Swiss Government Confirms Data Breach Across 200 SharePoint Accounts
The Swiss government reported that attackers breached Microsoft SharePoint servers belonging to the Federal Office for Information Technology and Telecommunication, compromising roughly 200 accounts. Authorities disconnected affected servers from the internet and launched an investigation with Microsoft. Officials stated that no sensitive data was stored on the platform, and the stolen information has not yet appeared online.
Key points
- The Federal Office for Information Technology and Telecommunication (BIT), the Swiss government's IT agency, experienced a cyberattack on its SharePoint servers.
- Security specialists detected abnormalities on July 28, 2026, and confirmed on July 31 that approximately 200 user and technical accounts were breached.
- Investigators suspect the intrusion exploited two SharePoint vulnerabilities that Microsoft patched in mid-July.
- Authorities disconnected certain servers from the wider internet and stated that no confidential or particularly sensitive personal data was stored on the platform.
The Swiss government has confirmed a cyberattack targeting the Federal Office for Information Technology and Telecommunication (BIT), resulting in the unauthorized access of data from approximately 200 accounts. Security specialists first detected network abnormalities on July 28, 2026, prompting an internal investigation that three days later confirmed the breach of roughly 200 user and technical accounts.
In response to the incident, authorities disconnected impacted servers from the wider internet. Investigators, with the assistance of Microsoft, are currently examining the breach and attempting to identify the perpetrators. While the initial access vector remains unconfirmed, officials suspect the attackers exploited a pair of SharePoint vulnerabilities that Microsoft patched in mid-July.
Despite the breach, the Swiss government stated that no confidential information or particularly sensitive personal data was permitted to be stored on the platform. The identity of the attackers remains unknown, and authorities reported that the stolen data has not yet surfaced on the dark web.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.