Swiss IT Agency Breach: SharePoint Vulnerabilities Exploited

Swiss government IT agency hacked; SharePoint flaws suspected in 200-account breach

The recent Swiss IT agency breach, which compromised around 200 user accounts, has brought SharePoint vulnerabilities into sharp focus. Early investigations suggest that attackers may have exploited weaknesses in SharePoint systems to gain unauthorised access. This event highlights the risks facing organisations using Microsoft SharePoint and the importance of swift patching and vigilant monitoring.

Details of the Swiss IT Agency Breach

On 10 June 2024, Switzerland’s federal IT agency publicly disclosed a significant security breach. The incident involved the compromise of approximately 200 user accounts within federal systems. Initial findings indicate that the attackers may have leveraged vulnerabilities in SharePoint, Microsoft’s widely used collaboration and document management platform. The breach is notable for both its scale and the sensitive nature of the affected infrastructure.

Timeline and Discovery

  • Early June 2024: Unusual account activity detected by internal monitoring systems.
  • 7 June 2024: Security teams initiated an investigation after identifying suspicious login patterns and access anomalies.
  • 10 June 2024: The breach was publicly confirmed by the agency, and preliminary details were shared with affected users and the wider public.

While forensic investigations are ongoing, early reports suggest the attackers exploited one or more known SharePoint vulnerabilities, although the specific CVE references have not yet been publicly confirmed.

How the Attack Unfolded

The attackers appear to have targeted the agency’s SharePoint environment, potentially using a combination of credential harvesting and exploitation of unpatched software. SharePoint has historically been targeted by threat actors, especially when publicly accessible and not kept up to date with security patches. Once access was gained, malicious actors were able to pivot within the network and compromise user accounts.

Suspected Exploitation Techniques

  • Exploitation of known SharePoint vulnerabilities, possibly those allowing remote code execution or privilege escalation.
  • Harvesting of user credentials, possibly through phishing or brute force attacks targeting weak passwords.
  • Use of compromised accounts to access sensitive information and further expand their presence in the network.

Notably, the breach appears to have been limited to account compromises and unauthorised access, with no immediate evidence of ransomware deployment or destructive activity. However, the agency is continuing to assess the full scope of the incident.

Who Is Affected and What Systems Are at Risk?

The breach directly impacts users with accounts managed by the Swiss federal IT agency. Approximately 200 accounts were identified as compromised, raising concerns about potential data leakage or unauthorised actions carried out under those identities. While the agency has not disclosed the precise roles or departments affected, the scale indicates a broad reach across federal operations.

Microsoft SharePoint users are the primary group at risk in this incident. Organisations running on-premises SharePoint, particularly older or unpatched versions, are especially vulnerable. The event serves as a warning to any entity using SharePoint for internal or external collaboration, especially where systems may be exposed to the internet.

Current Exploitation Status and Ongoing Response

At the time of writing, the Swiss federal IT agency has contained the initial breach and is in the process of resetting passwords and securing affected accounts. Incident response teams are monitoring for signs of further unauthorised activity and conducting a comprehensive review of SharePoint server configurations. There is no public indication that the attackers remain active within the environment, but the investigation is ongoing.

Authorities have not yet released specifics on the exploited vulnerabilities, but security researchers have noted several high-impact SharePoint flaws disclosed in recent months. The lack of patching or delayed updates is a recurring theme in similar incidents globally.

Why This Incident Matters

This breach underscores the persistent threat posed by unpatched enterprise software, particularly widely used platforms like SharePoint. For public and private sector organisations alike, the incident is a stark reminder of the risks associated with delayed vulnerability management and insufficient monitoring of user account activity.

Key Takeaways

  • SharePoint vulnerabilities can be rapidly exploited by attackers, often within days of public disclosure.
  • Account compromise in a central IT agency can have wide-reaching effects across federal operations.
  • Timely patching and proactive monitoring are essential to reduce risk from similar attacks.

What Organisations Should Do Now

Organisations using SharePoint, especially UK businesses and public sector bodies, should:

  • Review and apply the latest security patches for SharePoint and related Microsoft products.
  • Audit external exposure of SharePoint servers, restricting access to internal networks wherever possible.
  • Monitor account activity for unusual login patterns or privilege escalations.
  • Enforce strong password policies and implement multi-factor authentication for sensitive accounts.

Rapid action can help prevent similar breaches and limit the impact of any attempted exploitation.

Originally reported by Unknown.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call