Swiss Federal Office for Information Technology and Telecommunication: Swiss Government SharePoint Breach Compromised 200 Accounts

Swiss Federal Office for Information Technology and Telecommunication: Swiss Government SharePoint Breach Compromised 200 Accounts

Swiss Federal SharePoint Breach Exposes 200 Accounts in Credential Theft Incident

Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) revealed a network intrusion targeting its federal SharePoint platform, resulting in the compromise of approximately 200 user accounts. Unusual activity was detected on July 28, with security specialists confirming the credential theft by July 31. No ransomware group has claimed responsibility, and BIT has not disclosed the specific vulnerability exploited.

Investigators suspect the attack leveraged one of two SharePoint flaws patched in Microsoft’s July 2026 Patch Tuesday updates: CVE-2026-56164, a privilege escalation vulnerability actively exploited in the wild, or CVE-2026-50522, a critical remote code execution flaw that could allow attackers to steal SharePoint machine keys and maintain persistence. BIT has not confirmed which flaw was used, but the latter’s ability to enable long-term access raises concerns.

While the breach exposed login credentials, BIT stated that the affected SharePoint platform does not store confidential or highly sensitive personal data, and no evidence suggests data exfiltration beyond the stolen credentials. The incident’s impact is thus limited to credential compromise rather than broader data theft.

BIT responded swiftly to contain the breach, blocking external internet access to the SharePoint servers, applying patches, resetting affected account passwords, and reinstalling compromised servers. Federal employees have temporarily shifted to alternative file-sharing methods while remediation continues. The investigation involves collaboration with the Swiss Federal Office for Cyber Security and Microsoft.

The breach underscores the high-value nature of government collaboration platforms, which often integrate with federal identity systems and shared documents. Even when data theft is not confirmed, credential compromise can pose political and supply-chain risks. The incident also highlights the urgency of applying critical patches attackers exploited flaws addressed in routine updates, demonstrating that delayed deployment can leave systems vulnerable.

For other SharePoint deployments, the Swiss case serves as a cautionary example: rapid detection and containment limited the breach’s scope, preventing a potential full-tenant takeover. The ability to steal machine keys linked to CVE-2026-50522 could have allowed attackers to maintain persistent access, reinforcing the need for heightened monitoring of administrative accounts and key-management systems.

The incident also reveals broader challenges in public-sector cybersecurity, including reliance on a single commercial platform and difficulties in detecting subtle credential abuse within large-scale collaboration environments. Other national administrations running SharePoint are now advised to verify the July 2026 patches, audit machine key storage, and ensure elevated accounts receive the same scrutiny as standard users.

Source: https://dailysecurityreview.com/cyber-security/swiss-government-sharepoint-breach-compromised-200-accounts/

Swisscom cybersecurity rating report: https://www.rankiteo.com/company/swisscom

"id": "SWI1786128838",
"linkid": "swisscom",
"type": "Breach",
"date": "7/2026",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': '200 user accounts',
                        'industry': 'Public Sector',
                        'location': 'Switzerland',
                        'name': 'Swiss Federal Office for Information '
                                'Technology and Telecommunication (BIT)',
                        'type': 'Government Agency'}],
 'attack_vector': 'Exploitation of SharePoint vulnerabilities',
 'data_breach': {'number_of_records_exposed': '200',
                 'sensitivity_of_data': 'Low (no confidential or highly '
                                        'sensitive personal data)',
                 'type_of_data_compromised': 'Login credentials'},
 'date_detected': '2026-07-28',
 'description': 'Switzerland’s Federal Office for Information Technology and '
                'Telecommunication (BIT) revealed a network intrusion '
                'targeting its federal SharePoint platform, resulting in the '
                'compromise of approximately 200 user accounts. Unusual '
                'activity was detected on July 28, with security specialists '
                'confirming the credential theft by July 31. No ransomware '
                'group has claimed responsibility, and BIT has not disclosed '
                'the specific vulnerability exploited.',
 'impact': {'data_compromised': 'Login credentials of ~200 accounts',
            'operational_impact': 'Temporary shift to alternative file-sharing '
                                  'methods',
            'systems_affected': 'Federal SharePoint platform'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The incident underscores the high-value nature of '
                    'government collaboration platforms, the urgency of '
                    'applying critical patches, and the need for heightened '
                    'monitoring of administrative accounts and key-management '
                    'systems. It also highlights challenges in public-sector '
                    'cybersecurity, including reliance on single commercial '
                    'platforms and difficulties in detecting credential abuse.',
 'post_incident_analysis': {'corrective_actions': ['Patch deployment',
                                                   'Password resets',
                                                   'Server reinstallation'],
                            'root_causes': ['Exploitation of unpatched '
                                            'SharePoint vulnerabilities '
                                            '(CVE-2026-56164 or '
                                            'CVE-2026-50522)']},
 'recommendations': ['Verify July 2026 SharePoint patches',
                     'Audit machine key storage',
                     'Ensure elevated accounts receive scrutiny',
                     'Enhance monitoring of administrative accounts'],
 'references': [{'source': 'Microsoft Patch Tuesday (July 2026)'}],
 'response': {'containment_measures': ['Blocked external internet access to '
                                       'SharePoint servers',
                                       'Applied patches',
                                       'Reset affected account passwords'],
              'incident_response_plan_activated': True,
              'remediation_measures': ['Reinstalled compromised servers'],
              'third_party_assistance': 'Swiss Federal Office for Cyber '
                                        'Security, Microsoft'},
 'stakeholder_advisories': 'Other national administrations running SharePoint '
                           'are advised to verify patches, audit machine key '
                           'storage, and monitor elevated accounts.',
 'title': 'Swiss Federal SharePoint Breach Exposes 200 Accounts in Credential '
          'Theft Incident',
 'type': 'Credential Theft',
 'vulnerability_exploited': ['CVE-2026-56164', 'CVE-2026-50522']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.