Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
Key Takeaways Swiss federal authorities confirmed a cyberattack on SharePoint servers managed by the Federal Office for Information Technology and Telecommunication (BIT). The breach, detected on...
Key Takeaways
- Swiss federal authorities confirmed a cyberattack on SharePoint servers managed by the Federal Office for Information Technology and Telecommunication (BIT).
- The breach, detected on July 28, led to the compromise of login credentials for approximately 200 user and technical accounts.
- Investigators suspect the attackers exploited recently disclosed Microsoft SharePoint vulnerabilities before patches were fully deployed.
- While no data exfiltration has been confirmed, BIT has reset compromised passwords, blocked external access, and is rebuilding affected servers.
Swiss federal authorities have confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and Telecommunication (BIT). This incident resulted in the compromise of login credentials for roughly 200 user and technical accounts within the government’s IT infrastructure.
Table Of Content
The Federal Office for Information Technology and Telecommunication initially detected unusual activity within its SharePoint environment on Tuesday, July 28. Security specialists quickly launched an investigation into the anomalies, confirming that the servers were likely targeted through recently disclosed Microsoft SharePoint vulnerabilities.
In response to the confirmed breach, the agency immediately restricted internet access to the affected SharePoint systems and applied necessary security fixes. Microsoft had released multiple patches for SharePoint vulnerabilities in mid-July.
SharePoint is a widely utilized platform for document storage, collaborative work, internal communications, and file sharing across many organizations. BIT operates several SharePoint servers within Swiss federal data centers to support various government services and employee workflows.
Swiss Government SharePoint Compromised
Following the release of Microsoft’s security updates, BIT commenced the process of installing these patches across its systems. However, investigators now believe that unknown threat actors may have exploited the vulnerabilities before the patching and other defensive measures were fully completed.
The precise identity, origin, and motivations of the attackers remain unconfirmed as the forensic investigation continues. During this ongoing inquiry, security teams discovered on Friday, July 31, that several login credentials had been compromised.
The affected credentials included both standard user accounts and technical accounts, which are typically used by systems or applications. In response, BIT promptly initiated a password reset for all impacted accounts.
Authorities said that current analysis has not yielded any evidence to suggest that files, documents, or other data were exfiltrated from the SharePoint platform. The compromise appears to be limited to the credentials associated with approximately 200 accounts.
Investigators further noted that the affected SharePoint environment is not permitted to store confidential government information or highly sensitive personal data, which may limit the potential impact of the credential compromise.
Ongoing Investigation and Mitigation Efforts
BIT is collaborating closely with the Federal Office for Cyber Security (BACS) and Microsoft to thoroughly investigate the intrusion and ascertain the full scope of the attack. The technical investigation is active, and authorities have indicated that further findings are possible as forensic work progresses.
As a precautionary measure, BIT is in the process of reinstalling the compromised SharePoint servers. External internet access to the platform will remain blocked until this recovery work is complete and officials can confirm the environment’s security. Federal administration employees can still access documents internally and use alternative methods for sharing information with external personnel during this period.
This incident underscores the persistent risks faced by organizations managing internet-facing collaboration platforms. SharePoint systems are frequently targeted due to their central role in holding business documents, providing internal user access, and integrating with other Microsoft services.
BIT reported the incident to BACS and the State Secretariat for Security Policy (SEPOS) within the timeframe mandated by Switzerland’s Information Security Act. The agency also shared relevant technical indicators from the attack with operators of critical infrastructure via the BACS platform, aiming to help other organizations detect potential signs of similar intrusion activity.
What You Should Do
- Apply Patches Immediately: Ensure all systems, especially internet-facing collaboration platforms like SharePoint, are patched promptly following vendor security updates.
- Implement Strong Credential Management: Enforce strong, unique passwords for all accounts and consider multi-factor authentication (MFA) to mitigate credential compromise.
- Monitor for Unusual Activity: Continuously monitor network traffic and system logs for any anomalous behavior, especially around critical systems like SharePoint.
- Restrict Network Access: Limit external access to internal collaboration platforms to only what is absolutely necessary, utilizing firewalls and network segmentation.
- Prepare for Server Rebuilding: Have a plan and resources ready to rebuild compromised servers from trusted backups to ensure a clean recovery.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.