ctipilot.ch

BIT/FOITT SharePoint Server breach (Switzerland, 2026-07)

incident · incident:foitt-bit-sharepoint-breach-2026-07 single-source-victim

Intrusion into the on-premises Microsoft SharePoint Servers operated by Switzerland's Bundesamt für Informatik und Telekommunikation (BIT) in the Confederation's own data centres. Anomalies were noticed 2026-07-28 and credential compromise of roughly 200 user and technical accounts was confirmed 2026-07-31; BIT states the attack was carried out by previously unknown actors and presumably enabled by exploitation of the SharePoint flaws Microsoft disclosed in mid-July 2026, with no indication of further data exfiltration. Disclosed by the Federal Council / BIT on 2026-08-04; the affected servers are being rebuilt (Der Bundesrat / BIT, 2026-08-04).

Aliases: Cyberangriff auf SharePoint-Server des BIT, Bundesamt für Informatik und Telekommunikation SharePoint-Angriff

Coverage timeline
4
first 2026-08-05 → last 2026-08-13
Peak priority
high
4 high
Sources cited
15
13 hosts
Sections touched
4
active-threats, deep-dive, updates
Co-occurring entities
2
see Related entities below
ATT&CK techniques
11
pinned v19.2 · see below
2026-08-054 appearances2026-08-13

Hunting pivots

Affected products
Microsoft SharePoint ServerMicrosoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription EditionOracle WebLogic Server

ATT&CK techniques

11 techniques observed across 4 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1190Exploit Public-Facing Application×4

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-13/sharepoint-cve-2026-55040-jwt-forgery-exploited-root-cause · 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · 2026-08-06/canton-graubuenden-sharepoint-server-breach · 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Credential Access TA0006

T1606Forge Web Credentials×1

Adversaries may forge credential materials that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies, tokens, or other materials to authenticate and authorize user access.

Evidence: 2026-08-13/sharepoint-cve-2026-55040-jwt-forgery-exploited-root-cause · ATT&CK page ↗

Discovery TA0007

T1087.002Account Discovery: Domain Account×1

Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.

Evidence: 2026-08-13/sharepoint-cve-2026-55040-jwt-forgery-exploited-root-cause · ATT&CK page ↗

Lateral Movement TA0008

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-08-13/sharepoint-cve-2026-55040-jwt-forgery-exploited-root-cause · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-08-06/canton-graubuenden-sharepoint-server-breach · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Story timeline

  1. 2026-08-13UPDATE — attackers are running Rapid7's SharePoint proof-of-concept against honeypots within a day, and the published root cause is four validation failures that let an unsigned token impersonate a site administrator
    updatesThe SharePoint JWT bypass moved from proof-of-concept to observed attack traffic in under 24 hours, and its mechanics give defenders a specific server-side hunt
  2. 2026-08-09European government's own operating infrastructure was the target this week — a federal document platform, a national beneficial-ownership register, a state treasury and a heat plant, with two of the entry points on no internet-facing asset inventory
    weekly-top-storiesEuropean public bodies in five jurisdictions compromised in one week, and two of the entry points were on no asset inventory
  3. 2026-08-06Canton Graubünden discloses a SharePoint server breach a day after the Confederation did — the on-premises wave has reached Swiss cantonal government
    active-threatsA second Swiss public-sector SharePoint victim in 48 hours, and the intrusion sat unnoticed for a week
  4. 2026-08-05Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed
    deep-diveSwiss federal SharePoint servers breached mid-patching — ~200 accounts taken, servers now being rebuilt

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • deep-dive1
  • active-threats1
  • weekly-top-stories1
  • updates1

Source distribution

  • cert.pl2 (13%)
  • presseportal.ch2 (13%)
  • admin.ch1 (7%)
  • bleepingcomputer.com1 (7%)
  • cisa.gov1 (7%)
  • gr.ch1 (7%)
  • persoenlich.com1 (7%)
  • rapid7.com1 (7%)
  • other5 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (15)

Entries about BIT/FOITT SharePoint Server breach (Switzerland, 2026-07) (4)

2026-08-13 · view entry permalink →

HIGHCVE-2026-55040updateNATOB2

UPDATE — attackers are running Rapid7's SharePoint proof-of-concept against honeypots within a day, and the published root cause is four validation failures that let an unsigned token impersonate a site administrator

UPDATE · originally covered UPDATE — the half-patched SharePoint chain this pipeline flagged in July is now complete and public: CVE-2026-63520 ships, and Rapid7 releases the analysis and proof-of-concept for CVE-2026-55040 (2026-08-12)

yesterday's entry recorded that Rapid7 had published a technical analysis and proof-of-concept for CVE-2026-55040 and stated plainly that it did not have that analysis in hand, so no behavioural detail could be offered. Two things changed within a day. The proof-of-concept is being used in attacks, and the analysis — read in full for this entry — turns an exposure problem into a hunt.

