
Switzerland’s Federal Office for Information Technology and Communications (BIT) disclosed Tuesday that unknown attackers broke into its on-premises SharePoint servers and compromised approximately 200 accounts — a mix of user and technical service accounts. The agency said its early analysis found no evidence that any data beyond the stolen credentials was accessed, though it cautioned that investigation is ongoing. The BIT also noted that no confidential information or particularly sensitive personal data was stored on the affected SharePoint platform. Once the anomalous access was detected, BIT blocked all internet-facing access to SharePoint and applied the relevant patches on the same day.
SharePoint is a persistent target for both financially motivated groups and nation-state actors: it is widely used to store internal documents and is deeply integrated with Microsoft’s authentication infrastructure, meaning that access to a SharePoint server can be a launchpad for broader network compromise. Several of the vulnerabilities associated with this incident appear in CISA’s Known Exploited Vulnerabilities catalog, though neither Microsoft nor CISA has publicly attributed this specific attack to any threat group. One complicating factor is that certain SharePoint vulnerabilities expose machine keys — the cryptographic secrets SharePoint uses to sign internal authentication tokens. When those keys are stolen, an attacker can forge legitimate-looking requests that a patched server will still accept. CISA, CERT-EU, and national CERTs have repeatedly warned that patching alone is insufficient: machine keys must also be rotated and IIS restarted before a compromised server can be considered clean. BIT said it is reinstalling the affected servers as an additional precaution rather than relying on the patch alone.
