Swiss IT Agency BIT Compromised via Suspected SharePoint Vulnerabilities
Switzerland's Federal Office for Information Technology and Communications (BIT) reported a breach affecting around 200 accounts, with exploitation of SharePoint vulnerabilities suspected.

Switzerland’s Federal Office for Information Technology and Communications (BIT) disclosed a significant security incident where approximately 200 accounts on its on-premises SharePoint servers were compromised by unknown actors. The breach was detected by security specialists who observed anomalies on the agency's Microsoft servers. While the exact entry point remains unconfirmed, the BIT suspects that vulnerabilities within SharePoint software were exploited, particularly those addressed in Microsoft's July Patch Tuesday release.
Several of the implicated SharePoint vulnerabilities have since been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog. However, neither Microsoft nor CISA have publicly attributed these specific exploitations to any particular threat group. The BIT's initial investigation indicates that the compromised accounts primarily involved login credentials, with no immediate evidence of broader data exfiltration. The agency cautioned, however, that this analysis is ongoing and that the affected SharePoint platform does not store highly sensitive personal data or confidential information.
SharePoint servers are a frequent target for both financially motivated cybercriminals and state-sponsored intelligence-gathering operations. Its deep integration with Microsoft's authentication services makes it a valuable pivot point for attackers aiming to gain deeper access into a victim's network. The compromise at the BIT affected both user and technical accounts. Upon detecting the anomalous access, the agency took immediate action by blocking internet access to the affected SharePoint environment and applying patches to the identified vulnerabilities.
This incident highlights a broader trend of attacks targeting SharePoint. Organizations globally have been alerted to the risks associated with these vulnerabilities. CERT-EU, for instance, advised organizations to reconsider exposing Microsoft SharePoint Server directly to the internet due to the number of critical vulnerabilities recently discovered. The advisory underscores the persistent threat landscape surrounding widely used enterprise software.
CISA issued a specific warning regarding the exploitation of these flaws, noting that attackers were capable of extracting machine keys from Microsoft's Internet Information Services (IIS), the web server that underpins SharePoint. These stolen keys grant attackers cryptographic secrets used for signing session tokens, enabling them to establish persistence within a compromised network. This means that even after the initial vulnerability is patched, a leaked credential on a SharePoint server could still be leveraged by an attacker.
To fully mitigate the risks, CISA, CERT-EU, and other national CERTs emphasized the critical need to rotate machine keys and restart IIS, rather than solely relying on patch application. The BIT confirmed it was taking further preventative measures by reinstalling the affected SharePoint servers to ensure a clean and secure environment. This comprehensive approach aims to eradicate any lingering threats and restore the integrity of their systems.
The incident serves as a stark reminder for organizations to maintain robust patch management practices and to closely monitor their Microsoft environments for any signs of compromise. The potential for attackers to leverage stolen credentials and cryptographic keys to maintain persistent access underscores the importance of proactive security measures and thorough incident response protocols.