惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

有赞技术团队
有赞技术团队
H
Hackread – Cybersecurity News, Data Breaches, AI and More
I
InfoQ
J
Java Code Geeks
Microsoft Security Blog
Microsoft Security Blog
G
Google Developers Blog
D
DataBreaches.Net
Recent Announcements
Recent Announcements
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
Y
Y Combinator Blog
博客园 - 【当耐特】
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
量子位
C
Check Point Blog
F
Fortinet All Blogs
罗磊的独立博客
Last Week in AI
Last Week in AI
GbyAI
GbyAI
L
LangChain Blog
博客园 - 司徒正美

The Register - Security

Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw ShinyHunters claims dump puts 119K Vimeo emails in the wild
Hungary officials used weak passwords exposed in breach dump
2026-04-11 · via The Register - Security

Security

Hungarian government creds left in the safe hands of 'FrankLampard'

Nearly 800 state logins surfaced in breach data, including defense and NATO-linked accounts

Hungary's government has discovered the hard way that the biggest threat to national security might just be its own password choices.

An investigation by Bellingcat has uncovered close to 800 Hungarian government email and password pairings circulating in breach dumps, cutting across nearly every major ministry, from defense and foreign affairs to finance.

This doesn't look like anyone breaking in so much as people making it easy. Weak passwords, reused in places they shouldn't be, and eventually ending up where they always do.

REG AD

The defense department data is worth examining on its own. Bellingcat puts the number at around 120 compromised records tied to defense staff, including fallout from a 2023 breach of NATO's eLearning platform that exposed emails, passwords, and phone numbers. Most of it traces back to a spike in 2021, but data keeps showing up into 2026, and some of the stealer logs suggest a few of those machines may have been genuinely infected, not just caught up in old leaks.

REG AD

Then there are the passwords. A colonel working in "information security" used "FrankLampard," apparently deciding that a former England footballer was as good a guardian of state secrets as any. A district director had "123456aA," while another senior figure tied to Hungary's NATO delegation used a password that translates to "cute" in English.

There was more in the same vein. A brigadier general used a short nickname based on his own name to sign up for a film festival. Elsewhere, it's the usual mix of names, simple patterns, and things that look like they were typed once and never revisited.

One example highlighted in the report, "linkedinlinkedin," appears to have been swept up in the old LinkedIn data breach and then seemingly kept in service anyway, which is one way to stay consistent if nothing else.

According to the analysis, officials were using their government email addresses to sign up for all sorts of third-party services, then reusing the same passwords across them. Once those sites were breached, the credentials ended up in the usual places.

Bellingcat also found infostealer logs tied to dozens of machines, some from as recently as last month. That points to something more recent than old breach data doing the rounds, with signs that at least some devices may have been compromised more actively.

The Hungarian government has been given a stark warning. When credentials tied to core state functions end up bundled in breach collections alongside everyone else's compromised shopping and social media accounts, it raises uncomfortable questions about how seriously basic security hygiene is being taken.

None of this required sophisticated tooling or zero-days. Just a few bad passwords, a bit of reuse, and the internet doing what it does best: remembering everything. ®