Swiss Federal IT Agency Compromised 200 SharePoint Accounts via Suspected Vulnerabilities
What Happened — The Federal Office for Information Technology and Communications (BIT) in Switzerland disclosed that roughly 200 user and technical accounts on its on‑premises SharePoint servers were compromised. The breach is believed to stem from several critical SharePoint vulnerabilities disclosed in July’s Patch Tuesday, which were later listed in CISA’s Known Exploited Vulnerabilities catalog.
Why It Matters for Compliance & Audit Readiness
- Credential compromise directly tests the effectiveness of SOC 2 CC6.1 (Logical Access) controls and the organization’s ability to detect and respond to unauthorized access.
- Exploited software flaws highlight the need for continuous patch‑management evidence and key‑rotation procedures—key audit artifacts for demonstrating a robust security posture.
- The incident underscores the importance of maintaining a defensible audit trail (evidence of detection, containment, and remediation) to satisfy SOC 2 auditors and regulators.
Who Is Affected — Federal and public‑sector IT agencies, as well as any organization running on‑premises SharePoint servers.
Recommended Actions
- Map the incident to SOC 2 access‑control criteria (CC6.1, CC6.2) and document the detection, containment, and remediation steps as audit evidence.
- Verify that all SharePoint patches are applied, rotate IIS machine keys, and restart services per CISA guidance; retain logs of these actions.
- Strengthen credential‑management policies: enforce MFA, conduct regular credential‑rotation, and monitor for anomalous logins. Source: The Record
Technical Notes — The attackers likely leveraged multiple SharePoint CVEs (e.g., CVE‑2024‑xxxx) that allowed extraction of IIS machine keys, enabling forged session tokens even after patching. No data beyond the compromised credentials has been confirmed as accessed. Source: The Record