More than 700 email addresses and corresponding passwords linked to nine UK government domains have been leaked on the dark web over the past year, according to a report by cybersecurity firm NordStellar. The breach has raised fears that sensitive taxpayer data or critical infrastructure such as power grids could be targeted by hackers.
The Ministry of Justice was the most affected, with 195 passwords leaked, followed by the Department for Work and Pensions (122) and the Ministry of Defence (111). Other departments including the Home Office, Foreign Office, Department for Transport, UK Parliament, Department of Health and Social Care, and HM Revenue & Customs also had login details exposed.
Vakaris Noreika, head of product at NordStellar, said it was unclear whether the leaked details had been used to access sensitive resources but warned of a “growing danger” of major data leaks. He noted that compromised passwords could allow hackers to access police records, citizen databases, or infrastructure networks like power grids and water supplies.
Dr Gareth Mott, a cybersecurity fellow at the Royal United Services Institute, compared the potential impact to the 2022 Ministry of Defence data breach involving Afghan resettlement applicants, calling it “the Afghan lists on steroids”. He stressed that even one active account could serve as an initial attack vector for motivated external actors.
The leak follows a string of cyber attacks on UK institutions, including a breach at the Legal Aid Agency in April and a phishing attack on HMRC that stole £47 million from 100,000 accounts. The National Cyber Security Centre recently warned of a record number of serious attacks, partly driven by Chinese and Russian hackers.



