Swiss federal IT office hit by cyberattack
Following a cyberattack on the SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), access via the internet has been blocked for people outside the federal administration.
Around 200 accounts were compromised in the incident. There are no indications of any further data breaches.
The unknown attackers are believed to have exploited vulnerabilities in Microsoft’s SharePoint software, the FOITT said on Tuesday. The software manufacturer had reported several such vulnerabilities in mid-July. The FOITT operated the servers in the federal government’s own data centres and, according to its own statements, had immediately begun installing the security updates provided. SharePoint is a web application used for collaboration and file storage.
During the course of their analysis, the experts discovered on July 31 that the login details for around 200 user and technical accounts had been compromised. According to its own statements, the FOITT immediately reset the relevant passwords. Based on the investigations to date, which are being supported by the National Cybersecurity Centre (NCSC) and Microsoft, there is no evidence of any further data leakage. However, the analysis is still ongoing.
The FOITT is currently reinstalling the affected SharePoint servers as a precautionary measure. Internet access for external users remains blocked until this work is completed. Federal administration staff can continue to access their documents and share them via alternative channels. According to the FOITT, no confidential information or particularly sensitive personal data may be stored on the SharePoint platform.
+ Almost one attack a day reported on critical Swiss infrastructures
The NCSC recorded 28 cyberattacks on the Federal Administration last year alone. A total of 325 attacks on critical infrastructure were reported last year. In around one in four reports, a public administration body – the Federal Administration or a cantonal or municipal administration – was affected.
The best-known case involved the federally owned defence contractor Ruag. In autumn 2025, the hacker group Akira attacked the IT systems of Ruag’s subsidiary LLC in the US state of Virginia. Data was stolen from the subsidiary’s systems. The attackers then threatened to publish the data on the dark web and demanded a ransom. Ruag eventually paid the blackmailers and had the data returned.
+ How we produce English news
Translated from German, reviewed by an English Department journalist.
In compliance with the JTI standards
More: SWI swissinfo.ch certified by the Journalism Trust Initiative
You can find an overview of ongoing debates with our journalists here . Please join us!
If you want to start a conversation about a topic raised in this article or want to report factual errors, email us at english@swissinfo.ch.