Swiss Federal IT Office Reinstalls SharePoint Servers After Access Credentials Were Compromised
What Is Confirmed So Far
Switzerland’s Federal Office of Information Technology, Systems and Telecommunication, FOITT, reported a cyberattack against on-premises SharePoint servers operated for the federal administration.
The analysis found that access credentials for around 200 user and technical accounts had been compromised. FOITT reset the affected passwords, blocked internet access to SharePoint for people outside the federal administration, and is reinstalling the affected servers as a precautionary measure.
At this stage, FOITT has found no evidence of data leakage beyond the compromised access credentials. The analysis is ongoing with support from the Swiss National Cyber Security Centre, NCSC, and Microsoft.
The Key Distinction
FOITT states that the unknown actors are believed to have exploited Microsoft SharePoint vulnerabilities reported by Microsoft in mid-July.
However, the public information does not name a specific CVE as the confirmed initial access vector for this incident. This matters because the July SharePoint wave includes several actively exploited vulnerabilities in on-premises SharePoint Server environments, including CVE-2026-50522 and other CVEs from the same series.
The accurate framing is this: the incident occurred amid active exploitation of SharePoint vulnerabilities, but FOITT has not publicly confirmed which vulnerability, if any, served as the initial access vector in this case.
Why the Case Matters
SharePoint often functions as a working environment for documents, collaboration, internal sharing and exchange with external participants. When such an environment is affected, the investigation cannot stop at patch deployment.
Compromised access credentials change the task. Teams need to determine which accounts were exposed, what permissions they had, whether they were used after compromise, and whether there are signs of document access, permission changes or unusual administrative activity.
Server reinstallation is a precautionary measure, not automatic proof that every system was fully compromised. But when system integrity is uncertain, this approach reduces risk before external access is restored.
What Organizations Should Check
Organizations using on-premises SharePoint Server should look beyond whether the latest patch has been installed.
Practical checks:
- whether SharePoint Server was exposed to the internet;
- whether all July updates and supported builds have been applied;
- which user and technical accounts have SharePoint access;
- whether passwords, tokens, certificates, machine keys, secrets and service principals have been rotated;
- whether IIS, SharePoint ULS, Windows Event, authentication, proxy and firewall logs have been reviewed;
- whether there are signs of web shells, persistence, unusual administrative actions or lateral movement;
- whether there are traces of bulk file downloads, permission changes or access from unusual locations;
- whether there is a safe recovery plan before external access is restored.
In a SharePoint incident, patching reduces risk, but it does not answer whether the system was already used by an attacker. A compromise assessment is needed before and after updating.
DIAMATIX Comment
From the DIAMATIX perspective, this case shows why document and collaboration platforms should be part of daily monitoring, not only maintenance.
SharePoint contains documents, access paths, technical accounts and links to internal processes. If such an environment is compromised, the team needs to prove not only whether the patch was applied, but whether identities, keys and the environment itself can be trusted after the incident.
SOC (Security Operations Center) and MDR (Managed Detection and Response) processes should connect signals from servers, accounts, network access and logs. This helps the investigation determine faster whether the incident is contained or whether there are signs of wider activity.
Questions for CISO and IT Teams
- Which SharePoint environments are on-premises and internet-facing?
- Which accounts, keys and service identities must be rotated after an incident?
- Do we retain enough logs for retrospective investigation?
- Can we detect web shells, persistence or unusual administrative actions?
- Can we prove whether documents were accessed, downloaded or shared?
- Is there a clear recovery process before external access is restored?
The practical takeaway: for on-premises SharePoint Server, patching is only one part of response. After possible exploitation, teams must verify whether the system, credentials and keys have been restored to a trustworthy state.
Review your readiness for SharePoint and collaboration-platform incidents
DIAMATIX can help review exposure, access, logs, technical accounts and response processes for incidents involving SharePoint and other collaboration platforms.
Request a visibility and response readiness review with DIAMATIX.
Trusted · Innovative · Vigilant
Sources
- Federal Office of Information Technology, Systems and Telecommunication, FOITT. Cyberattack against SharePoint servers.
- Swissinfo / Keystone-SDA. Swiss federal IT office hit by cyberattack.
- National Cyber Security Centre Switzerland, NCSC.
- CERT-EU. Critical Vulnerabilities in Microsoft SharePoint.
- NHS England Digital. Critical Vulnerability CVE-2026-50522 in Microsoft SharePoint Server Under Exploitation.
- CERT-FR. Multiple vulnerabilities in Microsoft SharePoint.
This article is based on publicly available information as of 10.08.2026. It does not attribute the Swiss incident to a specific CVE because no such CVE has been publicly confirmed in the available sources.






