Swiss government says SharePoint-linked data breach affected hundreds of accounts
The servers were disconnected to investigate the attack
- Swiss government confirms attackers breached BIT’s SharePoint servers
- Investigators suspect exploitation of recent SharePoint flaws
- No sensitive or confidential data is believed to have been stored on the platform
Cybercriminals broke into the IT network of the Swiss government and stole data from roughly 200 accounts. As a result, the Swiss government disconnected some of its servers from the wider internet and launched an investigation.
In an announcement, the Swiss government said that on July 28 2026 its security specialists noticed “abnormalities” in the Federal Office for Information Technology and Telecommunication’s (BIT) SharePoint servers.
Three days later, on July 31, the investigators determined that the attackers accessed data found in around 200 accounts, both user and technical.
Two vulnerabilities
The investigation is currently ongoing, the agency said, adding that it is getting support from Microsoft, as well. So far, the identity of the attackers is unknown, and the stolen data has not yet leaked to the dark web.
“No confidential information or particularly sensitive personal data may be stored on the SharePoint platform,” the announcement reads.
While BIT has not yet determined the initial access vector, it suspects it to be one of two flaws in SharePoint that Microsoft fixed last month:
“In mid-July, Microsoft announced several vulnerabilities in SharePoint,” it says in the announcement. “After the publication of the corresponding security updates, the FOITT immediately started work on importing them into its own systems.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“The cyberattack was carried out by previously unknown actors, which was presumably made possible by exploiting these vulnerabilities in the SharePoint software.” It did not say which vulnerabilities those are, but in its report, BleepingComputer says that it could be one of these two: CVE-2026-56164 (an actively exploited privilege escalation vulnerability), or CVE-2026-50522 (a critical remote code execution flaw later exploited to steal SharePoint machine keys and maintain access after servers were patched).
Given its popularity among businesses of all sizes, SharePoint is a major target for cybercriminals. So far, no threat actors claimed responsibility for the attack, or demanded any ransom in exchange for the stolen data.
Via BleepingComputer
➡️ Read our full guide to the best antivirus
1. Best overall:
Bitdefender Total Security
2. Best for families:
Norton 360 with LifeLock
3. Best for mobile:
McAfee Mobile Security
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.