Switzerland’s federal IT agency disclosed that attackers compromised about 200 accounts on on-premises SharePoint servers operated by the Federal Office for Information Technology and Communications (BIT), also referred to in reporting as FOITT. The intrusion was detected after anomalies were identified roughly a week earlier, and officials said both user and technical accounts were affected. Initial analysis found no evidence that data beyond login credentials was accessed, and the attackers had not been publicly identified.
Swiss authorities said the breach likely involved exploitation of SharePoint vulnerabilities patched by Microsoft in its July Patch Tuesday updates. In response, the agency blocked internet access to the affected SharePoint systems for users outside the federal administration, applied patches, and began reinstalling impacted servers. The incident adds to wider concern over active exploitation of SharePoint flaws, including the risk that abused IIS machine keys could let attackers retain persistence unless the keys are rotated and IIS is restarted.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
On August 5, 2026, the Canton of Graubünden said it detected a cyberattack against a SharePoint server hosting the cantonal administration’s website after a warning about similar attacks on Swiss federal SharePoint systems. Initial analysis found no evidence of data exfiltration or compromised accounts, and the canton scheduled emergency patching while temporarily taking the website offline.
On July 31, 2026, analysis determined that credentials for about 200 user and technical accounts had been compromised in the SharePoint incident. The affected passwords were then reset, while authorities said they had found no evidence of data leakage beyond the credentials.
FOITT said Switzerland’s National Cybersecurity Centre and Microsoft are supporting the investigation into the SharePoint compromise. The agency also shared relevant technical indicators from the incident with Swiss critical infrastructure operators through the national cybersecurity platform.
BIT/FOITT disclosed that attackers had compromised roughly 200 accounts on its on-premises SharePoint servers. Its initial analysis found no evidence that data beyond login credentials had been accessed, and the attackers had not been identified.
After detecting the intrusion, BIT patched the SharePoint vulnerabilities it believed were exploited and started reinstalling the affected servers as a precaution. The agency suspected exploitation of vulnerabilities addressed in Microsoft’s July Patch Tuesday updates.
On the same day the anomalous access was detected, BIT blocked internet access to the affected SharePoint systems, including access for users outside the federal administration. This was part of its immediate containment response.
Switzerland’s Federal Office for Information Technology and Communications (BIT/FOITT) said security specialists detected anomalies on its on-premises Microsoft SharePoint servers. The agency later linked the activity to a compromise affecting about 200 user and technical accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
11 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcecyberveille.ch
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcemalware.news
Open sourcetherecord.media
Open sourceadmin.ch
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.