started · updated
Swiss Government SharePoint Servers Breached, Hundreds of Accounts
Unknown cyber‑actors exploited two recently disclosed SharePoint vulnerabilities (including CVE‑2026‑56164 and CVE‑2026‑50522) to gain access to the Federal Office for Information Technology and Telecommunication (BIT) SharePoint servers. The breach was first detected on 28 July 2026, and investigators confirmed that data from roughly 200 user and technical accounts had been accessed.
The Swiss government responded by isolating the affected servers, disconnecting them from the internet, resetting passwords and beginning a full rebuild of the server environment. No confidential or sensitive personal data is believed to have been stored on the platform, and no evidence of data exfiltration to the dark web has been found. BIT is receiving technical assistance from Microsoft and the Federal Office for Cybersecurity (BACS) as the forensic analysis continues.
Entities
Federal Office for Cybersecurity (BACS) · Federal Office for Information Technology and Telecommunication (BIT) · Microsoft