Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The Federal Office for Information Technology and Telecommunication (BIT) found the cyberattack after security experts saw strange activity on its SharePoint servers on July 28.
After confirming the incident, BIT stopped outside internet access to SharePoint, fixed the suspected issues, and changed the passwords for the affected accounts.
“During the analysis, security specialists discovered on Friday, July 31, that the login credentials for several accounts had been compromised,” BIT said.
The agency thinks the attackers used SharePoint weaknesses that Microsoft revealed in mid-July and fixed in the July Patch Tuesday updates. But, it hasn’t said which issue was exploited.
The attack might have used CVE-2026-56164, a SharePoint weakness that lets users gain higher access, or CVE-2026-50522, a serious flaw that lets attackers run their code remotely and steal keys to SharePoint machines even after fixes were made.
Both flaws were fixed in the July 2026 Patch Tuesday updates. It is still unknown if either weakness was used in the Swiss government attack or if the attackers took advantage of another issue that was fixed in those updates. BIT is looking into the incident with help from the Swiss Federal Office for Cyber Security and Microsoft.
So far, it has found no evidence that data was stolen beyond the compromised login credentials.
The agency said secret info and very personal data can’t be kept on the affected SharePoint site. BIT is putting the damaged servers back in place as a safety measure, and outside access will stay closed until this is done.
Federal workers can still access and share documents with outside people using other ways. Currently, no ransomware or data theft group has said they caused the problem.
Related Topic:
Ransomware group leaked 65,000 Swiss government documents
InfoSecBulletin Cybersecurity for mankind
