An investigation by Bellingcat found nearly 800 Hungarian government email and password pairs circulating in breach dumps, affecting almost every major ministry, including defense, foreign affairs, and finance. The exposed credentials were largely tied to weak password practices, password reuse on third-party services, and data from earlier breaches rather than a single sophisticated intrusion. Reported examples of compromised passwords included trivial choices such as FrankLampard, 123456aA, and cute.
About 120 of the exposed records were linked to defense personnel, including credentials associated with a 2023 breach of NATO's eLearning platform. Bellingcat also identified infostealer logs from dozens of machines, with some evidence as recent as last month, indicating that at least some systems may have been actively compromised more recently. The leaked credential data reportedly continued to surface through 2026, highlighting persistent security hygiene failures in sensitive Hungarian government functions.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Bellingcat found nearly 800 Hungarian government email and password pairs circulating in breach dumps, affecting ministries including defense, foreign affairs, and finance. The investigation highlighted weak passwords, password reuse, and continued credential exposure into 2026.
Bellingcat identified infostealer logs from dozens of machines associated with Hungarian government users, indicating some systems may have been actively compromised. Some of these logs were described as appearing as recently as the month before the April 2026 reporting.
A 2023 breach of NATO's eLearning platform contributed to the exposure of some Hungarian government credentials, including records tied to defense personnel. Reporting later linked part of roughly 120 compromised defense-related records to this incident.
Leaked credential data involving Hungarian government email accounts surged in 2021, reflecting widespread password reuse on third-party services rather than a single centralized intrusion. The exposed records ultimately affected nearly 800 email-password pairs across major ministries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.