< Back to all clusters
[CRIME] · United Kingdom · 14 sources

started · updated

Russian hackers use FortiBleed to breach UK government and maritime networks

More than 80,000 Fortinet firewalls were compromised in the “FortiBleed” breach, exposing over 86,000 administrator credentials across 194 countries. In the United Kingdom, credentials belonging to Foreign Office staff, local‑government officials and IT personnel at British embassies (Thailand, Mauritius, Derbyshire, Waltham Forest) were stolen, giving attackers access to email accounts and internal systems. The leaked log‑ins – including those for the NHS, energy providers and pharmaceutical suppliers – are being offered on dark‑web forums for up to $60,000 (£44,000).

The incident also threatens the maritime sector: Cydome identified 703 satellite‑linked IP addresses linked to ship‑owner and ship‑management companies, with 41.5% of the leaked log‑ins belonging to shipping and freight firms. The exposure could allow attackers to move through networks unnoticed, control operational systems or sell access to ransomware groups.

UK authorities, including the National Cyber Security Centre, have issued urgent alerts, urging password resets, multi‑factor authentication and removal of internet‑facing management interfaces. The U.S. Cybersecurity and Infrastructure Security Agency has issued similar guidance. No definitive state involvement has been proven, but the scale of the breach raises concerns about potential ransomware attacks on critical services such as hospitals and energy grids.

Sources

3 months ago
3 months ago
3 months ago