The Federal Office for Information Technology and Telecommunication (BIT), Switzerland's federal IT office, has confirmed a cyberattack on its Microsoft SharePoint servers that compromised approximately 200 accounts. The breach was detected on July 28 after security specialists observed unusual activity on the servers.
Following the discovery, BIT immediately took action, blocking external internet access to SharePoint, patching suspected vulnerabilities, and resetting passwords for the affected accounts. By July 31, the agency's analysis confirmed that login credentials for several accounts had been compromised.
BIT believes the attackers exploited vulnerabilities in SharePoint that Microsoft disclosed and addressed in its July 2026 Patch Tuesday updates. While the specific flaw utilized has not been publicly identified, two possibilities include CVE-2026-56164, an actively exploited privilege escalation vulnerability, or CVE-2026-50522, a critical remote code execution flaw. The latter was reportedly exploited in other incidents to steal SharePoint machine keys, enabling persistent access even after servers were patched. It remains unconfirmed if either of these particular vulnerabilities was leveraged in the Swiss government attack, or if another flaw from the same update cycle was used.
The investigation into the incident is ongoing, with assistance from the Swiss Federal Office for Cyber Security and Microsoft. As of now, BIT has found no evidence that data beyond the login credentials was stolen. The agency emphasized that confidential information and highly sensitive personal data are not permitted to be stored on the affected SharePoint platform.
As a precautionary measure, BIT is in the process of reinstalling the compromised servers. External access to SharePoint will remain blocked until this work is completed. Federal employees are currently using alternative methods for document access and external sharing.
No ransomware or data extortion group has yet claimed responsibility for the breach.






