The Swiss Federal Office for Information Technology and Communications (FOITT) has confirmed a significant cybersecurity breach affecting its on-premises SharePoint servers. According to Security Affairs, unknown threat actors gained unauthorized access to approximately 200 user and technical accounts by exploiting vulnerabilities within Microsoft’s SharePoint software.
The breach, which the FOITT detected on July 28, was officially verified on July 31. The agency manages over 1,000 specialist applications and provides roughly 50,000 workstation systems for the Swiss Federal Administration. Upon discovering the anomalies, the agency acted to secure its infrastructure by disabling external internet access to its SharePoint environment and initiating a password reset for all impacted accounts.
Incident Timeline and Data
| Event | Date |
|---|---|
| Microsoft discloses SharePoint vulnerabilities | July 14 |
| FOITT detects anomalous activity | July 28 |
| Account compromise confirmed | July 31 |
Official investigations are currently ongoing, with technical support provided by the National Cybersecurity Centre (NCSC) and Microsoft. As a preventative measure, the agency is proceeding with a full reinstallation of the compromised servers. While the FOITT has noted no evidence of further data exfiltration, the forensic analysis continues to assess the extent of the unauthorized access.
Technical reports indicate that the attackers likely leveraged vulnerabilities disclosed by Microsoft in mid-July. Among these is CVE-2026-50522, which carries a CVSS score of 9.8. This remote code execution flaw is categorized as low complexity, allowing threat actors to potentially steal machine keys—cryptographic secrets used by Internet Information Services (IIS) to sign session tokens. This technique permits attackers to maintain persistence on a network by forging legitimate session requests, even after initial software patches have been applied.
Why It Matters
The exploitation of government-hosted on-premises SharePoint servers highlights a persistent challenge in the public sector: the latency between vulnerability disclosure and the execution of comprehensive patches. When attackers successfully exfiltrate machine keys, they effectively bypass traditional credential-based security, rendering standard password resets insufficient for full remediation. This incident signals a need for infrastructure operators to move beyond simple patching toward implementing advanced identity verification and zero-trust architectures, particularly as sophisticated actors prioritize the theft of long-term cryptographic material over simple data theft. The reliance on legacy on-premises systems remains a high-value target for state-sponsored or advanced persistent threat groups.

Reader Discussion & Insights