Threat-intelligence company Defused reported on 2026-08-12 that "Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots", roughly a day after the code was published (BleepingComputer, 2026-08-12). That is one company observing its own sensors, not a vendor confirmation: the same report notes that "While Microsoft has labeled this security flaw as an attractive target for attackers", it has not yet flagged it as successfully exploited in the wild (BleepingComputer, 2026-08-12). Switzerland's NCSC added the exploitation-attempt claim to its own July Patch Tuesday advisory on 12 August, having added the analysis and proof-of-concept to the same advisory the day before (NCSC-CH, 2026-08-12). For scale, the same reporting cites Shadowserver, which "currently tracks over 8,500 Microsoft SharePoint servers exposed online", with the honest caveat that how many are honeypots or already patched is unknown (BleepingComputer, 2026-08-12).

How the bypass works, and why it matters that it is four bugs and not one. Rapid7's analysis, based on decompilation of the identity module from a fully patched Subscription Edition build, states that "The root cause is a chain of four distinct weaknesses that, when combined, allow an unauthenticated remote attacker to forge a valid JWT and impersonate any SharePoint site user" (Rapid7, 2026-08-11). SharePoint's server-to-server authentication uses a nested token: an outer token carrying user identity claims, and an inner "actor token" representing the calling application that is expected to be cryptographically signed. Each of the four failures removes one guarantee from that design.

First, the token handler explicitly turns off the requirement for signed tokens when it builds its validation parameters — Rapid7's description is blunt: "This single line disables the JWT library's cryptographic signature verification", so the outer token is accepted with no signature at all. Second, the code resolves the inner actor token's signing key from a thumbprint value carried in that token's own header, searching all trusted certificates including SharePoint's own local security-token-service certificate, and assigns the resolved key without ever verifying a signature against it. Third, issuer validation then looks for a registered token service matching that certificate, does not find one — because the server's own signing certificate is not in the collection being searched — and treats the absence of a match as grounds to accept rather than reject. Fourth, the final signature step requires only that a signature string be non-empty; any arbitrary value satisfies it. The result is that the identity in the outer token's name claim, which the caller chooses, is resolved to a real account. (Rapid7, 2026-08-11)

Two properties of that chain matter operationally more than the mechanics themselves. The certificate whose thumbprint the attacker needs is published by the server: Rapid7 records that it is retrievable from an unauthenticated metadata endpoint on the SharePoint site itself, so no prior access is required to obtain it. And picking a useful identity is a separate reconnaissance step — Rapid7 describes querying the target's domain controller over an anonymous SMB session to learn the domain identifier, then walking relative identifiers to enumerate candidate accounts and find one that is a site administrator, noting that a user principal name works too but is less reliable to guess. (Rapid7, 2026-08-11)

Detection, in telemetry terms. The decisive weakness leaves a server-side record: Rapid7's decompilation shows the issuer-validation path emitting a trace message stating that the issuer was accepted because no registered token service matches the signing certificate, immediately before returning success (Rapid7, 2026-08-11). On a healthy farm that path should be rare; on an attacked one it fires on every forged token. That message in the SharePoint diagnostic trace logs is the highest-value single artefact available, and it is a server-side one, so it survives an attacker who never touches the endpoint. Alongside it, three sequences are worth building around: an unauthenticated request to the site's metadata endpoint from an external address, followed within a short window by bearer-token requests to the site's REST API from the same source; authenticated REST activity — reading files, minting a form digest, changing configuration — with no corresponding interactive sign-in or federation token issuance for that account in identity logs; and anonymous SMB sessions enumerating account identifiers from an address that also talks to the SharePoint front end.

Triage: legitimate server-to-server integrations also present bearer tokens to the SharePoint REST API, which is why the token's presence is not the signal. The discriminators are the ones the mechanism forces: a token whose acceptance is accompanied by the unregistered-signing-certificate trace message, activity attributed to a highly privileged account with no matching sign-in event in the identity provider, and an external source address that fetched the unauthenticated metadata endpoint shortly beforehand. A normal integration is registered, so its issuer resolves against a registered token service and never takes the accepting-by-default branch.

