Russian-linked hackers have been targeting UK government email accounts in a cyber campaign that has exposed login credentials for government officials, diplomatic staff, and critical national infrastructure organizations. This operation, dubbed "FortiBleed" by researchers, has compromised tens of thousands of Fortinet firewalls worldwide, with attackers exploiting a security vulnerability and combining it with credentials from previous data leaks to bypass conventional security protections. The incident is still active, with compromised devices being used to gather additional information that could facilitate further attacks. Security experts believe the campaign has affected more than 80,000 Fortinet firewalls, making it one of the largest ongoing credential-based cyber operations targeting enterprise networks.
The leaked credentials include email addresses and passwords associated with Foreign Office employees, local government officials, and IT personnel working at British diplomatic missions, including embassies in Thailand and Mauritius. Accounts linked to councils such as Derbyshire and Waltham Forest were also exposed, as well as those connected to the NHS, energy companies, and medicine suppliers. Such organizations are considered particularly attractive targets because successful cyberattacks can quickly disrupt healthcare services and other essential public operations.
The stolen credentials are being advertised on dark web marketplaces, with access reportedly offered for prices reaching as much as $60,000. A threat actor operating under the alias "SantaAd" is said to be offering the data for sale, although attempts to obtain a response from a Telegram account believed to be linked to the individual were unsuccessful.
In response to the ongoing threat, the UK's National Cyber Security Centre (NCSC) has issued an urgent advisory warning organizations about a "brute force" attack targeting Fortinet systems. The agency has instructed network administrators to review their infrastructure, identify compromised devices, and isolate affected systems without delay to prevent additional unauthorized access.
While the attackers are believed to be operating from Russia, there is currently no evidence directly linking the campaign to the Russian government. However, security experts have noted that cybercriminal groups based in Russia have frequently been viewed as advancing Moscow's broader strategic interests, even when no formal state connection has been established.
This incident comes against the backdrop of growing concerns over cyber threats directed at British institutions. In May 2024, the head of GCHQ warned that Russia was increasingly encouraging hackers to target UK organizations. The warning was followed by a major cyberattack in June 2024 against pathology services provider Synnovis, an incident widely believed to have been carried out by Russian-linked actors. That breach caused severe disruption across parts of the NHS, forcing the cancellation of more than 1,000 operations and around 2,000 medical appointments.
With the FortiBleed campaign continuing to evolve, cybersecurity officials are urging organizations using Fortinet products to treat the threat as an immediate priority and ensure compromised credentials can no longer be used to gain access to sensitive systems. This incident highlights the ongoing challenges faced by the UK in defending against sophisticated cyber threats and the need for continuous vigilance and proactive security measures.