Switzerland’s federal IT office (BIT) says hackers exploit vulnerabilities in Microsoft SharePoint servers used for government operations. BIT reports it detected unusual activity on the SharePoint platform on July 28 and then confirmed the intrusion. After confirming the breach, BIT blocks internet access to the SharePoint service and closes the vulnerabilities that attackers were using.
BIT states the attackers’ activity resulted in the compromise of login credentials for approximately 200 accounts. The following days include continued incident review, and by July 31, BIT’s security specialists identify that credentials for several accounts were affected. The reports also describe that the breach involved access through the SharePoint environment and credential compromise, rather than public disclosure of specific data contents.
The two outlets agree on the core elements: the target is BIT’s Microsoft SharePoint servers, the method is exploitation of SharePoint vulnerabilities, BIT detects and mitigates the incident after unusual activity, and the suspected impact is credential compromise across around 200 accounts. Both reports attribute the event to BIT’s official assessment and describe BIT’s containment steps.