The root cause is a chain of four distinct weaknesses that, when combined, allow an unauthenticated remote attacker to forge a valid JWT and impersonate any SharePoint site user.

This single line disables the JWT library's cryptographic signature verification.

Rapid7 2026-08-11

Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots

Defused, quoted by BleepingComputer

Internet threat watchdog Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online.

While Microsoft has labeled this security flaw as an attractive target for attackers

BleepingComputer 2026-08-12
vulnerability13 Aug 04:55Zmulti-sourceOpen finding ↗

2026-08-09 · view entry permalink →

HIGHexploitedNATOA1

European government's own operating infrastructure was the target this week — a federal document platform, a national beneficial-ownership register, a state treasury and a heat plant, with two of the entry points on no internet-facing asset inventory

If you did nothing this week: peer institutions in five European jurisdictions disclosed compromises of the machinery they run the state with — and in two of them the way in was connectivity and legacy infrastructure that appears on no internet-facing asset inventory.

Switzerland took two of them in 48 hours, at both levels of government. The Bundesamt für Informatik und Telekommunikation, which operates the Confederation's own data centres, disclosed on 4 August that its on-premises SharePoint Servers were compromised and that "rund 200 Konten kompromittiert wurden" — user accounts and technical service accounts alike (Der Bundesrat / BIT, 2026-08-04). The detail that matters for anyone still running on-premises SharePoint is the timing: BIT had begun installing the July updates immediately on release, and staff spotted the anomalies on 28 July while that work was in progress, so the servers are being rebuilt from scratch rather than patched in place. One day later the Canton of Graubünden's IT office reported a compromise of a SharePoint server hosting the cantonal administration's public web presence, reporting on first analysis no accounts compromised and no data exfiltrated (Kanton Graubünden, 2026-08-05); Keystone-SDA reporting adds that two files were placed on the server and their code was not executed (persoenlich.com, 2026-08-05). Neither Swiss disclosure names a CVE, which is why an estate-wide compromise assessment keyed on the July SharePoint exploitation window — not a CVE-scoped patch check — is the operation this pair calls for.

Two further disclosures show the objective shifting from the citizen's data to the state's own authoritative record. Liechtenstein's Amt für Justiz lost copies of the beneficial-ownership register: "Datenkopien von rund 31'000 Rechtsträgern widerrechtlich abgegriffen" (Regierung des Fürstentums Liechtenstein, 2026-08-02), and the government's follow-up media conference published the exact field set — legal-entity name plus surname, first name, date of birth, nationality and country of residence, with no address, telephone number or financial data recorded (Regierung des Fürstentums Liechtenstein, 2026-08-04). That composition is the point: what was taken is an identity-verification kit tied to the natural persons behind Swiss- and EU-administered structures, not a marketing list. In Hungary, Telex.hu reports that the Magyar Államkincstár's Agricultural and Rural Development Office was breached in late July by ByteToBreach — the actor already tracked here for the attack on Romania's national land registry — with experts consulted on attacker-leaked screenshots assessing entry through an Oracle WebLogic server whose fixes date to an October 2017 patch cycle, escalating to Windows domain-administrator rights (Telex.hu, 2026-08-03).

The week's most consequential access path was published on its last day. CERT Polska's follow-up forensic report on the 29 December 2025 attacks on Poland's energy sector discloses a second, previously unnamed victim — a combined heat and power plant supplying about 50,000 residents, where three Siemens PLCs were switched to STOP mode and password-locked, shutting down a steam turbine and the process-water treatment system. The attacker reached it from an already-compromised wind-farm substation by tunnelling over SSH through a cellular router into the distribution system operator's private APN, a mobile network shared by both sites, and then into a WAGO PFC200 controller whose WAN-side web interface answered on factory credentials (CERT Polska incident follow-up report, 2026-08-08). CERT Polska states that "the use of a private APN to gain access to the OT network was the first instance of this attack vector being observed in a real-world cyberattack," and — the sentence European operators should act on — that surveys of organisations using similar solutions "indicated that this configuration was commonly encountered in Poland" (CERT Polska, 2026-08-08). Belgium supplies the fifth shape: Digitaal Vlaanderen confirmed to WIRED that Belgium's Centre for Cybersecurity notified it on 3 March 2026 of a North Korean compromise, that the affected workstation was isolated and exposed credentials rotated, and that the incident is contained — one organisation inside a victim set the researcher built from nearly two years of access to the actors' own servers (WIRED, 2026-08-05).

