Russian-linked hackers target UK government email accounts in cyber campaign
A large-scale cyber campaign targeting Fortinet security devices has exposed login credentials linked to UK government bodies, diplomatic staff and critical infrastructure organisations. While there is no evidence that can attribute the breach to the Russian state, the warning is that the ongoing operation poses significant risks to public sector and essential services

A widespread cyber campaign has exposed login credentials belonging to UK government officials, overseas diplomatic staff and organisations responsible for critical national infrastructure, raising fresh concerns over the country's cyber defences as attackers continue to exploit vulnerable network security devices.
According to a report by The Telegraph, the operation, dubbed "FortiBleed" by researchers, has compromised tens of thousands of Fortinet firewalls worldwide. The attackers are said to have gained access by exploiting a security vulnerability and combining it with credentials obtained from previous data leaks, allowing them to bypass conventional security protections and access sensitive systems.
The incident is still active, according to cybersecurity researchers, with compromised devices reportedly being used to gather additional information that could facilitate further attacks. According to the report, security experts believe the campaign has affected more than 80,000 Fortinet firewalls, making it one of the largest ongoing credential-based cyber operations targeting enterprise networks.
Government and critical infrastructure accounts exposed
The Telegraph reported that the leaked credentials include email addresses and passwords associated with Foreign Office employees stationed overseas, local government officials and IT personnel working at British diplomatic missions, including embassies in Thailand and Mauritius.
The publication also reported that accounts linked to councils such as Derbyshire and Waltham Forest were among those exposed.
Beyond government organisations, login credentials connected to the NHS, energy companies and suppliers involved in the distribution of medicines have also reportedly appeared in the leaked dataset. Such organisations are considered particularly attractive targets because successful cyberattacks can quickly disrupt healthcare services and other essential public operations.
Researchers say the stolen credentials are being advertised on dark web marketplaces, with access reportedly offered for prices reaching as much as $60,000 (Rs 57.16 lakh). A threat actor operating under the alias "SantaAd" is said to be offering the data for sale, although attempts to obtain a response from a Telegram account believed to be linked to the individual were unsuccessful, according to the report.
The campaign was first identified by cybersecurity researcher Volodymyr Diachenko, who has been tracking the activity.
Authorities urge organisations to act immediately
In response to the ongoing threat, the UK's National Cyber Security Centre (NCSC) has issued an urgent advisory warning organisations about a "brute force" attack targeting Fortinet systems. The agency has instructed network administrators to review their infrastructure, identify compromised devices and isolate affected systems without delay to prevent additional unauthorised access.
While the attackers are believed to be operating from Russia, there is currently no evidence directly linking the campaign to the Russian government. Security experts have nevertheless noted that cybercriminal groups based in Russia have frequently been viewed as advancing Moscow's broader strategic interests, even when no formal state connection has been established.
The latest incident comes against the backdrop of growing concerns over cyber threats directed at British institutions. In May 2024, the head of GCHQ warned that Russia was increasingly encouraging hackers to target UK organisations.
The warning was followed by a major cyberattack in June 2024 against pathology services provider Synnovis, an incident widely believed to have been carried out by Russian-linked actors. That breach caused severe disruption across parts of the NHS, forcing the cancellation of more than 1,000 operations and around 2,000 medical appointments.
With the FortiBleed campaign continuing to evolve, cybersecurity officials are urging organisations using Fortinet products to treat the threat as an immediate priority and ensure compromised credentials can no longer be used to gain access to sensitive systems.

Samsung Galaxy Fold 8 Ultra, Fold 8, Flip 8 launched: Here is how much it costs in India with discounts
Florida pastor sues OpenAI, says ChatGPT's medical advice delayed emergency treatment: Report
US accuses China's Moonshot AI of using Anthropic's Fable to build K3 model
Apple's biggest Mac refresh in years could bring 11 new models: Report
Amazon lays off employees in its Artificial General Intelligence (AGI) division
