惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
IT之家
IT之家
Microsoft Security Blog
Microsoft Security Blog
博客园 - 司徒正美
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
D
DataBreaches.Net
B
Blog RSS Feed
博客园_首页
The GitHub Blog
The GitHub Blog
I
InfoQ
L
LangChain Blog
G
Google Developers Blog
M
MIT News - Artificial intelligence
美团技术团队
腾讯CDC
V
Visual Studio Blog
aimingoo的专栏
aimingoo的专栏
博客园 - 聂微东
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Apple Machine Learning Research
Apple Machine Learning Research
A
About on SuperTechFans
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗

The Register - On-Prem

Ohio hits pause on datacenter tax breaks draining its coffers Europe told to cool its datacenter boom before water and power run short Kyndryl takes employees' pulse while cutting off circulation for some Outlook has an image problem Microsoft says cu l8r to text message security 'Workforce rebalancing' comes for Kyndryl, and delivery teams are in the firing line MAGA's Mace wants to make power bills great again, calls for datacenter moratorium Datacenters slurping up so much juice they boosted prices 75% in largest US energy market Exploited Exchange Server flaw turns OWA inboxes into script launchpads Utah mega datacenter could dump 23 atomic bombs worth of energy per day Rust stalks IBM mainframes, but only in nightly form Iran war hits datacenter building supply chains, upping costs ON CALL: Custom PC worked in the lab, failed on site – and so did the angry client ShinyHunters claims dump puts 119K Vimeo emails in the wild Vodafone dials up full control of VodafoneThree Palantir CEO: 10 percent of world 'professionally hates us' Bad news for OpenClaw stans: Apple’s Mac Mini starts at $799 AWS networking lab tour: Making networking disappear Royal Navy chief backs drones, robot ships Bank of England is gold standard for tech projects, says PAC UK pensions dept shopping for spy-van tech worth up to £2M Microsoft boss tells investors the company is working to 'win back fans' What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Microsoft levels up Azure Local for sovereign clouds Cloudflare: autocrats, wars, and votes caged the net in Q1 ZTE & XLSMART launch Jakarta AI & 5G-A Innovation Center When robots join the race: 5G-A powers a new kind of marathon 5G-A powers a new kind of marathon Oracle plans to power its New Mexico DC with fuel cell farm DCMS to new CDIO: Microsoft migration, overhaul ERP, survive
Hungary officials used weak passwords exposed in breach dump
2026-04-11 · via The Register - On-Prem

Security

Hungarian government creds left in the safe hands of 'FrankLampard'

Nearly 800 state logins surfaced in breach data, including defense and NATO-linked accounts

Hungary's government has discovered the hard way that the biggest threat to national security might just be its own password choices.

An investigation by Bellingcat has uncovered close to 800 Hungarian government email and password pairings circulating in breach dumps, cutting across nearly every major ministry, from defense and foreign affairs to finance.

This doesn't look like anyone breaking in so much as people making it easy. Weak passwords, reused in places they shouldn't be, and eventually ending up where they always do.

REG AD

The defense department data is worth examining on its own. Bellingcat puts the number at around 120 compromised records tied to defense staff, including fallout from a 2023 breach of NATO's eLearning platform that exposed emails, passwords, and phone numbers. Most of it traces back to a spike in 2021, but data keeps showing up into 2026, and some of the stealer logs suggest a few of those machines may have been genuinely infected, not just caught up in old leaks.

REG AD

Then there are the passwords. A colonel working in "information security" used "FrankLampard," apparently deciding that a former England footballer was as good a guardian of state secrets as any. A district director had "123456aA," while another senior figure tied to Hungary's NATO delegation used a password that translates to "cute" in English.

There was more in the same vein. A brigadier general used a short nickname based on his own name to sign up for a film festival. Elsewhere, it's the usual mix of names, simple patterns, and things that look like they were typed once and never revisited.

One example highlighted in the report, "linkedinlinkedin," appears to have been swept up in the old LinkedIn data breach and then seemingly kept in service anyway, which is one way to stay consistent if nothing else.

According to the analysis, officials were using their government email addresses to sign up for all sorts of third-party services, then reusing the same passwords across them. Once those sites were breached, the credentials ended up in the usual places.

Bellingcat also found infostealer logs tied to dozens of machines, some from as recently as last month. That points to something more recent than old breach data doing the rounds, with signs that at least some devices may have been compromised more actively.

The Hungarian government has been given a stark warning. When credentials tied to core state functions end up bundled in breach collections alongside everyone else's compromised shopping and social media accounts, it raises uncomfortable questions about how seriously basic security hygiene is being taken.

None of this required sophisticated tooling or zero-days. Just a few bad passwords, a bit of reuse, and the internet doing what it does best: remembering everything. ®