Hackers Compromise Swiss Government SharePoint Servers

Swiss federal authorities have confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and Telecommunication (BIT). The incident resulted in the compromise of login credentials linked to approximately 200 user and technical accounts.

BIT detected unusual activity on its SharePoint environment on Tuesday, July 28. Security specialists quickly investigated the anomalies and confirmed that the servers may have been targeted through recently disclosed Microsoft SharePoint vulnerabilities. The agency immediately blocked internet access to the affected SharePoint systems and applied the required security fixes.

After Microsoft released security updates, BIT began installing the patches on its systems. However, investigators believe unknown threat actors may have exploited the vulnerabilities before all defensive actions were completed. The exact identity, origin, and motives of the attackers remain unknown.

During the ongoing forensic investigation, security teams discovered on Friday, July 31, that several login credentials had been compromised. The affected accounts included both standard user accounts and technical accounts used by systems or applications. BIT responded by resetting passwords for all impacted accounts.

Authorities stated that current analysis has not identified evidence that files, documents, or other data were exfiltrated from the SharePoint platform. The compromise appears to be limited to credentials associated with around 200 accounts. Investigators also noted that confidential government information and highly sensitive personal data are not permitted to be stored on the affected SharePoint environment.

BIT is working with the Federal Office for Cyber Security (BACS) and Microsoft to investigate the intrusion and determine the full scope of the attack. The technical investigation remains active, and authorities have not ruled out further findings as forensic work continues.

As a precaution, BIT is reinstalling the affected SharePoint servers. External internet access to the platform will remain blocked until the recovery work is completed and officials confirm that the environment is secure. Federal administration employees can still access documents internally and use alternative methods to share information with external personnel.

The incident highlights the ongoing risks facing organizations that run internet-facing collaboration platforms. SharePoint systems can become attractive targets because they often hold business documents, provide access to internal users, and integrate with other Microsoft services. Prompt patching, credential monitoring, network restrictions, and server rebuilding remain important response measures after suspected exploitation.

BIT reported the incident to BACS and the State Secretariat for Security Policy, or SEPOS, within the required timeframe under Switzerland’s Information Security Act. The agency also shared relevant technical indicators from the attack on critical infrastructure with operators via the BACS platform, helping other organizations identify potential signs of related intrusion activity.

This breach underscores the critical importance of timely patching and vigilant monitoring of collaboration platforms like SharePoint. Organizations must prioritize securing these systems to prevent unauthorized access and potential data breaches. Implementing robust security measures, such as regular vulnerability assessments and incident response planning, is essential to mitigate the risks associated with such attacks.