INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Swiss authorities investigate SharePoint credential leak incident involving Microsoft
| 2026-08-10 09:57 DATA BREACH
Executive Summary
AI-generated
The Swiss federal IT department was hacked, with approximately 200 accounts compromised, in mid-July. The Federal Office of Information Technology, Systems and Telecommunication (BIT) discovered irregular activity on its SharePoint servers on Tuesday, July 28, and immediately blocked access. BIT attributed the breach to vulnerabilities in Microsoft's widely used SharePoint platform, specifically CVE-2026-56164 and CVE-2026-50522, which were actively exploited by hackers. The attackers managed to steal SharePoint machine keys, allowing them to maintain access after servers were patched. As a result of this incident, BIT is reinstalling the affected SharePoint servers, blocking external internet access until completion, while personnel from the Federal Administration can continue accessing documents via alternative routes.
Technical Mitigations AI-generated
• Patch the actively exploited SharePoint privilege escalation vulnerability (CVE-2026-56164) as part of July 2026 Patch Tuesday updates.
• Apply the critical remote code execution flaw fix for CVE-2026-50522, described by Microsoft as relatively easy to exploit.
• Enforce multi-factor authentication (MFA) on user and technical accounts affected by the breach.
• Monitor for unusual account activity related to SharePoint machine keys.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Intelligence Sources
IT Pro
2026-08-10