London, December 3, 2024 – The login credentials of nearly 600 employees accessing the British Ministry of Defence’s (MOD) Defence Gateway website have been discovered circulating on the dark web over the past four years, with 124 compromised credentials identified in 2024 alone.
The Defence Gateway is a non-classified portal used by MOD employees for various functions, including HR, email, collaboration, and training. The ongoing thefts have affected individuals accessing the site from multiple locations, including Iraq, Qatar, Cyprus, Europe, and the UK.
While it remains unclear if the stolen credentials have been used successfully, the MOD’s Defence Gateway reportedly employs multi-factor authentication (MFA), which serves as an additional security measure. This raises questions about the potential for deeper compromises and the methods used by attackers to obtain these credentials, with speculation pointing towards criminal entities possibly linked to Russian intelligence.
Concerns have been raised regarding the devices used by employees to access the portal, as many were personal rather than military-issued, increasing the risk of compromise through phishing attacks or infostealer malware. Cybersecurity experts have highlighted that even with MFA, determined attackers could still gain access if they are able to capture the necessary authentication codes.
Additionally, the exposure of these credentials could leave affected employees vulnerable to further attacks, as cybercriminals may seek to exploit personal information linked to the compromised accounts. With 600 stolen credentials identified over four years, experts note that even a small number of successful phishing attacks can achieve significant results.
Despite the alarming nature of these findings, they also indicate proactive security measures are in place, as the detection of such credential compromises suggests monitoring of dark web activities. However, the incident underscores the ongoing challenges posed by sophisticated cyberattacks, particularly in light of recent warnings from the UK’s National Cyber Security Center regarding extensive data harvesting efforts linked to Russian state-sponsored activities.