SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency

Wait 5 sec.

Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue.Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The FOITT said the unknown attackers are believed to have exploited vulnerabilities in Microsoft’s SharePoint software. The software manufacturer had reported several such vulnerabilities in mid-July. The FOITT is the largest IT service provider in the Federal Administration. It provides around 50,000 workstation systems, develops customised, secure and user-friendly IT solutions together with the administrative units, and operates over 1,000 specialist applications, mainly in its own modern data centres.The FOITT operated the servers in the federal government’s own data centres and, according to its own statements, had immediately begun installing the security updates provided. FOITT detected the anomalies on July 28 and confirmed the account compromise three days later, on July 31.“The cyberattack was carried out by previously unknown actors, presumably by exploiting these vulnerabilities in the SharePoint software,” the Swiss agency said.“During the course of their analysis, the experts discovered on July 31 that the login details for around 200 user and technical accounts had been compromised.” reports the media outlet Swiss Info. “According to its own statements, the FOITT immediately reset the relevant passwords. Based on the investigations to date, which are being supported by the National Cybersecurity Centre (NCSC) and Microsoft, there is no evidence of any further data leakage. However, the analysis is still ongoing.”Both user and technical accounts were hit. On the same day anomalous access was detected, FOITT blocked external internet access to SharePoint and began patching. It’s now reinstalling the affected servers entirely as a precaution and has shared all relevant technical indicators with Swiss critical infrastructure operators through the national cybersecurity agency’s platform.The July Patch Tuesday timing matters here. Microsoft disclosed multiple serious SharePoint vulnerabilities on July 14. One flaw, tracked as CVE-2026-50522 (CVSS score of 9.8) could enable an attacker to execute remote code over a network. Microsoft said exploitation would be considered low complexity, as an attacker does not require a great deal of knowledge of the system to complete an attack. Researchers warned that attackers are stealing machine keys to maintain long-term access. That last part is the critical detail: machine keys are the cryptographic secrets that IIS uses to sign session tokens, and once stolen they let an attacker forge legitimate-looking requests that a fully patched server will still accept.The Swiss FOITT is reinstalling the affected SharePoint servers as a precaution after the cyber incident. External internet access remains blocked until the work is complete, while federal employees can still access and share documents through alternative channels. FOITT pointed out that the platform is not intended to store confidential information or highly sensitive personal data.Patching closes the door; it doesn’t change the locks. SharePoint is increasingly targeted by cybercriminals and nation-state actors because of its deep integration with Microsoft authentication. Attackers exploiting vulnerabilities could use it as an entry point to compromise wider networks, making direct internet exposure of SharePoint servers a growing security risk.“CERT-EU strongly recommends updating affected servers as soon as possible, rotating credentials for any assets that may have been vulnerable and exposed to the internet, and conducting a compromise assessment to identify potentially affected SharePoint instances.” CERT-EU’s advisory warns. “Given the number of recent critical vulnerabilities affecting SharePoint, organisations should reconsider exposing any Microsoft SharePoint Server directly to the internet.”Neither Microsoft nor CISA have attributed the exploitations publicly to any specific threat group. Switzerland’s National Cyber Security Centre (NCSC) recorded 28 cyberattacks targeting the Federal Administration in 2025 and 325 incidents affecting critical infrastructure, with about one in four involving public administration. One of the most notable cases hit the state-owned defense contractor Ruag, whose U.S. subsidiary was breached by the Akira ransomware group, leading to data theft and a ransom payment to recover the stolen information.The practical takeaway for any organization still running on-premises SharePoint exposed to the internet: apply the July patches, then rotate your machine keys and restart IISm in that order, not one without the other. If you can’t take the server offline to reinstall it the way FOITT is doing, at minimum validate that external internet exposure has been eliminated. The window between vulnerability disclosure and active exploitation in this campaign was measured in days, not weeks.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)