Advertisement

Russian-linked hackers target UK government email accounts in cyber campaign

A large-scale cyber campaign targeting Fortinet security devices has exposed login credentials linked to UK government bodies, diplomatic staff and critical infrastructure organisations. While there is no evidence that can attribute the breach to the Russian state, the warning is that the ongoing operation poses significant risks to public sector and essential services

Advertisement
AI-generated representational photo.
AI-generated representational photo.
FP Tech Desk|Jul 06, 2026, 14:59:30 IST

A widespread cyber campaign has exposed login credentials belonging to UK government officials, overseas diplomatic staff and organisations responsible for critical national infrastructure, raising fresh concerns over the country's cyber defences as attackers continue to exploit vulnerable network security devices.

According to a report by The Telegraph, the operation, dubbed "FortiBleed" by researchers, has compromised tens of thousands of Fortinet firewalls worldwide. The attackers are said to have gained access by exploiting a security vulnerability and combining it with credentials obtained from previous data leaks, allowing them to bypass conventional security protections and access sensitive systems.

Advertisement

The incident is still active, according to cybersecurity researchers, with compromised devices reportedly being used to gather additional information that could facilitate further attacks. According to the report, security experts believe the campaign has affected more than 80,000 Fortinet firewalls, making it one of the largest ongoing credential-based cyber operations targeting enterprise networks.

techMore from Tech

Government and critical infrastructure accounts exposed

The Telegraph reported that the leaked credentials include email addresses and passwords associated with Foreign Office employees stationed overseas, local government officials and IT personnel working at British diplomatic missions, including embassies in Thailand and Mauritius.

The publication also reported that accounts linked to councils such as Derbyshire and Waltham Forest were among those exposed.

Advertisement

Beyond government organisations, login credentials connected to the NHS, energy companies and suppliers involved in the distribution of medicines have also reportedly appeared in the leaked dataset. Such organisations are considered particularly attractive targets because successful cyberattacks can quickly disrupt healthcare services and other essential public operations.

Researchers say the stolen credentials are being advertised on dark web marketplaces, with access reportedly offered for prices reaching as much as $60,000 (Rs 57.16 lakh). A threat actor operating under the alias "SantaAd" is said to be offering the data for sale, although attempts to obtain a response from a Telegram account believed to be linked to the individual were unsuccessful, according to the report.

The campaign was first identified by cybersecurity researcher Volodymyr Diachenko, who has been tracking the activity.

Authorities urge organisations to act immediately

In response to the ongoing threat, the UK's National Cyber Security Centre (NCSC) has issued an urgent advisory warning organisations about a "brute force" attack targeting Fortinet systems. The agency has instructed network administrators to review their infrastructure, identify compromised devices and isolate affected systems without delay to prevent additional unauthorised access.

While the attackers are believed to be operating from Russia, there is currently no evidence directly linking the campaign to the Russian government. Security experts have nevertheless noted that cybercriminal groups based in Russia have frequently been viewed as advancing Moscow's broader strategic interests, even when no formal state connection has been established.

Advertisement

The latest incident comes against the backdrop of growing concerns over cyber threats directed at British institutions. In May 2024, the head of GCHQ warned that Russia was increasingly encouraging hackers to target UK organisations.

The warning was followed by a major cyberattack in June 2024 against pathology services provider Synnovis, an incident widely believed to have been carried out by Russian-linked actors. That breach caused severe disruption across parts of the NHS, forcing the cancellation of more than 1,000 operations and around 2,000 medical appointments.

With the FortiBleed campaign continuing to evolve, cybersecurity officials are urging organisations using Fortinet products to treat the threat as an immediate priority and ensure compromised credentials can no longer be used to gain access to sensitive systems.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Jul 06, 2026, 14:59:30 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next