The Swiss Federal Office of Information Technology, Systems and Telecommunication (FOITT) has blocked internet access for external users after a cyberattack compromised around 200 accounts. The attackers are believed to have exploited vulnerabilities in Microsoft's SharePoint software.

"No confidential information or particularly sensitive personal data may be stored on the SharePoint platform."
Switzerland is currently grappling with a digital siege that has forced the Federal Office of Information Technology (FOITT) to take the unprecedented step of severing internet access for all external users. This aggressive defensive maneuver follows a targeted strike against the nation's SharePoint servers, leaving the federal administration in a state of high-alert isolation. While internal staff continue to operate through alternative channels, the digital drawbridge has been raised against the outside world. This is not a drill; it is a calculated response to a breach that threatens the very backbone of Swiss administrative efficiency. The FOITT is currently engaged in a total reinstallation of the affected infrastructure, a massive technical undertaking that signals the severity of the intrusion. In a world where connectivity is king, Switzerland has chosen silence over vulnerability, proving that no entity is too large to be targeted by sophisticated digital adversaries.
A staggering 200 user and technical accounts have been confirmed as compromised in this latest breach. The attackers struck with surgical precision, exploiting known vulnerabilities in Microsoftâs SharePoint softwareâflaws that were only identified and reported in mid-July. Despite the FOITTâs immediate efforts to deploy security updates within their proprietary data centers, the hackers found a window of opportunity. On July 31, forensic experts uncovered the breach, triggering an emergency reset of all affected credentials. While the FOITT maintains that no 'highly sensitive' personal data was stored on these specific platforms, the compromise of technical accounts presents a critical risk to system integrity. The National Cybersecurity Centre (NCSC) is now working alongside Microsoft to trace the digital fingerprints of the attackers, but the analysis remains ongoing. This incident highlights the terrifying speed at which vulnerabilities are weaponized, often outpacing the defensive capabilities of even the most diligent state offices.
The numbers are alarming: the NCSC recorded 28 direct cyberattacks on the Federal Administration last year alone. However, the scope of the threat is far broader. A total of 325 attacks targeted Swiss critical infrastructure in the same period, meaning nearly one attack occurs every single day. Shockingly, in 25% of these cases, a public administration bodyâat the federal, cantonal, or municipal levelâwas the primary target. This is a relentless campaign against the stability of the Swiss state. The memory of the 2025 Akira hacker group attack on Ruag remains fresh, where data was stolen and held for ransom. Unlike the Ruag incident, where a ransom was ultimately paid to recover stolen data, the FOITT is currently standing its ground, focusing on containment and restoration. The frequency of these incursions suggests that Switzerland is no longer a neutral bystander in the global cyberwar; it is a frontline target.
As the FOITT works feverishly to reinstall its servers, the implications for Swiss digital sovereignty are profound. This breach serves as a wake-up call for every canton and municipality across the Confederation. The transition to cloud-based collaboration tools like SharePoint offers efficiency, but it also creates a centralized target for global threat actors. Moving forward, the Swiss government must confront a difficult reality: the cost of defense is soaring, and the traditional Swiss value of discretion is being challenged by the need for radical transparency in cybersecurity. The FOITTâs decision to block external access is a temporary fix for a permanent problem. As the investigation continues, the focus will shift from 'how did this happen' to 'how do we ensure it never happens again.' The resilience of the Swiss digital infrastructure is being tested like never before, and the outcome of this battle will dictate the security of the nation's data for the next decade.