Cybersecurity
Swiss Federal IT Office Hit by Cyberattack, 200 Accounts Breached
The Federal Office of Information Technology (FOITT) blocked external internet access to its SharePoint servers following a cyberattack that exploited software vulnerabilities and compromised around 200 user accounts.

Digital Siege: Federal IT Infrastructure Under Fire
Switzerland’s digital fortress has been breached. In a staggering blow to national administrative security, the Federal Office of Information Technology, Systems and Telecommunication (FOITT) has been forced to sever all external internet access to its SharePoint servers. This drastic 'kill-switch' maneuver follows a sophisticated cyberattack that has left the government grappling with the security of its internal collaboration networks. While federal staff maintain internal document access, the outside world—and potential attackers—have been locked out of the system entirely. This isn't just a technical glitch; it is a high-stakes defensive posture against an unknown adversary. The FOITT operates these servers within the government’s own high-security data centers, yet even these domestic bastions proved vulnerable. As of today, the servers are undergoing a total reinstallation, a move that underscores the severity of the intrusion. The message is clear: the Swiss digital perimeter is under constant, aggressive surveillance, and the attackers have found a way in.
Exploiting the Gap: The SharePoint Vulnerability
Timing is everything in cyber warfare, and the attackers struck with surgical precision. The breach exploited specific vulnerabilities in Microsoft’s SharePoint software—vulnerabilities that the manufacturer had only just identified in mid-July. Despite the FOITT immediately initiating security patches, the attackers moved faster than the bureaucracy could update. This highlights a critical 'patch gap' where government systems remain exposed even after a threat is known. The National Cybersecurity Centre (NCSC) and Microsoft experts are now working around the clock to trace the footprint of the intrusion. While the FOITT insists that no 'confidential information' or 'sensitive personal data' is stored on these specific platforms, the breach of a primary collaboration tool used for file storage and administration raises alarming questions about the integrity of federal workflows. The vulnerability wasn't just in the code; it was in the window of time between the discovery of the flaw and the completion of the defense.
The 200 Account Crisis: Assessing the Damage
A staggering 200 user and technical accounts have been compromised in this single event. On July 31, forensic analysts discovered that login credentials for these accounts had been harvested by the intruders. The FOITT acted instantly to reset passwords, but the damage to the trust of the network is significant. While officials claim there is 'no evidence' of further data leakage, the investigation remains active and fluid. Contrast this with the 2025 attack on the defense contractor Ruag, where the Akira hacker group successfully held data for ransom. In that instance, the government-owned entity eventually paid the blackmailers—a move that set a dangerous precedent. In this current SharePoint breach, the focus is on containment and total system reconstruction. The sheer volume of 200 compromised accounts suggests a broad attempt to gain a foothold within the federal administration’s digital ecosystem, potentially seeking a pathway to even more sensitive systems.
A Nation at Risk: The Escalating Cyber War
Switzerland is facing nearly one attack every single day on its critical infrastructure. Last year alone, the NCSC recorded 325 attacks on vital systems, with public administration bodies—federal, cantonal, and municipal—accounting for one in four of these reports. The Federal Administration itself was targeted 28 times in the past year, proving that the neutrality of the Swiss state offers no protection in the digital realm. This latest SharePoint breach is a wake-up call for a nation that prides itself on security and discretion. As the FOITT works to bring its servers back online, the broader implication is undeniable: the frequency and sophistication of these attacks are surging. Switzerland must now confront a reality where its administrative backbone is a primary target for global cyber-aggressors. The move to reinstall servers from scratch is a necessary, albeit costly, admission that in the modern age, total isolation is sometimes the only way to ensure total security. The digital frontier is the new frontline for Swiss sovereignty.