Hackers Breach Swiss Government SharePoint: 200 Accounts Compromised

Photo: BleepingComputer
Quick answer
Hackers exploited unpatched vulnerabilities in Microsoft SharePoint to breach Swiss government servers, compromising 200 accounts.
Switzerland's Federal Office of Information Technology and Telecommunications (BIT) confirmed a cyberattack on its Microsoft SharePoint servers. The incident was detected on July 28, when security experts identified suspicious activity within the system. As a result, hackers gained access to approximately 200 employee accounts.
According to BIT, attackers exploited vulnerabilities in SharePoint that Microsoft had patched in its July security updates. The flaws are suspected to be critical CVEs CVE-2026-56164 (privilege escalation) or CVE-2026-50522 (remote code execution), though the exact vulnerability remains undisclosed.
Following the attack's discovery, BIT blocked external access to the platform, applied patches, and reset passwords for affected accounts. The investigation is being conducted in collaboration with Switzerland's Federal Cybersecurity Office and Microsoft. No evidence of data theft has been found beyond the compromised credentials, as no sensitive information was stored on the platform.
As a precautionary measure, BIT is reinstalling compromised servers. External access to SharePoint will remain blocked until the process is complete. Employees can continue accessing documents through alternative channels. No ransomware or data-leak groups have claimed responsibility for the attack.
Common questions
- Which vulnerabilities did hackers exploit to breach Switzerland's SharePoint?
- Attackers likely exploited CVE-2026-56164 (privilege escalation) or CVE-2026-50522 (remote code execution), both patched in Microsoft's July updates. The exact vulnerability remains undisclosed.
- Were any data stolen in the SharePoint breach?
- BIT has found no evidence of data theft beyond compromised credentials. No sensitive information was stored on the platform.
- How did Switzerland respond to the incident?
- BIT blocked external access, applied patches, reset compromised passwords, and is reinstalling affected servers. Documents remain accessible via alternative channels.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml