Overview
- BIT detected unusual activity on its SharePoint servers on July 28 and on July 31 confirmed attackers had accessed data in about 200 user and technical accounts.
- In response BIT blocked external internet access to the SharePoint instance, applied Microsoft patches, reset affected passwords and is reinstalling compromised servers while offering alternative document‑sharing methods.
- Investigators suspect one of the SharePoint flaws fixed in mid‑July was used, with reporting naming CVE-2026-56164 as a privilege escalation bug and CVE-2026-50522 as a critical remote‑code‑execution flaw that can steal machine keys.
- BIT says it has found no evidence so far of data theft beyond the stolen login credentials, that sensitive personal data are not allowed on the affected platform, and that no group has claimed responsibility or leaked data publicly.
- Stolen credentials can be reused to move laterally into other systems, so BIT shared technical indicators with essential‑infrastructure operators and reported the incident to the Swiss cyber office and security authorities as the joint investigation continues.