Swiss Government Agency Hit: SharePoint Vulnerabilities Lead to 200 Account Compromises
Switzerland's **Federal Office for Information Technology and Communications (BIT)** has disclosed a cyberattack compromising approximately 200 accounts on its on-premises **SharePoint** servers. The incident, believed to stem from vulnerabilities addressed in July's **Patch Tuesday**, highlights the persistent threat to a platform often targeted by both financially motivated and state-sponsored actors.
The **BIT** announced the breach a week after security specialists detected anomalies on its **Microsoft** servers. While the exact entry point remains unconfirmed, the agency strongly suspects the attackers exploited several known vulnerabilities affecting **SharePoint** that were detailed in July's **Patch Tuesday** release.
βThe cyberattack was carried out by previously unknown actors, presumably by exploiting these vulnerabilities in the **SharePoint** software,β the Swiss agency stated.
Several of these critical vulnerabilities have since been added to the **U.S. Cybersecurity and Infrastructure Security Agencyβs (CISA)** Known Exploited Vulnerabilities catalog. Neither **Microsoft** nor **CISA** have publicly attributed the exploitations to any specific threat group.
Initial analyses by the Swiss agency suggest βno indication that any data beyond the compromised login credentialsβ was accessed. However, **BIT** cautioned that this analysis is ongoing, adding that βno confidential information or particularly sensitive personal data may be stored on the **SharePoint** platform.β
**SharePoint** remains a prime target for threat actors due to its common use for storing confidential documents and its deep integration with **Microsoftβs** authentication services. A foothold in **SharePoint** can allow attackers to burrow deeper into victims' networks.
The attack compromised both user and technical accounts at the Swiss agency. Upon detecting the anomalous access, **BIT** swiftly blocked internet access to **SharePoint** and applied the necessary patches.
Organizations in both the private and public sectors have issued alerts regarding the July **SharePoint** issues. **CERT-EU** notably advised: βGiven the number of recent critical vulnerabilities affecting **SharePoint**, organizations should reconsider exposing any **Microsoft SharePoint Server** directly to the internet.β
**CISA** further warned that attackers exploiting these flaws were extracting machine keys from **Microsoft's Internet Information Services (IIS)** β the web server underpinning **SharePoint**. This grants them the cryptographic secrets used to sign session tokens and establish persistence.
Once stolen, these keys enable an attacker to forge legitimate-looking requests that a fully patched server will still accept. This means a credential leak on a **SharePoint** server can outlive the patch that closed the original vulnerability.
**CISA**, **CERT-EU**, and other national CERTs have stressed the critical need to rotate machine keys and restart **IIS** rather than simply applying patches. As a preventative measure, **BIT** is reinstalling the affected **SharePoint** servers.