Site navigation

Thousands of Civil Servant Passwords Leaked Online

Elizabeth Greenberg

,

civil servant password leak
“Exposure of sensitive data, including passwords, of civil servants is particularly dangerous,” Karolis Arbačiauskas, head of product at NordPass, said.

Thousands of civil servants have had their passwords exposed on the dark web since the start of 2024, research from NordPass shows.

The security firm, using its threat exposure management platform NordStellar, discovered 3,014 passwords across the dark net that belonged to UK civil servants.

Aberdeen City Council was one of the UK authorities named in the report, with 538 passwords leaked from the council in total.

While the leaks may be of passwords for regional institutions, the report said that the number of leaked passwords may not be a reflection of an organisation’s internal security posture.

External factors, such as the size of an organisation and the reuse of passwords, could put these organisations at increasing risk despite their security posture.

“In many cases, a single malware infection on an employee’s personal device or the compromise of a popular third-party website can expose dozens of accounts. Furthermore, the majority of leaks originate from external sites where employees registered using their work email addresses,” Karolis Arbačiauskas, head of product at NordPass, said.

While the stats are concerning, they are not necessarily linked directly to faults in these institutions’ security measures.

“If these passwords were not changed after their appearance on the dark web and multi-factor authentication (MFA) is not enabled, attackers could potentially access the email accounts and other sensitive information of these civil servants,” Arbačiauskas said.

“Moreover, we found hundreds of thousands of email addresses with other exposed data like names, last names, phone numbers, autofills, and cookies. This data can be exploited for phishing attacks and pose significant risks.”


Recommended reading


Issuing basic security measures like multi-factor authentication and ensuring that workers do not reuse passwords for sensitive accounts can be essential in keeping these more at risk accounts secure.

“Exposure of sensitive data, including passwords, of civil servants is particularly dangerous,” Arbačiauskas said. “Compromised passwords can affect not only organisations and their employees but also large numbers of citizens. Moreover, such incidents may also pose serious risks to a country’s strategic interests.”

A spokesperson for the Aberdeen City Council told DIGIT: “Aberdeen City Council regularly reviews lists of compromised credentials via the National Cyber Security Centre and other official sources.

“These email/ password combinations are typically used to sign up on external sites or services rather than being compromised from the council’s tenant. Regardless of this all impacted account holders are contacted, and their passwords are reset as a matter of course.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data