SharePoint breach: 200 accounts compromised in Switzerland

Switzerland discovered that its government servers were hit by who exploited security vulnerabilities in SharePoint. If you manage internal networks or cloud infrastructure, this incident shows exactly what happens when patches are delayed by even a few days.

  • The Swiss Federal Office for Information Technology and Telecommunications (BIT) lost control of 200 SharePoint accounts after a hack.
  • The attacks are attributed to zero-day or unpatched vulnerabilities that were patched by Microsoft in July.
  • The service has blocked external access and is proceeding with a complete reinstallation of the affected servers for security reasons.

Anatomy of the attack on the Swiss State

According to the official update from the Swiss Federal Office for Information Technology and Telecommunications (BIT) , security experts detected suspicious activity in SharePoint systems on July 28. The attackers exploited known vulnerabilities that Microsoft had gradually patched, although the exact CVE remains under investigation. The vulnerabilities under scrutiny include CVE-2026-56164 for administrator privileges and CVE-2026-50522 for remote code execution.

The BIT incident response team was forced to completely cut off external access to SharePoint to stop the attackers from moving laterally. Despite the fact that administrators immediately proceeded with a mass password reset, the damage to 200 accounts was already done. If you want to learn more about protecting your infrastructure, read our recently published article on cloud network security .

SharePoint and business risk

The biggest mistake organizations make is treating SharePoint as a simple internal document storage tool. When servers are directly connected to the without strict segmentation, they automatically become targets for bots scanning the internet for unpatched installations. In the case of Switzerland, the only safety net was the organization’s policy of prohibiting the storage of highly sensitive personal data on the platform.

If your business relies on on-premise or hybrid SharePoint infrastructures, patch response time determines whether you will be attacked. Attackers don't wait a week; they leverage automated scripts a few hours after Microsoft publishes security advisories.

What to do now on your networks

If you manage such services, it's not enough to simply apply the latest patch and relax. You need to take specific steps to immediately protect yourself before hackers find a backdoor into your systems.

First, check SharePoint logs for unusual HTTP requests to service folders and API endpoints. Second, temporarily isolate external access if you notice the slightest sign of anomalous behavior in user logins. Third, perform a direct check of the machine keys and certificates of the servers to rule out the possibility of Persistence, as happened in previous similar attacks.

Our opinion at TechNoid

We at TechNoid believe that the Swiss government’s response was extremely slow in its philosophy, despite its quick reflexes on the day of the incident. The fact that the servers were affected by vulnerabilities that had been announced since July shows a lack of automation in patch management. It’s not just Microsoft’s fault that the codes were leaked; it’s the “we’ll do it on the weekend” culture that is costing governments and multinationals. If we were in BIT’s shoes, the servers would have been automatically quarantined within 48 hours of Patch Tuesday, without a second thought.

Frequently Asked Questions about the cyberattack on SharePoint servers in Switzerland

Which organization in Switzerland was the victim of the cyberattack?

The Federal Office for Information Technology and Telecommunications (BIT) was the body affected.

How many user accounts were affected by the breach?

Around 200 user accounts were compromised by the attackers.

Which software platform was targeted by hackers?

The attackers exploited security vulnerabilities in Microsoft SharePoint servers.

Was there a leak of confidential or sensitive data?

According to investigations so far, no sensitive data was leaked, as its storage on the platform in question is prohibited.

What measures did the Swiss government take immediately after detecting the attack?

BIT blocked external access, reset the passwords and began a complete reinstallation of the servers.

What vulnerabilities are considered possible causes of the attack?

Researchers are investigating the CVE-2026-56164 and CVE-2026-50522 security vulnerabilities that were patched in July.

Which agency is collaborating to investigate the incident?

BIT is investigating the incident in collaboration with the Swiss Federal Cybersecurity Agency and Microsoft.

NewsRoom
NewsRoomhttps://technoid.gr
The editorial team of Technoid.gr consists of experienced journalists and technology enthusiasts with many years of experience in the specialized press. With a focus on validity and objective analysis, NewsRoom conveys the pulse of global developments, from the latest gadgets to the revolutionary innovations that are changing our world.

Related Articles

LEAVE A REPLY

enter your comment!
please enter your name here

- Advertisement -

Stay Connected

321SupportersLike
112FollowersFollow
231FollowersFollow
- Advertisement -

Most Popular 48hrs

- Advertisement -

Latest Articles