ctipilot.ch

Canton Graubünden SharePoint Server breach (Switzerland, 2026-08)

incident · incident:graubuenden-canton-sharepoint-breach-2026-08 single-source-victim

Intrusion into the public-facing Microsoft SharePoint server operated by Canton Graubünden's Amt für Informatik, which hosts the cantonal administration's web presence. The canton dates the attack to the afternoon of 29 July 2026 and disclosed it on 2026-08-05, one day after the Swiss Confederation's IT provider BIT disclosed its own on-premises SharePoint intrusion; two files were placed on the server without their code executing, and a first analysis found no compromised accounts and no data exfiltration (Kanton Graubünden, 2026-08-05).

Aliases: Cyberangriff auf einen SharePoint-Server des Kantons Graubünden, AFI Graubünden Cyberangriff

Coverage timeline
1
first 2026-08-06 → last 2026-08-06
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
2
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
Microsoft SharePoint Server

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-06/canton-graubuenden-sharepoint-server-breach · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-08-06/canton-graubuenden-sharepoint-server-breach · ATT&CK page ↗

Story timeline

  1. 2026-08-06Canton Graubünden discloses a SharePoint server breach a day after the Confederation did — the on-premises wave has reached Swiss cantonal government
    active-threatsA second Swiss public-sector SharePoint victim in 48 hours, and the intrusion sat unnoticed for a week

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • active-threats1

Source distribution

  • gr.ch1 (33%)
  • persoenlich.com1 (33%)
  • swissinfo.ch1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Canton Graubünden SharePoint Server breach (Switzerland, 2026-08) (1)

2026-08-06 · view entry permalink →

HIGHexploitedNATOA2

Canton Graubünden discloses a SharePoint server breach a day after the Confederation did — the on-premises wave has reached Swiss cantonal government

The Amt für Informatik (AFI) of Canton Graubünden detected a cyberattack against the SharePoint server that hosts the cantonal administration's public web presence (Kanton Graubünden, 2026-08-05). The canton's own account is that a first analysis found no indication that accounts were compromised or data exfiltrated, and that confidential information and specially-protected personal data are not stored on those web-presence servers in the first place; the cantonal ePortal and specialised applications were unaffected and remained reachable through the remediation (Kanton Graubünden, 2026-08-05). AFI head Lorenz Tanner, speaking to the Keystone-SDA news agency, put the intrusion on the afternoon of 29 July and said two files were placed on the server whose code was not executed — meaning the compromise sat unremarked for roughly a week before disclosure (persoenlich.com, 2026-08-05). AFI carried out an extraordinary update from the evening of 5 August (persoenlich.com, 2026-08-05), during which the canton said its website would be unreachable for several hours (Kanton Graubünden, 2026-08-05).

What makes this operationally significant for the constituency is not the canton's own limited damage but the pattern: this is the second confirmed Swiss public-sector victim of on-premises SharePoint exploitation disclosed in two days, after the Confederation's IT provider BIT reported roughly 200 compromised federal user and technical accounts (covered here on 2026-08-05). Tanner's stated view is that it could be the same vulnerability identified at federal level, one he describes as affecting SharePoint systems worldwide, and AFI is coordinating with the Federal Office for Cybersecurity (persoenlich.com, 2026-08-05). That link is a plausibility stated by the victim, not a confirmed technical finding — neither Swiss disclosure names a CVE, and no authority has published one for either incident, so an operator should treat "same flaw as the Confederation" as a working hypothesis rather than a scoping fact.

Triage: SharePoint farms legitimately write files into those directories during solution deployments, patch installation and content updates, so file creation alone is not the signal. The discriminators are timing and actor — writes that fall outside a change window, that are not attributable to an administrator session or a deployment job, and that are performed by the web-server worker process rather than the update or deployment tooling. A file that never executes, as at Graubünden, produces no process-execution event at all, so a detection strategy resting only on child-process spawning would have missed this one.

Das Amt für Informatik hat einen Cyberangriff auf einen SharePoint-Server des Kantons festgestellt.

Eine erste Analyse hat ergeben, dass es keine Anzeichen darauf gibt, dass Konten kompromittiert oder Daten abgeflossen sind.

Kanton Graubünden — Standeskanzlei 2026-08-05

Es wurden zwei Dateien platziert, deren Code allerdings nicht ausgeführt worden sei.

persoenlich.com (Keystone-SDA) 2026-08-05
incident06 Aug 04:11Zsingle-source · victim disclosureOpen finding ↗