Switzerland’s federal IT office says attackers breached its Microsoft SharePoint servers by exploiting a vulnerability and compromised about 200 accounts. BIT responded by blocking external SharePoint access, patching the suspected flaws, resetting passwords, and investigating the incident with the Swiss Federal Office for Cyber Security and Microsoft. #SharePoint #BIT #Microsoft
Keypoints
- BIT detected unusual activity on its SharePoint servers on July 28.
- Hackers compromised login credentials for several accounts, affecting roughly 200 accounts.
- BIT blocked external access, patched the suspected vulnerabilities, and reset passwords.
- The attack may have involved CVE-2026-56164 or CVE-2026-50522, both fixed in July 2026 Patch Tuesday.
- BIT is reinstalling the compromised servers and has found no evidence of data theft so far.