Microsoft: 200 accounts compromised in Swiss government’s Microsoft SharePoint breach

Microsoft: 200 accounts compromised in Swiss government’s Microsoft SharePoint breach

Swiss Federal Agency Hit by SharePoint Exploit, 200 Accounts Compromised

On July 28, Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT) detected unusual activity on its Microsoft SharePoint servers, prompting an immediate investigation. After confirming a cyber intrusion, BIT severed internet access to the platform and patched the exploited vulnerabilities.

By July 31, security teams discovered that attackers had compromised login credentials for approximately 200 accounts, including both user and technical profiles. BIT responded by resetting all affected passwords. The agency attributed the breach to unpatched SharePoint vulnerabilities disclosed by Microsoft in mid-July, though the specific flaw either the privilege escalation bug CVE-2026-56164 or the remote code execution flaw CVE-2026-50522 remains undisclosed.

The attackers, described as "previously unknown actors," likely leveraged these vulnerabilities to gain access, potentially using the latter flaw to extract SharePoint machine keys and maintain persistence even after patches were applied. BIT is collaborating with the Federal Office for Cybersecurity (BACS) and Microsoft to analyze the incident.

While no evidence suggests data exfiltration beyond the stolen credentials, BIT confirmed that the affected SharePoint platform is not authorized to store confidential or sensitive personal information. The agency reported the incident to BACS and the State Secretariat for Security Policy in compliance with Switzerland’s Information Security Act and shared technical indicators with critical infrastructure operators.

As of now, no group has claimed responsibility for the attack, and federal employees retain access to documents through alternative methods.

Source: https://www.helpnetsecurity.com/2026/08/07/swiss-government-microsoft-sharepoint-vulnerabilities/

Microsoft Security cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security

"id": "MIC1786107729",
"linkid": "microsoft-security",
"type": "Vulnerability",
"date": "7/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'customers_affected': '200 accounts (users and '
                                              'technical profiles)',
                        'industry': 'Information Technology / Government',
                        'location': 'Switzerland',
                        'name': 'Federal Office of Information Technology, '
                                'Systems and Telecommunication (BIT)',
                        'type': 'Government Agency'}],
 'attack_vector': 'Exploitation of unpatched vulnerabilities',
 'data_breach': {'data_exfiltration': 'No evidence of data exfiltration beyond '
                                      'stolen credentials',
                 'number_of_records_exposed': '200',
                 'sensitivity_of_data': 'Not authorized to store confidential '
                                        'or sensitive personal information',
                 'type_of_data_compromised': 'Login credentials'},
 'date_detected': '2024-07-28',
 'description': 'On July 28, Switzerland’s Federal Office of Information '
                'Technology, Systems and Telecommunication (BIT) detected '
                'unusual activity on its Microsoft SharePoint servers, '
                'prompting an immediate investigation. After confirming a '
                'cyber intrusion, BIT severed internet access to the platform '
                'and patched the exploited vulnerabilities. By July 31, '
                'security teams discovered that attackers had compromised '
                'login credentials for approximately 200 accounts, including '
                'both user and technical profiles. The agency attributed the '
                'breach to unpatched SharePoint vulnerabilities disclosed by '
                'Microsoft in mid-July, though the specific flaw remains '
                'undisclosed. The attackers likely leveraged these '
                'vulnerabilities to gain access and potentially extract '
                'SharePoint machine keys to maintain persistence. BIT is '
                'collaborating with the Federal Office for Cybersecurity '
                '(BACS) and Microsoft to analyze the incident. While no '
                'evidence suggests data exfiltration beyond the stolen '
                'credentials, BIT confirmed that the affected SharePoint '
                'platform is not authorized to store confidential or sensitive '
                'personal information.',
 'impact': {'data_compromised': 'Login credentials for approximately 200 '
                                'accounts',
            'operational_impact': 'Internet access to SharePoint platform '
                                  'severed temporarily',
            'systems_affected': 'Microsoft SharePoint servers'},
 'initial_access_broker': {'backdoors_established': 'Potential extraction of '
                                                    'SharePoint machine keys '
                                                    'for persistence',
                           'entry_point': 'Exploitation of SharePoint '
                                          'vulnerabilities'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'corrective_actions': 'Patching vulnerabilities, '
                                                  'resetting compromised '
                                                  'credentials',
                            'root_causes': 'Unpatched SharePoint '
                                           'vulnerabilities'},
 'references': [{'source': 'Cyber Incident Description'}],
 'regulatory_compliance': {'regulations_violated': 'Information Security Act '
                                                   '(Switzerland)',
                           'regulatory_notifications': 'Reported to BACS and '
                                                       'the State Secretariat '
                                                       'for Security Policy'},
 'response': {'containment_measures': 'Severed internet access to the '
                                      'SharePoint platform, reset affected '
                                      'passwords',
              'incident_response_plan_activated': 'Yes',
              'recovery_measures': 'Alternative document access methods '
                                   'provided to federal employees',
              'remediation_measures': 'Patched exploited vulnerabilities',
              'third_party_assistance': 'Federal Office for Cybersecurity '
                                        '(BACS) and Microsoft'},
 'stakeholder_advisories': 'Technical indicators shared with critical '
                           'infrastructure operators',
 'threat_actor': 'Previously unknown actors',
 'title': 'Swiss Federal Agency Hit by SharePoint Exploit, 200 Accounts '
          'Compromised',
 'type': 'Data Breach',
 'vulnerability_exploited': ['CVE-2026-56164', 'CVE-2026-50522']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.