News: 1775896214

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Hungarian government creds left in the safe hands of 'FrankLampard'

(2026/04/11)


Hungary's government has discovered the hard way that the biggest threat to national security might just be its own password choices.

An investigation by [1]Bellingcat has uncovered close to 800 Hungarian government email and password pairings circulating in breach dumps, cutting across nearly every major ministry, from defense and foreign affairs to finance.

This doesn't look like anyone breaking in so much as people making it easy. Weak passwords, reused in places they shouldn't be, and eventually ending up where they always do.

[2]

The defense department data is worth examining on its own. Bellingcat puts the number at around 120 compromised records tied to defense staff, including fallout from a 2023 breach of NATO's eLearning platform that exposed emails, passwords, and phone numbers. Most of it traces back to a spike in 2021, but data keeps showing up into 2026, and some of the stealer logs suggest a few of those machines may have been genuinely infected, not just caught up in old leaks.

[3]

[4]

Then there are the passwords. A colonel working in "information security" used "FrankLampard," apparently deciding that a former England footballer was as good a guardian of state secrets as any. A district director had "123456aA," while another senior figure tied to Hungary's NATO delegation used a password that translates to "cute" in English.

There was more in the same vein. A brigadier general used a short nickname based on his own name to sign up for a film festival. Elsewhere, it's the usual mix of names, simple patterns, and things that look like they were typed once and never revisited.

[5]

One example highlighted in the report, "linkedinlinkedin," appears to have been swept up in the old LinkedIn data breach and then seemingly kept in service anyway, which is one way to stay consistent if nothing else.

[6]Every day in every way, passwords are getting worse and worse

[7]You probably can't trust your password manager if it's compromised

[8]Payroll pirates are conning help desks to steal workers' identities and redirect paychecks

[9]LastPass hammered with £1.2M fine for 2022 breach fiasco

According to the analysis, officials were using their government email addresses to sign up for all sorts of third-party services, then reusing the same passwords across them. Once those sites were breached, the credentials ended up in the usual places.

Bellingcat also found infostealer logs tied to dozens of machines, some from as recently as last month. That points to something more recent than old breach data doing the rounds, with signs that at least some devices may have been compromised more actively.

The Hungarian government has been given a stark warning. When credentials tied to core state functions end up bundled in breach collections alongside everyone else's compromised shopping and social media accounts, it raises uncomfortable questions about how seriously basic security hygiene is being taken.

None of this required sophisticated tooling or zero-days. Just a few bad passwords, a bit of reuse, and the internet doing what it does best: remembering everything. ®

Get our [10]Tech Resources



[1] https://www.bellingcat.com/news/2026/04/09/the-hungarian-government-passwords-exposed-online/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2adobv28XOs64Vu-YFb_S5QAAANE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44adobv28XOs64Vu-YFb_S5QAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33adobv28XOs64Vu-YFb_S5QAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44adobv28XOs64Vu-YFb_S5QAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2026/02/23/password_opinion/

[7] https://www.theregister.com/2026/02/16/password_managers/

[8] https://www.theregister.com/2026/02/11/payroll_pirates_business_social_engineering/

[9] https://www.theregister.com/2025/12/11/lastpass_ico_fine/

[10] https://whitepapers.theregister.com/



In the HU military their brass…

Bebu sa Ware

after buffing, is the brightest thing about them. Like everywhere I guess.

You prefer the company of the opposite sex, but are well liked by your own.