← All articles

Warlock SharePoint Attacks: Swiss KRITIS Alert 2026

A China-linked ransomware gang's SharePoint exploitation spree against critical infrastructure puts Swiss water, telecom and government operators on notice.

A China-linked ransomware group known as Warlock has exploited vulnerabilities in Microsoft SharePoint to breach a water utility, a telecom operator, a regional government body and a university, according to reporting published this week S1. The campaign confirms that SharePoint remains a favoured initial-access vector for ransomware operators targeting critical infrastructure and public-sector networks, and it places Swiss operators running equivalent collaboration platforms squarely within the same exposure window.

Why Warlock's Target List Should Concern Swiss Operators

Warlock's choice of victims is not incidental. Water utilities, telecom providers, regional government bodies and universities share a common profile: they run large, often decentralised SharePoint deployments, they hold operationally sensitive data, and patching cycles in these sectors are frequently slower than in commercial enterprises due to legacy integrations and limited IT staffing S1. Switzerland's own critical infrastructure landscape mirrors this profile almost exactly, with cantonal utilities, telecom carriers, cantonal and federal administrative bodies, and academic institutions all operating comparable collaboration infrastructure, often inherited from years of incremental IT expansion rather than designed with a unified security architecture.

The attribution to a China-linked actor matters for risk modelling. Unlike opportunistic criminal ransomware crews, state-linked groups tend to combine financially motivated encryption operations with longer dwell times and broader data exfiltration, meaning a breach is rarely a single-stage event. For Swiss KRITIS operators, this raises the stakes beyond ransom payment decisions: any SharePoint compromise by this group should be treated as a potential espionage and data-theft incident as well as a disruption threat, warranting forensic scope well beyond the encrypted systems themselves. Incident responders should assume that document repositories, authentication tokens and connected directories were accessed long before encryption was triggered, and that visible disruption may be the final stage of a much longer intrusion.

The breadth of sectors hit in a single campaign also signals that Warlock is not narrowly specialised but opportunistically scanning for exposed SharePoint instances across multiple verticals simultaneously. This matters for Swiss risk assessment because it suggests the group's targeting logic is driven by exploitable infrastructure rather than sector-specific intent, meaning any Swiss institution with an internet-facing, unpatched SharePoint deployment could be swept into a future wave regardless of its perceived strategic value to a state-linked actor.

SharePoint as a Persistent Entry Point

The exploitation pattern described in this campaign is not a novel technique; it is the continuation of a well-documented trend in which SharePoint vulnerabilities serve as a reliable initial-access route for ransomware actors S1. Collaboration platforms are attractive precisely because they sit at the intersection of internet-facing exposure and deep internal trust: a compromised SharePoint instance often provides direct pivot points into document repositories, identity systems and connected line-of-business applications. Once inside, attackers can move laterally using credentials harvested from the platform itself, often without triggering alerts designed for traditional network intrusion patterns.

For Swiss financial-sector CISOs whose organisations also operate SharePoint for internal collaboration or as a gateway to partner institutions in water, telecom or government supply chains, the lesson is that third-party and interconnected exposure matters as much as direct ownership. A ransomware incident at a telecom provider or government body can cascade into financial institutions that depend on those services for connectivity, authentication or regulatory reporting, meaning sector boundaries offer limited protection against this specific attack pattern. Supply-chain risk assessments that treat telecom and government partners as low-risk because they fall outside the financial sector's direct regulatory perimeter are no longer defensible given this campaign's demonstrated reach.

It is also worth noting that the repeated reuse of SharePoint as an attack vector across multiple unrelated campaigns suggests that patch management alone, while necessary, is insufficient as a standalone defence. Configuration hardening, network segmentation isolating SharePoint servers from sensitive internal systems, and continuous monitoring of authentication anomalies on these platforms must accompany any patching programme, since vulnerability windows between disclosure and exploitation have narrowed to the point where patching speed alone cannot be relied upon as the sole control.

Closing the Gap Before Exploitation Becomes Encryption

The time between a SharePoint vulnerability becoming known and its exploitation by ransomware groups has consistently narrowed across recent campaigns, and Warlock's activity against water, telecom, government and university targets reinforces that compressed timeline S1. Swiss organisations that treat SharePoint patching as routine IT maintenance rather than a critical-infrastructure security control are misjudging the threat; the sectors already hit in this campaign are functionally identical to Swiss KRITIS categories, and the exploit chain does not discriminate by jurisdiction. Operators who assume geographic distance from the reported victims provides any meaningful protection are relying on a false sense of security that this campaign directly contradicts.

Boards and compliance officers overseeing Swiss utilities, telecom carriers, cantonal bodies and universities should expect this incident to surface in regulatory and audit conversations, given the direct sectoral overlap with confirmed victims. The practical response is not reactive cleanup after an incident but proactive verification that internet-facing SharePoint instances are patched, monitored and segmented before an opportunistic or targeted actor finds the same entry point documented in this campaign. Swiss financial institutions with upstream dependencies on these sectors should treat this as a prompt to review their own third-party risk assumptions rather than wait for a direct hit, particularly where outsourced IT or shared service arrangements extend SharePoint exposure beyond an institution's own direct control.

Ultimately, the Warlock campaign is a reminder that ransomware operators continue to find the highest return on effort not through sophisticated zero-day development but through the exploitation of widely deployed, often under-maintained collaboration platforms. Swiss institutions in water, telecom, government and academic sectors, along with the financial entities that depend on them, should treat this disclosure as confirmation that their own SharePoint environments warrant immediate, verified scrutiny rather than scheduled, routine review.

◆ Key Takeaway

Audit every internet-facing SharePoint instance in your environment today for unpatched vulnerabilities and unusual authentication activity, since Warlock has demonstrated this exact exploit path against water, telecom, government and university targets.

  • Inventory all SharePoint deployments, including those managed by subsidiaries, cantonal partners or outsourced IT providers, and confirm patch levels against known exploited vulnerabilities.
  • Restrict internet-facing exposure of SharePoint instances wherever business requirements allow, moving authentication behind stronger access controls and multi-factor enforcement.
  • Monitor SharePoint and connected identity systems for anomalous file access, privilege escalation, or data exfiltration patterns consistent with ransomware pre-encryption activity.
  • Review incident response plans to explicitly cover scenarios where ransomware is paired with data theft by a state-linked actor rather than treated as a pure encryption event.
  • Assess third-party and supply-chain dependencies on water, telecom and government service providers that may be in scope for this campaign and request evidence of their patching posture.
  • Brief boards and compliance teams on the direct sectoral overlap between Warlock's confirmed victims and Swiss critical-infrastructure categories so that resourcing decisions reflect the actual threat.
  • Establish or test offline backup and recovery procedures specifically against SharePoint-originated compromise scenarios, including recovery of authentication and directory services.