Swiss government SharePoint breach compromised 200 accounts
The Swiss government's federal IT office has been breached, with hackers exploiting vulnerabilities in Microsoft SharePoint servers to compromise approximately 200 accounts. The agency has blocked external internet access to SharePoint, patched the suspected vulnerabiliti…
Intelligence analysis by Llama

A cyberattack on the Swiss government's SharePoint servers has compromised around 200 accounts, with hackers exploiting vulnerabilities disclosed by Microsoft in mid-July. The agency has taken steps to contain the breach and is investigating the incident with assistance from the Swiss Federal Office for Cyber Security and Microsoft.
Imagine you have a super important document that you store on a shared drive at work. Hackers found a way to break into the drive and steal the login information for 200 accounts. The company quickly fixed the problem and changed the passwords to keep the hackers out.
Analysis
Vulnerabilities Exploited in the Breach
The Swiss government's federal IT office has been breached, with hackers exploiting vulnerabilities in Microsoft SharePoint servers to compromise approximately 200 accounts. The agency has blocked external internet access to SharePoint, patched the suspected vulnerabilities, and reset the passwords for the affected accounts.
The breach is believed to have occurred after security specialists noticed unusual activity on the SharePoint servers on July 28. After confirming the breach, the agency took swift action to contain the damage, including blocking external internet access to SharePoint, patching the suspected vulnerabilities, and resetting the passwords for the affected accounts.
The agency is investigating the incident with assistance from the Swiss Federal Office for Cyber Security and Microsoft. So far, it has found no evidence that data was stolen beyond the compromised login credentials. The agency said confidential information and particularly sensitive personal data are not permitted to be stored on the affected SharePoint platform.
Possible Vulnerabilities Used in the Breach
The agency believes the attackers exploited SharePoint vulnerabilities disclosed by Microsoft in mid-July and fixed in the July Patch Tuesday updates. However, it has not disclosed which flaw was used. The attack potentially involved either CVE-2026-56164, an actively exploited SharePoint privilege escalation vulnerability, or CVE-2026-50522, a critical remote code execution flaw later exploited to steal SharePoint machine keys and maintain access after servers were patched.
Investigation and Containment
The agency is reinstalling the compromised servers as a precaution, and external access will remain blocked until that work is completed. Federal employees can continue accessing documents and sharing them with external personnel through alternative methods. At this time, no ransomware or data extortion group has claimed responsibility for the breach.
Conclusion
The breach highlights the importance of patching vulnerabilities in critical systems and the need for robust cybersecurity measures to protect sensitive information. The agency's swift action to contain the damage and its ongoing investigation demonstrate its commitment to protecting the sensitive information stored on its SharePoint platform.
Key points
- The Swiss government's federal IT office has been breached, with hackers exploiting vulnerabilities in Microsoft SharePoint servers to compromise approximately 200 accounts.
- The agency has blocked external internet access to SharePoint, patched the suspected vulnerabilities, and reset the passwords for the affected accounts.
- The breach is believed to have occurred after security specialists noticed unusual activity on the SharePoint servers on July 28.
- The agency is investigating the incident with assistance from the Swiss Federal Office for Cyber Security and Microsoft.
- So far, it has found no evidence that data was stolen beyond the compromised login credentials.
The swift action taken by the Swiss government's federal IT office to contain the breach and its ongoing investigation demonstrate its commitment to protecting sensitive information. The agency's efforts to reinstall the compromised servers and block external access will help prevent further damage and ensure the security of the SharePoint platform.
The breach highlights the potential risks of exploiting vulnerabilities in critical systems and the need for robust cybersecurity measures to protect sensitive information. If the hackers had stolen sensitive data, it could have led to serious consequences, including identity theft and financial loss.



