INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Swiss Government SharePoint Breach Compromised 200 Accounts
| 2026-08-06 18:14 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
The Swiss Federal IT office has confirmed a cyberattack on its Microsoft SharePoint servers, compromising approximately 200 accounts. The attack is believed to have exploited vulnerabilities disclosed by Microsoft in mid-July and fixed as part of the July Patch Tuesday updates. The attackers likely used one of two flaws: CVE-2026-56164 or CVE-2026-50522, both of which were actively exploited before being patched. The breach has raised concerns about data security and potential cybercrime activity within the country's government institutions.
Technical Mitigations AI-generated
* Implement a secure patch management policy to ensure timely and effective deployment of security updates, including the July Patch Tuesday updates that fixed vulnerabilities exploited by attackers.
* Conduct regular vulnerability assessments and penetration testing (VAST) on SharePoint servers to identify potential weaknesses and prioritize remediation efforts.
* Use a web application firewall (WAF) or intrusion detection system (IDS) to detect and prevent unauthorized access attempts, and configure it to alert security teams when suspicious activity is detected.
* Regularly review and update software dependencies, including Microsoft SharePoint, to ensure that all known vulnerabilities are patched before they can be exploited by attackers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-56164CVE-2026-56164
CVE-2026-50522CVE-2026-50522
Target & Sectors
DACH
DACH
governmentgovernment
manufacturingmanufacturing
telecommunicationstelecommunications
Incident Timeline
July 2026
The Swiss Federal Office for Cyber Security and Microsoft were breached due to a vulnerability in the BIT investigation tool.
Click on any entity below to view its context and source!
organisation
the Swiss Federal Office
BIT is investigating the incident with assistance from the Swiss Federal Office for Cyber Security and Microsoft.
organisation
Cyber Security
BIT is investigating the incident with assistance from the Swiss Federal Office for Cyber Security and Microsoft.
organisation
BleepingComputer
BleepingComputer contacted BIT to ask which vulnerability was exploited and whether its investigation had uncovered evidence of data theft, but a response was not immediately available.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
July 14
Microsoft disclosed multiple serious SharePoint vulnerabilities on July 14.
July 28
Threat actors used compromised technology to target The Federal Office for Information Technology on July 28.
Click on any entity below to view its context and source!
industry
Technology
The Federal Office for Information Technology and Telecommunication (BIT) detected the cyberattack after security specialists noticed unusual activity on its SharePoint servers on July 28.
organisation
The Federal Office for Information Technology
The Federal Office for Information Technology and Telecommunication (BIT) detected the cyberattack after security specialists noticed unusual activity on its SharePoint servers on July 28.
organisation
SharePoint
The Federal Office for Information Technology and Telecommunication (BIT) detected the cyberattack after security specialists noticed unusual activity on its SharePoint servers on July 28.
July 31
Threat actors used compromised login details to target 200 user and technical accounts on Swiss government SharePoint.
Click on any entity below to view its context and source!
industry
Media
“During the course of their analysis, the experts discovered on July 31 that the login details for around 200 user and technical accounts had been compromised.”
reports
the media outlet Swiss Info.
victims
200 user
“During the course of their analysis, the experts discovered on July 31 that the login details for around 200 user and technical accounts had been compromised.”
reports
the media outlet Swiss Info.
Friday, July 31
The Swiss government's SharePoint account login credentials were compromised due to a breach on Friday, July 31.
2026/08/06
Threat actors exploited vulnerabilities in Microsoft's SharePoint software to compromise approximately 200 accounts.
Click on any entity below to view its context and source!
organisation
Microsoft SharePoint
Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts.
organisation
SharePoint Flaws
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency.
organisation
Hack Switzerland’s
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency.
organisation
Federal IT Agency
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency.
organisation
SharePoint
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts.
organisation
FOITT
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts.
organisation
BIT
Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had compromised approximately 200 accounts on its on-premises SharePoint servers.
After confirming the breach, BIT blocked external internet access to SharePoint, patched the suspected vulnerabilities, and reset the passwords for the affected accounts.
organisation
National Cyber Security Centre
Switzerland’s National Cyber Security Centre (NCSC) recorded 28 cyberattacks targeting the Federal Administration in 2025 and 325 incidents affecting critical infrastructure, with about one in four involving public administration.
organisation
NCSC
Switzerland’s National Cyber Security Centre (NCSC) recorded 28 cyberattacks targeting the Federal Administration in 2025 and 325 incidents affecting critical infrastructure, with about one in four involving public administration.
organisation
CVE-2026
The attack potentially involved either
CVE-2026-56164
, an actively exploited SharePoint privilege escalation vulnerability, or
CVE-2026-50522
, a critical remote code execution flaw later exploited to steal SharePoint machine keys and maintain access after servers were patched.
organisation
Microsoft
The agency believes the attackers exploited SharePoint vulnerabilities disclosed by Microsoft in mid-July and fixed in the July Patch Tuesday updates.
The FOITT said the unknown attackers are believed to have exploited
vulnerabilities
in Microsoft’s SharePoint software.
organisation
the Federal Administration
The FOITT is the largest IT service provider in the Federal Administration.
organisation
the National Cybersecurity Centre
Based on the investigations to date, which are being supported by the National Cybersecurity Centre (NCSC) and Microsoft, there is no evidence of any further data leakage.
Tactical Metrics
Metrics
victims
200
User
Click for context!
“During the course of their analysis, the experts discovered on July 31 that the login details for around 200 user and technical accounts had been compromised.”
reports
the media outlet Swiss Info.
Intelligence Sources
Security Affairs
2026-08-04
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
Security Affairs
BleepingComputer
2026-08-06
Swiss government SharePoint breach compromised 200 accounts
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-07T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
Microsoft SharePoint
entity
6x
timeline
Temporal Reference
July 28
date
4x
industry
Targeted Sector
Government
sector
4x
attribution
Attributing Entity
SharePoint
authority
4x
tactic
Cyber Operation Type
Privilege Escalation
tactic
2x
vulnerability
Exploited CVE
CVE-2026-56164
cve
2x
general metric
%
54
%
Contextual Telemetry
Context Block
9 METRICS
target region
Target Country
Switzerland
country
general metric
Accounts
200
accounts
general metric
Cyberattacks
28
cyberattacks
general metric
Incidents
325
incidents
victims
User
200
user
vulnerability
CVSS Score
10
score
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
general metric
Workstation Systems
50,000
workstation systems
general metric
Specialist Applications
1,000
specialist applications
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.