All stories

Exploited SharePoint vulnerabilities compromise approximately 200 accounts within the Swiss government

⚠️ Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to the Swiss Federal Office for Information Technology and Telecommunication (BIT). Approximately 200 accounts had their login credentials compromised. Immediate actions include patching systems via July updates and resetting affected user passwords.

Summary

The Swiss Federal Office for Information Technology and Telecommunication (BIT) is investigating a cyberattack that targeted its SharePoint infrastructure. Security specialists first detected unusual activity on the servers on July 28. Following the discovery, BIT blocked all external internet access to the SharePoint platform to contain the incident.

The investigation has confirmed that login credentials for several accounts were compromised. While the agency has not found evidence of data theft beyond these credentials, it is currently reinstalling the affected servers as a precautionary measure. External access to the platform remains blocked until this reinstallation process is finished.

What happened

Security specialists at BIT identified suspicious activity on SharePoint servers in late July. By Friday, July 31, the agency confirmed that attackers had successfully compromised the login credentials for approximately 200 accounts.

BIT has stated that confidential information and sensitive personal data are not permitted to be stored on this specific SharePoint platform. Despite this policy, the agency is working with the Swiss Federal Office for Cyber Security and Microsoft to determine the full scope of the incident. No ransomware or data extortion groups have claimed responsibility for the activity thus far.

Technical details

The exact vulnerability used in the attack remains unconfirmed, but BIT believes the attackers exploited flaws disclosed by Microsoft in mid-July. These vulnerabilities were addressed in the July 2026 Patch Tuesday updates.

Security researchers have identified two potential vectors that align with this timeline:

  • CVE-2026-56164: An actively exploited SharePoint privilege escalation vulnerability.
  • CVE-2026-50522: A critical remote code execution flaw that can be used to steal SharePoint machine keys, allowing attackers to maintain access even after servers are patched.

It is not yet clear if the attackers utilized one of these specific flaws or a different vulnerability included in the same July update cycle.

Defender guidance

Organizations running Microsoft SharePoint should prioritize the following actions:

  • Apply July 2026 Patches: Ensure all SharePoint servers are updated with the latest patches from the July Patch Tuesday cycle to mitigate known RCE and privilege escalation risks.
  • Credential Hygiene: If a breach is suspected, perform a mandatory password reset for all accounts that may have been exposed.
  • Monitor Machine Keys: Be alert for unauthorized access or changes related to SharePoint machine keys, as these can be used to maintain persistence after patching.
  • Verify Data Storage Policies: Audit what types of data are stored on internet-facing SharePoint instances to minimize the impact of potential credential theft.

Sources

  1. https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
  2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
  3. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -