Bottom line: Attackers compromised the SharePoint servers of the Swiss Federal Office of Information Technology, taking over hundreds of user accounts in the process.
The Swiss Federal Office of Information Technology, Systems and Telecommunication (FOITT) has fallen victim to a successful cyberattack on its SharePoint servers. The attackers succeeded in compromising hundreds of user accounts.
The incident became known on August 4, 2026. According to the report, attackers successfully attacked the SharePoint servers of the Federal Office of Information Technology, Systems and Telecommunication (FOITT), compromising hundreds of user accounts in the process. No further technical details on the vulnerability exploited or on the attacker group are available from the source so far.
The case is relevant for CISOs because FOITT, as the central IT service provider for the Swiss federal government, plays a critical role for government applications. A compromise in this environment can have knock-on effects beyond the compromised accounts on connected systems and data holdings, particularly where SharePoint serves as a central collaboration platform linked to other internal services.
SharePoint servers have for years been among attackers’ preferred targets, as they frequently consolidate sensitive documents, access rights and identity information. Organizations should take this incident as an opportunity to check their own SharePoint installations for up-to-date patches, review access logs for unusual authentication patterns, and verify the security of user accounts — for example through multi-factor authentication. Further information on the cause, scope and countermeasures of the FOITT incident is not yet available.
Source: borncity.com · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.