Thousands of civil servants have had their passwords exposed on the dark web since the start of 2024, research from NordPass shows.
The security firm, using its threat exposure management platform NordStellar, discovered 3,014 passwords across the dark net that belonged to UK civil servants.
Aberdeen City Council was one of the UK authorities named in the report, with 538 passwords leaked from the council in total.
While the leaks may be of passwords for regional institutions, the report said that the number of leaked passwords may not be a reflection of an organisation’s internal security posture.
External factors, such as the size of an organisation and the reuse of passwords, could put these organisations at increasing risk despite their security posture.
“In many cases, a single malware infection on an employee’s personal device or the compromise of a popular third-party website can expose dozens of accounts. Furthermore, the majority of leaks originate from external sites where employees registered using their work email addresses,” Karolis Arbačiauskas, head of product at NordPass, said.
While the stats are concerning, they are not necessarily linked directly to faults in these institutions’ security measures.
“If these passwords were not changed after their appearance on the dark web and multi-factor authentication (MFA) is not enabled, attackers could potentially access the email accounts and other sensitive information of these civil servants,” Arbačiauskas said.
“Moreover, we found hundreds of thousands of email addresses with other exposed data like names, last names, phone numbers, autofills, and cookies. This data can be exploited for phishing attacks and pose significant risks.”
Recommended reading
- Report: Half of All Enterprise Passwords Vulnerable to Cracking
- UK Gov Cyber Breaches Survey 2024 | Key Stats and Data
- Report: Cyber Breaches Are Tanking Share Prices
Issuing basic security measures like multi-factor authentication and ensuring that workers do not reuse passwords for sensitive accounts can be essential in keeping these more at risk accounts secure.
“Exposure of sensitive data, including passwords, of civil servants is particularly dangerous,” Arbačiauskas said. “Compromised passwords can affect not only organisations and their employees but also large numbers of citizens. Moreover, such incidents may also pose serious risks to a country’s strategic interests.”
A spokesperson for the Aberdeen City Council told DIGIT: “Aberdeen City Council regularly reviews lists of compromised credentials via the National Cyber Security Centre and other official sources.
“These email/ password combinations are typically used to sign up on external sites or services rather than being compromised from the council’s tenant. Regardless of this all impacted account holders are contacted, and their passwords are reset as a matter of course.”





