Swiss Federal IT Office Breach Compromises 200 Accounts
Hackers exploited on-premises SharePoint vulnerabilities to infiltrate government data centers.
Hackers have compromised approximately 200 user and technical accounts within Switzerland's Federal Office for Information Technology, Systems and Telecommunication (FOITT/BIT). The breach targeted on-premises Microsoft SharePoint servers hosted in the federal government's own data centers, signaling a significant security lapse in the nation's digital infrastructure.
Security specialists first detected anomalies on July 31, 2026. According to the FOITT, the attack was carried out by previously unknown actors who likely exploited vulnerabilities in the SharePoint software. In response, the agency took immediate remediation steps, which included resetting passwords, blocking external internet access to the affected servers, and performing full reinstallations of the compromised systems as a precautionary measure. Despite the scale of the account compromise, the FOITT stated that no confidential information or particularly sensitive personal data is stored on the SharePoint platform.
The SharePoint Vulnerability Trend
This incident occurs amid a global surge in attacks targeting Microsoft SharePoint servers. In July 2026, Microsoft released patches for several critical vulnerabilities, some of which were subsequently added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog. These specific flaws are particularly dangerous because they allow attackers to extract machine keys from Internet Information Services (IIS). By stealing these cryptographic secrets, hackers can forge session tokens, allowing them to maintain a persistent presence within a network even after the initial software vulnerabilities have been patched.
Risks of Legacy Infrastructure
The breach underscores the inherent risks of maintaining on-premises legacy infrastructure within government environments. Because SharePoint is deeply integrated with core authentication services, a foothold in these servers can serve as a jumping-off point for attackers to pivot deeper into a secure network. The fact that the Swiss government found it necessary to completely reinstall servers—rather than simply applying software updates—highlights the severity of machine key theft. When such secrets are stolen, the only way to fully evict an attacker is to rotate the cryptographic keys and rebuild the environment from a known clean state.
Future Outlook
While the FOITT has taken steps to secure the environment, the identity of the attackers remains unknown. Security analysts will be watching to see if this breach was an isolated incident or part of a wider campaign targeting European government entities. The primary remaining question is whether the attackers attempted to use their 200 compromised accounts to move laterally into other federal systems before the anomalies were detected on July 31.