Swiss Government Hack Exposes 200 Official Accounts in Silent Breach
By 813 Staff
On August 6, Swiss federal authorities confirmed that a breach of their SharePoint infrastructure compromised roughly 200 user accounts, a figure first reported by @BleepinComputer. Internal documents show the attack was detected in late July, but the rollout of remediation measures has been anything but smooth, with affected agencies only now beginning to rotate credentials and audit access logs.
The intrusion targeted the Swiss Federal Administration’s shared document platform, which hosts sensitive inter-departmental communications, procurement records, and personnel files. Engineers close to the project say the attackers exploited a misconfigured service account with elevated privileges, allowing them to move laterally across multiple directorates before triggering alerts. The exact entry vector remains unconfirmed, though preliminary analysis points to a phishing campaign that bypassed multi-factor authentication on a subset of legacy accounts.
What makes this breach distinct is not the scale—200 accounts is modest by enterprise standards—but the concentration. The compromised profiles belonged largely to mid-level administrators and legal advisors, individuals whose access patterns grant deep visibility into cross-agency workflows. That suggests the actors were not casting a wide net but selecting targets with specific clearance, a tactic more commonly associated with espionage operations than opportunistic cybercrime.
For the broader market, this incident underscores a recurring lesson: on-premises collaboration tools are becoming the weak link in zero-trust architectures. The Swiss government has been migrating workflows to Microsoft 365, but internal memos reveal that a significant portion of legacy SharePoint farms remained unpatched, with some servers running builds from 2021. Security teams had flagged these systems for decommissioning in Q3, but budget approvals lagged, leaving the window open.
The immediate next steps involve a mandatory password reset for all 200 affected users and a forensic review of document exfiltration, though officials have stated that no evidence of data theft has been confirmed as of this writing. Federal cybersecurity agency MELANI has issued a restricted advisory to cantonal governments, urging them to audit similar SharePoint deployments.
What remains uncertain is attribution. Swiss authorities have not named a suspected actor, and public statements are conspicuously vague. Analysts are watching whether this connects to a broader campaign targeting neutral European governments, but such speculation is currently unverified. For now, the focus is on containment and answering why a misconfigured account survived two years of scheduled audits—a question that will likely shape procurement decisions well beyond Bern.
Source: https://x.com/BleepinComputer/status/2085431314363101229


