The Swiss government has confirmed a cyberattack targeting SharePoint servers managed by the Federal Office for Information Technology and Telecommunication (BIT). The breach has affected around 200 user and technical accounts, compromising their login credentials. BIT identified unusual activities on its SharePoint systems on Tuesday, July 28.
Investigation and Immediate Response
Security experts promptly investigated the irregularities and identified that the attack exploited recent vulnerabilities disclosed in Microsoft SharePoint. BIT responded by blocking internet access to the compromised systems and applied necessary security patches. Microsoft had revealed multiple vulnerabilities in SharePoint earlier in July, prompting organizations to secure their systems.
SharePoint is a widely used platform for document storage and internal communication. BIT operates several SharePoint servers across Swiss federal data centers for government services. Despite the swift response, authorities suspect that malicious actors may have exploited the vulnerabilities before all defenses were in place.
Extent of the Breach and Ongoing Investigation
As forensic investigations continue, it was discovered on Friday, July 31, that login credentials for various user and technical accounts had been compromised. BIT took immediate action by resetting the passwords for all affected accounts. So far, there is no evidence indicating that files or sensitive data were extracted from the compromised environment.
BIT is collaborating with the Federal Office for Cyber Security (BACS) and Microsoft to assess the full scope of the attack. The investigation remains active, with authorities not ruling out further findings. Meanwhile, the installation of security updates continues, and external internet access to the platform remains restricted until security can be assured.
Preventive Measures and Security Implications
The incident underscores the vulnerability of internet-facing platforms like SharePoint, which are attractive targets due to their critical role in business operations and data management. Prompt patching, credential monitoring, and network restrictions are essential strategies in responding to such breaches.
BIT has reported the incident to BACS and the State Secretariat for Security Policy (SEPOS) as per Switzerland’s Information Security Act. They have also shared technical details with other infrastructure operators via the BACS platform to help identify potential related threats.
As a precaution, BIT is reinstalling the affected servers, ensuring federal employees can still access documents internally and use alternative methods for external communication. The event highlights the need for robust cybersecurity measures to protect sensitive information and maintain operational integrity.
