Swiss federal IT office says SharePoint breach exposed 200 accounts

The BIT breach lines up with the July SharePoint bug wave, though attribution remains open.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A SharePoint document repository interface with administrative access logs displayed, showing unauthorized account entries and the scope of exposed federal IT o
Share

Key points

  • Switzerland's Federal Office for Information Technology and Telecommunication (BIT) says hackers broke into its Microsoft SharePoint servers and compromised roughly 200 accounts.
  • Security staff spotted the intrusion on July 28 and confirmed stolen login credentials on July 31.
  • BIT believes the attackers used one of the SharePoint flaws Microsoft patched in its July 2026 update round.
  • No group has claimed the breach, and no data theft beyond the credentials has been found so far.
  • The affected servers are being rebuilt, and outside internet access to them stays switched off until that work finishes.

Switzerland's federal IT office has confirmed that hackers broke into its Microsoft SharePoint servers, the file-sharing platform used across the government, and got hold of login details for around 200 accounts.

The Federal Office for Information Technology and Telecommunication, known as BIT, said its security team noticed unusual activity on the servers on July 28. Three days later, on July 31, analysts confirmed that credentials for several accounts had been stolen. BIT cut off external internet access, applied the missing patches, and forced password resets on the affected accounts.

How did the hackers get in?

BIT believes the attackers used one of the SharePoint vulnerabilities Microsoft fixed in its July 2026 Patch Tuesday, the monthly bundle of security updates shipped on the second Tuesday of each month. The agency hasn't said which specific flaw was abused.

Two candidates stand out. One is CVE-2026-56164, a privilege escalation bug that lets an attacker who already has a foothold gain higher access rights, under active exploitation at the time. The other is CVE-2026-50522, a critical remote code execution flaw, meaning attackers could run their own commands on the server. We reported on 21 July 2026 that a public proof-of-concept for CVE-2026-50522 had already triggered active exploitation, and that the flaw was later chained with theft of SharePoint machine keys, cryptographic secrets that let intruders forge trusted sessions and quietly return even after patching.

A third possibility: a different flaw fixed in the same update round. BIT hasn't ruled that out.

Who is behind it?

Unknown, at least publicly. No ransomware or extortion crew has claimed responsibility, and BIT hasn't attributed the intrusion to any named cluster.

Context matters. The July SharePoint wave drew in several distinct sets of hands, including activity vendors have tracked as Chinese state-aligned, notably clusters Microsoft calls Linen Typhoon and Violet Typhoon, alongside opportunistic criminal actors picking up the same public exploits. Overlapping tooling across those groups makes single-source attribution risky, and BIT has sensibly not guessed. Capability to hit an internet-exposed SharePoint server doesn't, on its own, tell you intent.

What was taken?

So far, only login credentials. BIT says its investigation has found no evidence of wider data theft, and the agency notes that confidential material and sensitive personal data aren't permitted on the affected platform in the first place.

The Swiss Federal Office for Cyber Security and Microsoft are helping with the investigation. BIT is reinstalling the compromised servers from scratch; external access stays blocked until that rebuild is finished. Federal staff can still reach documents and share them with outside partners through other systems.

Timeline and facts

Date or item Detail
July 2026 Patch Tuesday Microsoft fixes the SharePoint flaws now suspected in the breach
July 28, 2026 BIT detects unusual activity on its SharePoint servers
July 31, 2026 Stolen credentials confirmed for several accounts
Accounts affected Around 200
Data theft found None beyond credentials, so far

Should you worry?

Not urgently. BIT says sensitive personal data wasn't permitted on these servers, and no evidence of citizen data exposure has surfaced. Federal employees whose passwords were reset should follow agency guidance on setting a strong replacement and enabling multi-factor authentication where it's offered.

© 2026 Threat Vectr