Swiss federal IT office says SharePoint breach exposed 200 accounts
The BIT breach lines up with the July SharePoint bug wave, though attribution remains open.

Key points
- Switzerland's Federal Office for Information Technology and Telecommunication (BIT) says hackers broke into its Microsoft SharePoint servers and compromised roughly 200 accounts.
- Security staff spotted the intrusion on July 28 and confirmed stolen login credentials on July 31.
- BIT believes the attackers used one of the SharePoint flaws Microsoft patched in its July 2026 update round.
- No group has claimed the breach, and no data theft beyond the credentials has been found so far.
- The affected servers are being rebuilt, and outside internet access to them stays switched off until that work finishes.
Switzerland's federal IT office has confirmed that hackers broke into its Microsoft SharePoint servers, the file-sharing platform used across the government, and got hold of the login details for around 200 accounts.
The Federal Office for Information Technology and Telecommunication, known as BIT, said its security team noticed unusual activity on the servers on July 28. Three days later, on July 31, analysts confirmed that credentials for several accounts had been stolen.
BIT cut off external internet access to the SharePoint servers, applied the missing patches, and forced password resets on the affected accounts. The incident was first reported by BleepingComputer.
How did the hackers get in?
BIT believes the attackers used one of the SharePoint vulnerabilities that Microsoft disclosed and fixed in its July 2026 Patch Tuesday, the monthly bundle of security updates the company ships on the second Tuesday of each month. The agency has not said which specific flaw was abused.
Two candidates stand out in that batch. One is CVE-2026-56164, a privilege escalation bug that lets an attacker who already has a foothold gain higher access rights, and which was under active exploitation at the time. The other is CVE-2026-50522, a critical remote code execution flaw, meaning attackers could run their own commands on the server. That second bug was later chained with theft of SharePoint machine keys, cryptographic secrets that let intruders forge trusted sessions and quietly walk back in even after servers were patched.
A third possibility is that the attackers used a different flaw fixed in the same update round. BIT has not ruled that out.
Who is behind it?
Unknown, at least publicly. No ransomware or extortion crew has claimed responsibility, and BIT has not attributed the intrusion to any named cluster.
Context matters here. The July SharePoint wave drew in several distinct sets of hands, including activity vendors have tracked as Chinese state-aligned, notably clusters Microsoft calls Linen Typhoon and Violet Typhoon, alongside opportunistic criminal actors picking up the same public exploits. Overlapping tooling across those groups makes single-source attribution risky, and BIT has sensibly not guessed. Capability to hit an internet-exposed SharePoint server does not, on its own, tell you intent.
What was taken?
So far, only login credentials. BIT says its investigation has found no evidence of wider data theft, and the agency notes that confidential material and sensitive personal data are not allowed to be stored on the affected SharePoint platform in the first place.
The Swiss Federal Office for Cyber Security and Microsoft are helping with the investigation. As a precaution, BIT is reinstalling the compromised servers from scratch. External access will stay blocked until that rebuild is finished. Federal staff can still reach documents and share them with outside partners through other systems.
Timeline and facts
| Date or item | Detail |
|---|---|
| July 2026 Patch Tuesday | Microsoft fixes the SharePoint flaws now suspected in the breach |
| July 28, 2026 | BIT detects unusual activity on its SharePoint servers |
| July 31, 2026 | Stolen credentials confirmed for several accounts |
| Accounts affected | Around 200 |
| Data theft found | None beyond credentials, so far |
What should ordinary people do?
Nothing urgent. BIT says sensitive personal data was not permitted on these servers, and no evidence of citizen data exposure has surfaced. Federal employees whose passwords were reset should follow their agency's guidance on setting a strong, unique replacement and turning on multi-factor authentication where offered.



