On July 28, 2026, security specialists at the Federal Office for Information Technology and Telecommunication (BIT/FOITT) detected anomalous activity on the Swiss federal administration's SharePoint servers. Three days later, on July 31, the compromise of approximately 200 accounts — both user and technical — was confirmed. The incident did not involve a zero-day vulnerability: the flaws had been fixed by Microsoft in its July bulletin, but the gap between patch availability and application gave attackers enough time to establish persistence.
- Approximately 200 user and technical accounts compromised on BIT/FOITT SharePoint servers, detected July 28 and confirmed July 31, 2026.
- The exploited vulnerabilities were disclosed by Microsoft in mid-July and patched in the July Patch Tuesday; this was not a zero-day.
- The BIT is reinstalling compromised servers as a precaution and maintains the external access block until work is complete.
- The agency found no evidence of data exfiltration beyond access credentials, and the affected platform did not host sensitive or classified personal data.
The Intrusion Sequence: Late Detection, Radical Response
The chain of events is documented in the BIT's official statement, cited by the sources. On July 28, security specialists noticed unusual activity on the SharePoint servers. By July 31, according to the same source, it emerged that access credentials for roughly 200 accounts had been compromised. The agency immediately reset passwords for all affected accounts and blocked external Internet access to the SharePoint platform.
The response went beyond credential rotation. The BIT is reinstalling the compromised servers as a precautionary measure, an indication of the perceived severity of the incident. External access remains suspended until this operation concludes. Users are employing alternative methods for document sharing, according to TechRadar.
The Gap Between Available Patch and Applied Patch
The technical core of the incident lies in the nature of the exploited vulnerabilities. The BIT believes attackers exploited SharePoint flaws disclosed by Microsoft in mid-July and patched in the July 2026 Patch Tuesday. Microsoft confirmed that CVE-2026-56164, a privilege escalation vulnerability with CVSS 5.3 (MEDIUM), is under active exploitation, according to the Microsoft Security Response Center. The attack vector is remote, with low complexity, and requires no pre-existing privileges or user interaction.
A second vulnerability, CVE-2026-50522, is described as a critical RCE with documented exploitation for machine key theft, which would enable persistent access even after patching. However, neither the BIT nor Microsoft have confirmed which of the two flaws, or both, was exploited in the Swiss incident. The dossier does not specify whether machine keys were actually stolen in this case.
"Patching closes the door; it doesn't change the locks" — analysis by Security Affairs, cited in the context of the incident.
Investigative Support and Indicator Sharing
The investigation is supported by the Federal Office for Cybersecurity (BACS/NCSC) and Microsoft. The BIT reported the incident to the BACS and the State Secretariat for Security Policy under the Information Security Act. Technicians shared technical indicators with critical infrastructure operators through the BACS platform.
Despite the collaboration, no elements have emerged to enable attribution of the attack. The BIT describes the attackers as "previously unknown actors." No ransomware or extortion group has claimed the incident. The dossier does not document confirmed lateral movement prior to detection, nor the exact nature of any data accessed beyond credentials.
Operational Context: Scale and Pressure on FOITT
The incident hits an agency managing a substantial IT infrastructure: roughly 50,000 workstation systems and over 1,000 specialized applications, according to Security Affairs. The BIT operates under growing pressure: in 2025, the NCSC recorded 28 cyberattacks against the federal administration and 325 incidents involving critical infrastructure.
Globally, approximately 1,500 on-premises SharePoint servers remain exposed on the Internet, according to Censys scans cited by Help Net Security in the context of CVE-2026-50522. This attack surface, combined with active exploitation of SharePoint vulnerabilities, makes the platform a recurring target for actors seeking persistent access to corporate and government networks.
Immediate Actions
- Verify the application status of the July 2026 Patch Tuesday updates on all on-premises SharePoint instances, prioritizing Internet-exposed systems.
- Rotate credentials for all accounts with access to compromised or potentially exposed SharePoint servers, including technical service accounts.
- Evaluate rotation of SharePoint machine keys where technically applicable, given the documented possibility of theft for post-patch persistence.
- Review SharePoint server access logs for the period July 15–31, 2026, searching for authentication anomalies or unauthorized code execution.
Why the Swiss Incident Changes the Patching Calculus
The BIT/FOITT case dismantles the narrative that patching timeliness alone is sufficient to contain risk. Patches were available, but application did not occur before attackers obtained valid credentials. The agency's response — server reinstallation, not merely applying updates — indicates that the structural damage of the compromise precedes the availability of the fix.
For SharePoint administrators, the lesson is operational and counter-intuitive: Patch Tuesday closes the flaw, but does not automatically invalidate access obtained through it. Credential rotation, and where indicated, machine key rotation, becomes an integral part of the response cycle, not a subsequent option. The absence of sensitive data on the affected platform mitigated the reputational and regulatory impact for the Confederation, but not the operational one: rebuilding a federal agency's collaboration infrastructure remains a cost measurable in work-days and service disruption.
Attackers have demonstrated that the exposure window — not the technical availability of the patch — is the variable that matters. It is a shift in perspective that security newsrooms are reporting with increasing frequency. The Swiss case provides institutional confirmation.
Sources
- https://www.helpnetsecurity.com/2026/08/07/swiss-government-microsoft-sharepoint-vulnerabilities/
- https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/amp/
- https://securityaffairs.com/196625/hacking/sharepoint-flaws-used-to-hack-switzerlands-federal-it-agency.html
- https://www.scworld.com/brief/swiss-federal-it-agency-foitt-compromised-about-200-accounts-due-to-sharepoint-flaws
- https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
- https://www.techradar.com/pro/security/swiss-government-says-sharepoint-linked-data-breach-affected-hundreds-of-accounts
- https://cybersecuritynews.com/hackers-breach-swiss-sharepoint-servers/
- https://www.helpnetsecurity.com/2026/07/15/microsoft-patch-tuesday-sharepoint-cve-2026-56164/
- https://www.helpnetsecurity.com/2026/07/22/sharepoint-cve-2026-50522-exploited/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
Information verified against cited sources and current as of publication.