Hundreds of Hungarian government credentials were found circulating in breach databases, exposing 795 unique email-password pairs tied to 12 of Hungary’s 13 ministries and personnel in sensitive defence, foreign affairs, interior, and economic roles. Bellingcat reported that the pattern pointed less to a single sophisticated state intrusion than to chronic security failures, including weak and reused passwords, use of official email accounts on non-work services, and signs of credential-stealing malware on 97 machines. The findings added to earlier warnings about Hungary’s cyber posture, including prior reporting that Russian intelligence had compromised the foreign ministry and an official letter describing thousands of workstations and hundreds of servers as unreliable.
In Germany, Julia Klöckner was reported by Der Spiegel to have been caught up in the recent Signal phishing campaign targeting political figures in Berlin’s government district. The incidents together underscored how senior officials remain vulnerable to basic account compromise techniques, from password reuse and infostealer infections to phishing against secure messaging platforms, increasing the risk of unauthorized access to sensitive government communications and systems.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Bellingcat found 795 unique Hungarian government email and password combinations circulating in breach databases, affecting 12 of Hungary's 13 ministries and personnel in sensitive roles across defence, foreign affairs, interior, and economic institutions. The exposed credentials included weak and reused passwords and government email use on non-work services.
Bellingcat reported evidence of credential-stealing malware infections on 97 machines tied to Hungarian government personnel. The finding supported the conclusion that exposed credentials were likely driven by poor cyber hygiene rather than a single sophisticated intrusion.
In a later letter, Hungary's National Security Service linked the attacks on government systems to Russia and described more than 4,000 workstations and 930 servers as "unreliable." This indicated a broader compromise or loss of trust in government IT infrastructure.
Earlier reporting cited by Bellingcat said Russian intelligence had compromised Hungary's foreign ministry, marking a major prior cybersecurity incident affecting the government. The exact date is not specified in the reference.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.