Info Gov

Login credentials belonging to staff at UK councils, the NHS, HMRC and other government bodies have been exposed as part of a large-scale cyber campaign attributed to Russian hackers.

According to a report in the Telegraph newspaper, a list of compromised accounts it had seen included credentials belonging to local government officials, the NHC and even IT staff at British embassies in Thailand and Mauritius.

It also reported that compromised credentials are being offered for sale on dark web forums for as much as $60,000 (£44,000) and said the breach also affected overseas Foreign Office staff, NHS organisations and other critical infrastructure.

Multiple industries - including government services - around the world fell victim to the attacks, according to an investigation by cyber security firm SOCRadar.

The National Cyber Security Centre (NCSC) has since warned organisations using Fortinet firewalls and VPN gateways to carry out checks on their devices and factory reset any devices they believe have been compromised.

Describing the attack, the national cyber watchdog said the programmes had been targeted as part of a global campaign, with some indications of potential impact in the UK.

It added: "A database of credentials has been leaked by a threat actor following brute-force, dictionary and credential stuffing attempts against internet-facing FortiGate and VPN portals.

"Credential stuffing is a method where attackers use passwords stolen from one web service to try to access accounts on other services, taking advantage of any reuse of username and password combinations."

The NCSC recommended UK organisations using Fortinet edge devices with SSL VPN enabled to investigate potentially malicious activity on the device and monitor their network for unusual activity.

It has set out a nine step-approach on its website: https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways.

Also in this section

Aug 12, 2026

ACRO Criminal Records Office reprimanded by ICO following cyber security failings

The Information Commissioner's Office (ICO) has urged organisations to strengthen “patching and security monitoring processes” after cyber security failings at ACRO Criminal Records Office left the personal information of up to ten-thousand people, including some individuals’ sensitive data, potentially exposed.
Aug 05, 2026

Third AI platform goes rogue during cyber testing

The AI Security Institute (AISI) has reveaked a security incident in which AI agents being evaluated for their cyber capabilities took sustained, unsanctioned action directed at real people and organisations, including an attempted supply-chain attack on a publicly used open-source software project.
Jul 30, 2026

New NCSC guidance sets out three-stage framework for cyber attack recovery

The National Cyber Security Centre (NCSC) has published new guidance setting out a three-stage framework to help organisations respond to and recover from highly disruptive cyber attacks, warning that recovery from the most serious incidents can take weeks or months and that victims must plan for consequences extending well beyond their technology estate.

InfoGov Masthead Newsletter 800