Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Swiss Government IT Agency Confirms SharePoint Breach, About 200 Accounts Compromised
Swiss Government IT Agency Confirms SharePoint Breach, About 200 Accounts Compromised
Read Time:3 Minute, 31 Second

Switzerland’s Federal Office for Information Technology, Systems and Telecommunication (BIT), the agency that runs IT infrastructure for the country’s federal administration, has confirmed that attackers broke into its SharePoint environment and made off with login credentials tied to roughly 200 accounts.

How the Intrusion Was Found

BIT says it first noticed unusual behavior on its SharePoint systems on Tuesday, July 28. Once its security team started digging into the anomalies, investigators concluded the servers had likely been targeted through a set of Microsoft SharePoint vulnerabilities that were publicly disclosed in mid-July. BIT operates several SharePoint instances out of Swiss federal data centers, and those systems support everything from document storage to internal collaboration for government staff.

The agency had already begun rolling out Microsoft’s patches for the disclosed flaws by the time the odd activity surfaced, but investigators now believe unidentified attackers managed to exploit the holes before every system was fully secured. As of this writing, the identity and motive of the intruders remain unknown, and BIT has not attributed the incident to any particular group or country.

Roughly 200 Accounts Affected

Three days after detecting the intrusion, on Friday, July 31, BIT’s forensic team discovered that a batch of login credentials had actually been compromised. The exposure spans both standard user accounts belonging to employees and technical accounts used by internal systems and applications to authenticate with one another. In response, BIT reset passwords across every affected account.

Officials say that, based on the investigation so far, there is no indication that documents or other files were actually pulled out of the SharePoint platform. They also point out that Switzerland’s rules bar the storage of classified government material or highly sensitive personal data on that particular environment, which limits the potential blast radius even if the compromise turns out to be worse than currently understood.

Containment and Recovery

As soon as the credential theft was confirmed, BIT cut off internet access to the affected SharePoint servers entirely. That has kept the systems reachable for internal federal staff, who can still open documents and collaborate through internal channels, while blocking any external connection until the agency is confident the environment is clean.

Rather than simply patch and move on, BIT is taking the more conservative route of rebuilding the impacted servers from scratch. Public internet access will stay disabled until that rebuild is finished and the agency can verify the platform is secure again.

BIT is coordinating its response with the Federal Office for Cyber Security (BACS) and with Microsoft, and the technical investigation is still active. Officials caution that further findings are possible as the forensic work continues, meaning the scope of the incident could still change.

Wider Reporting and Information Sharing

In line with obligations under Switzerland’s Information Security Act, BIT reported the breach to both BACS and the State Secretariat for Security Policy (SEPOS) within the required window. The agency also passed along technical indicators tied to the attack to operators of critical infrastructure through the BACS information-sharing platform, giving other organizations a chance to check their own environments for related activity.

Why SharePoint Keeps Ending Up in the Crosshairs

This incident is the latest reminder that internet-facing collaboration platforms remain a favorite target for attackers. SharePoint deployments are attractive precisely because of what makes them useful: they store business-critical documents, provide broad internal access, and integrate tightly with other Microsoft services such as Outlook, Teams, and Active Directory. A single successful exploit can open doors well beyond the platform itself.

Security teams responding to similar exposure typically lean on a handful of core measures, including:

  • Patching internet-facing collaboration servers as soon as vendor fixes are available, rather than waiting for a routine maintenance window
  • Monitoring for credential misuse and forcing resets across any account that may have been exposed
  • Restricting or temporarily removing external network access to vulnerable systems while remediation is underway
  • Rebuilding compromised servers instead of trusting that patching alone has removed every foothold an attacker may have planted

For now, Swiss federal employees can continue working through internal systems, but the public-facing SharePoint environment will stay dark until BIT completes its rebuild and confirms the intrusion has been fully contained.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Swiss Government IT Agency Confirms SharePoint Breach, About 200 Accounts Compromised, use the discussion on Forum.

>> forum community

Comments

Leave a Reply