highOther

Swiss Federal SharePoint Server Breach

First seen Aug 10, 2026 · Updated Aug 10, 2026

sharepointgovernmentdata-breachaccount-compromiseon-premises

Switzerland's Federal Office of Information Technology disclosed that attackers exploited vulnerabilities in on-premises Microsoft SharePoint servers to compromise roughly 200 government accounts. The incident highlights ongoing risks tied to unpatched or exposed SharePoint deployments within critical government infrastructure.

Technical Analysis

The breach reportedly involved exploitation of vulnerabilities in on-premises SharePoint Server deployments, a class of attack consistent with prior SharePoint remote code execution and authentication bypass flaws (e.g., CVE-2023-29357, CVE-2023-24955) commonly chained by threat actors to gain server-level access and harvest credentials or session tokens. Compromise of approximately 200 accounts suggests either direct credential theft from SharePoint's user store or lateral movement following initial server compromise, potentially via web shells or malicious ASPX payloads dropped on IIS-hosted SharePoint instances. No specific CVE was confirmed in the source material, so the exact exploit chain remains unverified pending official technical disclosure. If compromised accounts included service or application accounts used by internal automation, RAG pipelines, or AI agents with SharePoint connectors for document retrieval, exposed credentials or API tokens could allow attackers to exfiltrate sensitive indexed content or poison retrieval sources feeding agent workflows.

Affected Systems

On-premises Microsoft SharePoint Server (version unspecified) operated by Switzerland's Federal Office of Information Technology, Systems and Telecommunication (BIT); approximately 200 associated user/service accounts

Indicators of Compromise

  • No specific hashes, IPs, or domains disclosed in available reporting

Remediation Steps

  1. 1

    Patch SharePoint Servers

    Apply all available Microsoft security updates for SharePoint Server, prioritizing known RCE and auth-bypass CVEs (e.g., CVE-2023-29357, CVE-2023-24955, and any newer ToolShell-class vulnerabilities).

  2. 2

    Rotate Compromised Credentials

    Force password resets and invalidate active sessions/tokens for all affected and adjacent accounts, including service accounts used by connected applications or agents.

  3. 3

    Audit SharePoint Access Logs

    Review IIS and SharePoint ULS logs for signs of web shell deployment, unusual authentication patterns, or unauthorized admin actions.

  4. 4

    Isolate and Scan for Web Shells

    Inspect SharePoint server file systems for unauthorized ASPX/web shell files and remove persistence mechanisms.

  5. 5

    Restrict External Exposure

    Limit SharePoint server exposure to the internet where possible and enforce MFA and conditional access policies for all accounts.

  6. 6

    Review Agent/Automation Integrations

    Audit any AI agents, RAG pipelines, or automation tools with SharePoint connectors for compromised credentials or unauthorized data access.

Industries Most Exposed

governmentpublic sector

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.