A major scandal regarding the cybersecurity of state structures is unfolding in the United Kingdom. Russian hackers have managed to gain unauthorized access to the email accounts of British officials and employees of the Foreign and Commonwealth Office (FCO). According to experts, the attack was made possible by exploiting a critical vulnerability in Fortinet firewalls, which allowed the attackers to bypass the security systems protecting the country's critical infrastructure.

Scale of Data Compromise

The breach affected more than 80,000 devices using Fortinet equipment. The attackers, utilizing previously stolen data, gained access to the internal networks of the UK Foreign Office. Among the compromised accounts were those of embassy staff in Thailand and Mauritius, as well as officials from the Derbyshire and Waltham Forest regions in east London.

The situation is exacerbated by the fact that the stolen logins and passwords are already being sold on darknet forums. The price for access to this data reaches $60,000 (approximately £44,000). Access to the stolen resources is being offered by a user with the nickname «SantaAd».

Threat to Healthcare and Energy

Particularly alarming is the fact that among the stolen data are keys to the National Health Service (NHS) systems, energy companies, and pharmaceutical suppliers. Cybersecurity expert and former NHS doctor Saif Abed warned that the leak could lead to a «catastrophic» incident directly threatening patient safety.

«This is exactly the type of attack that becomes the first step towards large-scale ransomware attacks», Abed explained. Experts are drawing parallels with the incident in June 2024, when hackers, likely linked to Russia, breached the pathology laboratory system Synnovis. As a result of that attack, more than 1,000 operations and 2,000 doctor appointments were cancelled.

Technical Details and Government Response

Cybersecurity researcher Vladimir Dyachenko, who first discovered the security gap, reported that hackers gained access to the «core networks» of the Foreign Office. According to him, the attack has the potential to spread to other agencies. An analysis of the code used for the attack showed that it was written in Russian.

The UK's National Cyber Security Centre (NCSC) officially confirmed the «brute force» attack on Fortinet systems. The agency issued an emergency warning, ordering organizations to immediately check their networks and isolate compromised devices.

Geopolitical Context

Although there is currently no direct evidence of the Russian state's involvement in this specific attack, the UK believes that the Kremlin is deliberately turning a blind eye to the activities of hackers operating from Russian territory, using them as a tool for global destabilization.

This incident fits into the broader picture of the escalation of cyber conflict. Recently, the Google Threat Intelligence Group discovered a new spyware .NET backdoor called STOCKSTAY, which hackers from the Turla group are deploying against military and government institutions in Ukraine and European diplomatic bodies. It was also previously reported that the Security Service of Ukraine, together with the FBI, exposed Russian intelligence services for systematic attempts to hack the messengers of officials in Ukraine, Europe, and the US.