INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Swiss Government SharePoint Breach Compromised 200 Accounts

| 2026-08-06 18:14 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
The Swiss Federal IT office has confirmed a cyberattack on its Microsoft SharePoint servers, compromising approximately 200 accounts. The attack is believed to have exploited vulnerabilities disclosed by Microsoft in mid-July and fixed as part of the July Patch Tuesday updates. The attackers likely used one of two flaws: CVE-2026-56164 or CVE-2026-50522, both of which were actively exploited before being patched. The breach has raised concerns about data security and potential cybercrime activity within the country's government institutions.
Technical Mitigations AI-generated
* Implement a secure patch management policy to ensure timely and effective deployment of security updates, including the July Patch Tuesday updates that fixed vulnerabilities exploited by attackers. * Conduct regular vulnerability assessments and penetration testing (VAST) on SharePoint servers to identify potential weaknesses and prioritize remediation efforts. * Use a web application firewall (WAF) or intrusion detection system (IDS) to detect and prevent unauthorized access attempts, and configure it to alert security teams when suspicious activity is detected. * Regularly review and update software dependencies, including Microsoft SharePoint, to ensure that all known vulnerabilities are patched before they can be exploited by attackers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-56164CVE-2026-56164 CVE-2026-50522CVE-2026-50522
Target & Sectors
DACH DACH governmentgovernment manufacturingmanufacturing telecommunicationstelecommunications
Incident Timeline
‎July 2026
The Swiss Federal Office for Cyber Security and Microsoft were breached due to a vulnerability in the BIT investigation tool.
organisation the Swiss Federal Office
organisation Cyber Security
organisation BleepingComputer
organisation EDR
‎July 14
Microsoft disclosed multiple serious SharePoint vulnerabilities on July 14.
‎July 28
Threat actors used compromised technology to target The Federal Office for Information Technology on July 28.
industry Technology
organisation The Federal Office for Information Technology
organisation SharePoint
‎July 31
Threat actors used compromised login details to target 200 user and technical accounts on Swiss government SharePoint.
industry Media
victims 200 user
‎Friday, July 31
The Swiss government's SharePoint account login credentials were compromised due to a breach on Friday, July 31.
‎2026/08/06
Threat actors exploited vulnerabilities in Microsoft's SharePoint software to compromise approximately 200 accounts.
organisation Microsoft SharePoint
organisation SharePoint Flaws
organisation Hack Switzerland’s
organisation Federal IT Agency
organisation SharePoint
organisation FOITT
organisation BIT
organisation National Cyber Security Centre
organisation NCSC
organisation CVE-2026
organisation Microsoft
organisation the Federal Administration
organisation the National Cybersecurity Centre
Tactical Metrics
Metrics
victims
200
User
Intelligence Sources
Security Affairs 2026-08-04
BleepingComputer 2026-08-06