Decoding the world of cybersecurity

Swiss SharePoint attack exposes 200 accounts

Switzerland’s federal IT office is rebuilding affected SharePoint servers after an attack compromised credentials for roughly 200 user and technical accounts.

Swiss SharePoint attack exposes 200 accounts
Summary
  • Unknown attackers compromised credentials for around 200 user and technical accounts on Swiss federal SharePoint servers.
  • Officials suspect recently disclosed SharePoint vulnerabilities enabled the intrusion, although the investigation remains open.
  • External access is suspended while servers are rebuilt, with no evidence of wider data extraction identified so far.

Switzerland’s federal IT authority is rebuilding affected SharePoint servers after an attack compromised credentials belonging to roughly 200 user and technical accounts, exposing the operational consequences of a compromise that reached beyond individual logins into identities used by government systems.

The Federal Office of Information Technology, Systems and Telecommunication, known by its German abbreviation BIT, detected anomalies on its on-premises Microsoft SharePoint servers on 28 July. It blocked internet access to the service for people outside the federal administration after confirming the suspected intrusion.

Investigators established on 31 July that credentials associated with several accounts had been compromised. The affected identities included both user accounts and technical accounts, which can be used by applications, services, automated processes, or other infrastructure rather than by an individual employee.

BIT reset the relevant passwords and said approximately 200 accounts were affected based on its current assessment. It has not identified evidence that additional information was extracted, although the investigation is continuing with assistance from Switzerland’s Federal Office for Cyber Security and Microsoft.

The authority believes the attack was probably enabled by exploitation of vulnerabilities in SharePoint software that Microsoft disclosed in mid-July. It has not attributed the operation, identified the attackers’ initial access route conclusively, or published a detailed account of what they did after reaching the servers.

BIT said it began installing Microsoft’s security updates after they became available. The sequence illustrates the narrow window that can arise between disclosure, patch deployment, and exploitation across on-premises collaboration systems. Applying a patch closes the software weakness but does not automatically invalidate credentials, sessions, persistence mechanisms, or other access obtained before remediation.

The distinction between user and technical accounts is particularly important. A compromised user identity may expose documents and collaboration spaces available to one person, while a technical identity can carry permissions needed for integrations or routine system functions. The Swiss authorities have not said what privileges the compromised accounts held, and there is no confirmed evidence that the attackers used them to move into other systems.

SharePoint is widely used for document storage, project collaboration, and information exchange. BIT operates several SharePoint servers in federal data centres, rather than relying solely on Microsoft’s hosted service. The affected platform was also accessible to approved external users, creating a boundary between government systems and third parties that had to be closed during containment.

The federal administration said confidential information and particularly sensitive personal data should not be stored on the platform. That policy may limit the sensitivity of material directly held in SharePoint, but it does not settle the impact of the credential compromise. Account access can disclose organisational relationships, project structures, document metadata, and information that supports further targeting even where the platform is not intended to hold classified material.

BIT is rebuilding the affected servers as a precaution. External access will remain blocked until that work is complete, while federal employees can continue accessing documents internally and use alternative methods to exchange them with outside parties.

The incident was reported to the Federal Office for Cyber Security and the State Secretariat for Security Policy under Switzerland’s Information Security Act. BIT also shared relevant technical indicators through the federal cyber authority’s platform to help critical infrastructure operators identify related activity.

That information-sharing step suggests the government is treating the event as more than an isolated server problem, although it has not disclosed evidence that other Swiss operators were compromised. The attack remains unattributed, the precise exploitation chain is not confirmed, and the assessment that no wider data was removed may change as forensic work continues.

×