GoFirm
Back to Blog
Case Studies·3 min read

Two hundred Swiss government accounts were compromised. Some of them belonged to no one.

By GoFirm

On 28 July 2026, security specialists at Switzerland's Federal Office for Information Technology and Telecommunication (BIT), the agency that runs shared IT infrastructure for the Swiss federal administration, noticed unusual activity on its Microsoft SharePoint servers. Three days later, on 31 July, they confirmed what that activity meant: the login credentials for approximately 200 accounts had been compromised, spanning both individual user accounts and technical accounts used by automated processes and services.

BIT believes the attackers exploited one of two Microsoft SharePoint vulnerabilities disclosed in mid-July 2026 and fixed in that month's Patch Tuesday update, CVE-2026-56164, an actively exploited privilege escalation flaw, or CVE-2026-50522, a critical remote code execution bug that lets an attacker steal a server's machine keys and keep access even after the server is patched. The agency has not said which flaw was used, or whether it was patched before or after the intrusion began.

Once the compromise was confirmed, BIT blocked external internet access to SharePoint, applied the outstanding patches, reset the passwords on every affected account, and began reinstalling the compromised servers as a precaution. External access remains blocked while that work continues. Federal employees have been told to share documents through alternative channels in the meantime.

This fits a wider pattern. The same July vulnerabilities have been under active exploitation across government and enterprise SharePoint deployments since Microsoft's disclosure, researchers have tracked, with the remote code execution flaw in particular used to steal machine keys that let attackers persist even after a server is patched. No ransomware or extortion group has claimed responsibility for the Swiss breach, and BIT says it has found no evidence that data was taken beyond the compromised credentials themselves, in part because confidential or sensitive personal data is not permitted on the affected platform.

The defences that failed here were not weak by conventional standards. BIT patches its systems, monitors for unusual activity, and caught this intrusion within three days, faster than most of the breaches in this series manage. That response still could not undo what had already happened: for those three days, and for however long before 28 July the flaw had been exploitable, roughly 200 sets of credentials, including ones tied to no human at all, were available to whoever held them.

A credential compromise spanning 200 accounts, a fifth of them technical accounts with no person behind them, is an execution event long before any data moves. Before a technical account can authenticate from a new pattern or location, or before a batch of credentials tied to a single platform starts being used at unusual volume, a confirmation request should go to the named system owner on their registered device, independent of the compromised system itself.

A stolen machine key, however cleanly extracted, cannot produce that confirmation. Neither can a service account acting exactly as it was configured to, because nothing about its behaviour looks wrong to the systems watching it. The execution boundary holds regardless of whether the credential belongs to a person who can be fooled or a process that cannot be.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams. Deploy AI securely. Provide assurance continuously.

References


1. Abrams, L. 2026. Swiss government SharePoint breach compromised 200 accounts. BleepingComputer, 6 August 2026.
2. Help Net Security. 2026. 200 accounts compromised in Swiss government's Microsoft SharePoint breach. Help Net Security, 7 August 2026.
3. The Record. 2026. Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected. The Record from Recorded Future News, 2026.

Share this article