BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Aug 4, 2026 · 2 min read · Original story

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected

Switzerland’s Federal Office for Information Technology and Communications (BIT) disclosed Tuesday that hackers had compromised approximately 200 accounts on its on-premises SharePoint servers.

The agency made the announcement a week after security specialists first detected anomalies on the on-premises Microsoft servers. It did not confirm how the hackers got in but acknowledged several vulnerabilities affecting SharePoint had been identified in July’s Patch Tuesday release.

“The cyberattack was carried out by previously unknown actors, presumably by exploiting these vulnerabilities in the SharePoint software,” the Swiss agency said.

Several of the vulnerabilities have been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, although neither Microsoft nor CISA have publicly attributed the exploitations to any specific threat group.

The Swiss agency said its initial analyses “have shown no indication that any data beyond the compromised login credentials” was accessed, although it cautioned this analysis is ongoing. It added that “no confidential information or particularly sensitive personal data may be stored on the SharePoint platform.”

SharePoint is a prime target for both financially motivated hackers as well as state-sponsored groups seeking intelligence. The service — as well as often being used to store confidential documents — is deeply integrated with Microsoft’s authentication services, meaning skillful enough hackers could use a foothold there to burrow deeper into their victims’ networks.

Both user and technical accounts were compromised at the Swiss agency, which said that on the same day the anomalous access was detected, blocked internet access to SharePoint and patched the vulnerabilities.

Organizations in both the private and public sectors have issued alerts about July’s SharePoint issues. CERT-EU stated: “Given the number of recent critical vulnerabilities affecting SharePoint, organizations should reconsider exposing any Microsoft SharePoint Server directly to the internet.”

CISA warned that attackers exploiting the flaws were extracting machine keys from Microsoft's Internet Information Services (IIS) — the web server underpinning SharePoint — granting them the cryptographic secrets used to sign session tokens and establish persistence.

Once stolen, those keys let an attacker forge legitimate-looking requests that a fully patched server will still accept, meaning a credential leak on a SharePoint server can outlive the patch that closed the original hole.

CISA, CERT-EU and other national CERTs stressed the need to rotate machine keys and restart IIS rather than simply apply the patch. The BIT said it was reinstalling the affected SharePoint servers as a preventative measure.

References in this story

  1. Microsoft smashes Patch Tuesday record for second successive month therecord.media Vulnerability counts have been surging this year, and Microsoft's mammoth disclosure this week of 622 bugs is larger than the three previous months combined.
  2. Critical Vulnerabilities in Microsoft SharePoint cert.europa.eu Critical Vulnerabilities in Microsoft SharePoint
  3. CISA Urges SharePoint Hardening After New Exploitations | CISA www.cisa.gov
  4. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  5. Alex Martin (@AlexMartin) on X twitter.com UK Editor: @TheRecord_Media | Fellowship alumnus: @VirtualRoutes | @SkyNews | Agent: @NorthbankTalent
  6. Alexander Martin (@alexmartin.bsky.social) bsky.app Journalist covering cybersecurity and intelligence. UK Editor at The Record from Recorded Future News. Dad of two. 🏠 Sheffield 📧 [email protected] 📱 Signal: AlexanderMartin.79

← Back to all news