Triage: a compromised administrative estate of this kind produces telemetry that reads as ordinary operations, so the discriminators are relational rather than atomic. For the SharePoint cases, look for web-application process trees spawning script interpreters and for service-account authentication from hosts those accounts never normally touch — a service account is defined by its narrow, repetitive access pattern, and the deviation is the signal. For the OT path, the discriminator is direction and origin: an inbound management session to a field controller arriving from a peer device inside the carrier APN rather than from the operator's own engineering workstation subnet, and a controller-mode change (run to STOP) with no corresponding change-management window. Legitimate remote maintenance produces the same protocol events; it does not normally originate from another site's equipment.

Im Rahmen der Analyse des Vorfalls wurde festgestellt, dass rund 200 Konten kompromittiert wurden.

Der Bundesrat / Bundesamt für Informatik und Telekommunikation (BIT) 2026-08-04

Dabei wurden Datenkopien von rund 31'000 Rechtsträgern widerrechtlich abgegriffen.

Regierung des Fürstentums Liechtenstein 2026-08-02

To the best of our knowledge, the use of a private APN to gain access to the OT network was the first instance of this attack vector being observed in a real-world cyberattack.

Surveys conducted among organizations using similar solutions indicated that this configuration was commonly encountered in Poland.

CERT Polska (NASK) 2026-08-08

Builds on: 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · 2026-08-06/canton-graubuenden-sharepoint-server-breach · 2026-08-04/liechtenstein-vwbp-beneficial-ownership-register-breach · 2026-08-05/liechtenstein-vwbp-entry-point-identified-field-set · 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-08-08/dprk-contagious-interview-blast-radius-flemish-government

synthesis09 Aug 23:45Zmulti-sourceOpen finding ↗

2026-08-06 · view entry permalink →

HIGHexploitedNATOA2

Canton Graubünden discloses a SharePoint server breach a day after the Confederation did — the on-premises wave has reached Swiss cantonal government

The Amt für Informatik (AFI) of Canton Graubünden detected a cyberattack against the SharePoint server that hosts the cantonal administration's public web presence (Kanton Graubünden, 2026-08-05). The canton's own account is that a first analysis found no indication that accounts were compromised or data exfiltrated, and that confidential information and specially-protected personal data are not stored on those web-presence servers in the first place; the cantonal ePortal and specialised applications were unaffected and remained reachable through the remediation (Kanton Graubünden, 2026-08-05). AFI head Lorenz Tanner, speaking to the Keystone-SDA news agency, put the intrusion on the afternoon of 29 July and said two files were placed on the server whose code was not executed — meaning the compromise sat unremarked for roughly a week before disclosure (persoenlich.com, 2026-08-05). AFI carried out an extraordinary update from the evening of 5 August (persoenlich.com, 2026-08-05), during which the canton said its website would be unreachable for several hours (Kanton Graubünden, 2026-08-05).

What makes this operationally significant for the constituency is not the canton's own limited damage but the pattern: this is the second confirmed Swiss public-sector victim of on-premises SharePoint exploitation disclosed in two days, after the Confederation's IT provider BIT reported roughly 200 compromised federal user and technical accounts (covered here on 2026-08-05). Tanner's stated view is that it could be the same vulnerability identified at federal level, one he describes as affecting SharePoint systems worldwide, and AFI is coordinating with the Federal Office for Cybersecurity (persoenlich.com, 2026-08-05). That link is a plausibility stated by the victim, not a confirmed technical finding — neither Swiss disclosure names a CVE, and no authority has published one for either incident, so an operator should treat "same flaw as the Confederation" as a working hypothesis rather than a scoping fact.

Triage: SharePoint farms legitimately write files into those directories during solution deployments, patch installation and content updates, so file creation alone is not the signal. The discriminators are timing and actor — writes that fall outside a change window, that are not attributable to an administrator session or a deployment job, and that are performed by the web-server worker process rather than the update or deployment tooling. A file that never executes, as at Graubünden, produces no process-execution event at all, so a detection strategy resting only on child-process spawning would have missed this one.

Das Amt für Informatik hat einen Cyberangriff auf einen SharePoint-Server des Kantons festgestellt.

Eine erste Analyse hat ergeben, dass es keine Anzeichen darauf gibt, dass Konten kompromittiert oder Daten abgeflossen sind.

Kanton Graubünden — Standeskanzlei 2026-08-05

Es wurden zwei Dateien platziert, deren Code allerdings nicht ausgeführt worden sei.

persoenlich.com (Keystone-SDA) 2026-08-05
incident06 Aug 04:11Zsingle-source · victim disclosureOpen finding ↗

Earlier coverage (1)