Russian Hackers Breach UK Government and Foreign Ministry Emails, Data Sold on Darknet
Russian hackers infiltrated email accounts of British government officials and Foreign Office staff posted overseas, according to a Telegraph report cited by multiple outlets; confirmed compromised accounts include IT staff at UK embassies in Thailand and Mauritius and local authority employees in Derbyshire and Waltham Forest
Credentials spanning NHS hubs, energy suppliers, and medicine distributors sit alongside embassy and municipal logins in a single dark web listing, collapsing the line between government espionage exposure and critical-infrastructure ransomware risk. Diachenko's finding that hackers continue converting compromised Fortinet devices into internal collection points means the exposure window has not closed, pressuring NHS and energy operators to rotate credentials and audit access logs before further harvesting occurs. Russian-language code ties the toolset to Russian-speaking operators without establishing Kremlin direction, shaping whether London treats this as criminal extortion or state-tolerated proxy activity; the operation may instead be opportunistic criminal exploitation of a known Fortinet flaw monetized through a named broker rather than coordinated espionage. Low confidence attaches to any state-affiliation characterization, reflecting a single Telegraph investigation republished without independent corroboration by Meduza, United24 Media, and anews.
4 sources
- Russian hackers have infiltrated the email accounts of British government officials and overseas Foreign Office staff in a major national security breach -
The Telegraph - Russian Hackers Breach UK Government Data, Trading It for Up to $60,000 on the Dark Web -
United24 Media - Russian hackers steal log-ins from British officials - report -
anews - Russian hackers breach UK government official and diplomat emails, sell data on darknet -
Meduza