2026-08-06 · view entry permalink →
Canton Graubünden discloses a SharePoint server breach a day after the Confederation did — the on-premises wave has reached Swiss cantonal government
The Amt für Informatik (AFI) of Canton Graubünden detected a cyberattack against the SharePoint server that hosts the cantonal administration's public web presence (Kanton Graubünden, 2026-08-05). The canton's own account is that a first analysis found no indication that accounts were compromised or data exfiltrated, and that confidential information and specially-protected personal data are not stored on those web-presence servers in the first place; the cantonal ePortal and specialised applications were unaffected and remained reachable through the remediation (Kanton Graubünden, 2026-08-05). AFI head Lorenz Tanner, speaking to the Keystone-SDA news agency, put the intrusion on the afternoon of 29 July and said two files were placed on the server whose code was not executed — meaning the compromise sat unremarked for roughly a week before disclosure (persoenlich.com, 2026-08-05). AFI carried out an extraordinary update from the evening of 5 August (persoenlich.com, 2026-08-05), during which the canton said its website would be unreachable for several hours (Kanton Graubünden, 2026-08-05).
What makes this operationally significant for the constituency is not the canton's own limited damage but the pattern: this is the second confirmed Swiss public-sector victim of on-premises SharePoint exploitation disclosed in two days, after the Confederation's IT provider BIT reported roughly 200 compromised federal user and technical accounts (covered here on 2026-08-05). Tanner's stated view is that it could be the same vulnerability identified at federal level, one he describes as affecting SharePoint systems worldwide, and AFI is coordinating with the Federal Office for Cybersecurity (persoenlich.com, 2026-08-05). That link is a plausibility stated by the victim, not a confirmed technical finding — neither Swiss disclosure names a CVE, and no authority has published one for either incident, so an operator should treat "same flaw as the Confederation" as a working hypothesis rather than a scoping fact.
Triage: SharePoint farms legitimately write files into those directories during solution deployments, patch installation and content updates, so file creation alone is not the signal. The discriminators are timing and actor — writes that fall outside a change window, that are not attributable to an administrator session or a deployment job, and that are performed by the web-server worker process rather than the update or deployment tooling. A file that never executes, as at Graubünden, produces no process-execution event at all, so a detection strategy resting only on child-process spawning would have missed this one.
Das Amt für Informatik hat einen Cyberangriff auf einen SharePoint-Server des Kantons festgestellt.
Eine erste Analyse hat ergeben, dass es keine Anzeichen darauf gibt, dass Konten kompromittiert oder Daten abgeflossen sind.
Es wurden zwei Dateien platziert, deren Code allerdings nicht ausgeführt worden sei.