Back News.Liga Russian hackers attacked British government officials—the accounts were sold for $60,000
Russian hackers carried out a large-scale cyberattack, as a result of which they gained access to the email accounts of British government officials and employees of the UK Foreign Office. This was reported by , , The Telegraph., and
Why This Is Important. Russian intelligence agents and saboteurs are also actively operating within European Union institutions. For years, Russia has been conducting propaganda campaigns in Europe, posing security threats and attempting to undermine support for Ukraine. For details on the methods used by Russian agents and their recruitment efforts in Brussels— —follow the links: .
According to the publication, the attackers exploited a vulnerability in more than 80,000 Fortinet firewalls. Using previously stolen login credentials, they were able to bypass the security systems protecting the country’s critical infrastructure.
Among the compromised accounts were those of staff at British diplomatic missions in Thailand and Mauritius, as well as officials from local government bodies in Derbyshire and the Walham Forest area of London.
The stolen usernames and passwords have already appeared for sale on dark web forums. According to journalists, the price for access to certain accounts can reach $60,000.
In addition to government agencies, the breach also affected systems belonging to the UK's National Health Service (NHS), energy companies, and pharmaceutical suppliers.
Cybersecurity expert Saif Abed warned that such an incident could have serious consequences for the functioning of the healthcare system and patient safety. According to him, such attacks are often the first stage of large-scale ransomware campaigns.
The publication notes that in 2024, following a cyberattack on the Synnovis laboratory—which was also linked to Russian hackers—the United Kingdom had to cancel more than 1,000 surgeries and 2,000 medical appointments.
Cybersecurity researcher Volodymyr Dyachenko, who discovered the breach, stated that the attackers may have gained access to key networks of the Ministry of Foreign Affairs, and that the scale of the attack potentially poses a threat to other government agencies as well.
According to The Telegraph, an analysis of the program code indicates that it was written in Russian, and a user going by the pseudonym SantaAd is selling the stolen data.
The UK’s National Cyber Security Center (NCSC) has confirmed a brute-force attack against Fortinet systems. The agency has recommended that organizations check their networks, identify compromised devices, and isolate them.
Despite the lack of direct evidence of the Russian government’s involvement in the incident, the British side believes that Moscow effectively condones the activities of cybercriminals operating from Russian territory, using them as a tool to carry out information and cyberattacks.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
