Swiss federal IT office SharePoint servers breached, about 200 accounts compromised
Switzerland's Federal Office of Information Technology, Systems and Telecommunication (FOITT/BIT) disclosed that attackers exploited Microsoft SharePoint vulnerabilities on its servers and compromised about 200 user and technical accounts.
- Victim
- Federal Office of Information Technology, Systems and Telecommunication (FOITT/BIT)
On 4 August 2026, Switzerland's Federal Office of Information Technology, Systems and Telecommunication (FOITT, known in German as BIT), which runs IT services for the federal administration, announced that attackers had exploited vulnerabilities in Microsoft SharePoint to break into SharePoint servers hosted in the government's own data centers. About 200 accounts, including both user and technical accounts, were compromised.
Security specialists noticed unusual activity on the servers on 28 July 2026 and blocked external internet access to SharePoint the same day. On 31 July, their analysis showed that the login credentials of several accounts had been compromised. FOITT said it had begun installing Microsoft's security updates as soon as the flaws were disclosed in mid-July, and it reset the passwords of all affected accounts and started reinstalling the servers as a precaution.
The vulnerabilities
FOITT did not say which flaw was used. Reporting pointed to two SharePoint bugs fixed in Microsoft's July 2026 Patch Tuesday: CVE-2026-56164, an actively exploited privilege-escalation flaw, and CVE-2026-50522, a critical remote code execution bug that attackers used elsewhere to steal SharePoint machine keys and keep access after patching. The intrusion was part of the broader wave of on-premises SharePoint exploitation that CISA warned about in July.
Impact
The office said no confidential information or particularly sensitive personal data is allowed on the affected SharePoint platform, which is used for collaboration and file storage, and that it had found no evidence of data theft beyond the compromised credentials. The Federal Office for Cybersecurity and Microsoft supported the investigation, the incident was reported to the State Secretariat for Security Policy, and technical indicators were shared with critical infrastructure operators. No group claimed the attack.
Why it matters
The case shows how quickly mass-exploited server flaws reach national governments, even when patching starts promptly: machine-key theft and stolen credentials can let intruders persist after updates are applied. Resetting credentials and rebuilding servers, not only patching, is what closes that gap.
Timeline
FOITT security specialists detect unusual activity on the office's SharePoint servers and block internet access to the platform.
Analysis reveals that login credentials for several accounts have been compromised.
FOITT publicly announces the cyberattack and the compromise of about 200 accounts.
Sources
- databreaches.nethttps://databreaches.net/2026/08/04/swiss-federal-it-office-hit-by-cyberattack/
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/08/07/swiss-government-microsoft-sharepoint-vulnerabilities/
- scworld.comhttps://www.scworld.com/brief/swiss-federal-it-agency-foitt-compromised-about-200-accounts-due-to-sharepoint-flaws