SEPOS) in compliance with Switzerland’s Information Security Act and shared technical indicators to help other organizations detect similar threats. The investigation remains ongoing.

Source: https://cybersecuritynews.com/hackers-breach-swiss-sharepoint-servers/

Federal Public Defender, Western District of North Carolina cybersecurity rating report: https://www.rankiteo.com/company/federal-public-defender-western-district-of-north-carolina

Microsoft_SharePoint cybersecurity rating report: https://www.rankiteo.com/company/microsoft_sharepoint

"id": "FEDMIC1786112922",
"linkid": "federal-public-defender-western-district-of-north-carolina, microsoft_sharepoint",
"type": "Vulnerability",
"date": "7/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Information Technology',
                        'location': 'Switzerland',
                        'name': 'Federal Office for Information Technology and '
                                'Telecommunication (BIT)',
                        'type': 'Government agency'}],
 'attack_vector': 'Exploitation of Microsoft SharePoint vulnerabilities',
 'data_breach': {'data_exfiltration': 'No evidence of data exfiltration',
                 'number_of_records_exposed': '200',
                 'sensitivity_of_data': 'Not highly sensitive (does not store '
                                        'highly sensitive government or '
                                        'personal information)',
                 'type_of_data_compromised': 'User and technical account '
                                             'credentials'},
 'date_detected': '2024-07-28',
 'description': 'Swiss authorities confirmed a cyberattack targeting '
                'SharePoint servers operated by the Federal Office for '
                'Information Technology and Telecommunication (BIT), resulting '
                'in the compromise of approximately 200 user and technical '
                'accounts. The incident was detected on July 28 after security '
                'teams observed unusual activity in the agency’s SharePoint '
                'environment.',
 'impact': {'data_compromised': 'Approximately 200 user and technical accounts '
                                'compromised',
            'operational_impact': 'External internet access blocked to '
                                  'affected servers; alternative methods for '
                                  'external collaboration implemented',
            'systems_affected': 'SharePoint servers'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Risks of internet-facing collaboration platforms like '
                    'SharePoint, which are frequent targets due to their role '
                    'in document storage and internal workflows',
 'post_incident_analysis': {'corrective_actions': 'Accelerated patch '
                                                  'deployment, system '
                                                  'reinstallation, enhanced '
                                                  'monitoring',
                            'root_causes': 'Exploitation of unpatched '
                                           'Microsoft SharePoint '
                                           'vulnerabilities'},
 'regulatory_compliance': {'regulations_violated': 'Information Security Act '
                                                   '(Switzerland)',
                           'regulatory_notifications': 'Reported to Federal '
                                                       'Office for Cyber '
                                                       'Security (BACS) and '
                                                       'State Secretariat for '
                                                       'Security Policy '
                                                       '(SEPOS)'},
 'response': {'containment_measures': 'Password reset for all affected '
                                      'accounts, blocked external internet '
                                      'access to affected servers',
              'remediation_measures': 'Reinstalling affected systems',
              'third_party_assistance': 'Federal Office for Cyber Security '
                                        '(BACS), Microsoft'},
 'stakeholder_advisories': 'Technical indicators shared to help other '
                           'organizations detect similar threats',
 'title': 'Swiss Federal SharePoint Servers Hit by Cyberattack, Credentials '
          'Compromised',
 'type': 'Cyberattack',
 'vulnerability_exploited': 'Microsoft SharePoint vulnerabilities (patched in '
                            'mid-July)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.