Swiss federal office resets 200 accounts after SharePoint intrusion

Swiss federal IT office BIT resets roughly 200 accounts after a Microsoft SharePoint credential theft.

CSBadmin
2 Min Read

Switzerland’s federal IT office is cleaning up after intruders grabbed login credentials for around 200 accounts on its Microsoft SharePoint platform. The Federal Office of Information Technology, Systems and Telecommunication, known as BIT, detected suspicious activity on July 28 and responded by severing the platform’s internet access and patching the vulnerabilities under attack.

On July 31, BIT confirmed that credentials for several user and technical accounts had been compromised, and reset passwords across all affected accounts. The agency’s working theory is that the intruders came in through SharePoint weaknesses that Microsoft disclosed in mid-July and addressed in its July Patch Tuesday updates, although it has not identified the specific flaw.

The two most likely candidates are CVE-2026-56164, a privilege escalation bug already seen exploited in the wild, and CVE-2026-50522, a remote code execution flaw later used to steal SharePoint machine keys and hold onto access even after patching.

BIT notified the Federal Office for Cybersecurity and the State Secretariat for Security Policy within the window set by Switzerland’s Information Security Act, and passed technical indicators to essential-infrastructure operators through the BACS platform. Microsoft is helping with the analysis.

No confidential information or particularly sensitive personal data is allowed on the affected platform, the agency said, and no evidence has emerged so far that anything beyond the login credentials leaked. No group has claimed responsibility. The breach lands in a summer already marked by widespread exploitation of both candidate bugs after public proof-of-concept code appeared, making prompt patching of on-premises SharePoint servers a clear priority.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.