Nearly 800 email and password combinations tied to Hungarian government employees have been exposed online, raising serious concerns about national cybersecurity and the safeguarding of sensitive state information. The revelations, uncovered through an investigation by Bellingcat, paint a troubling picture of weak digital practices across key ministries, including those responsible for defence, foreign affairs and internal security.
The breach affects 12 out of Hungary’s 13 ministries, exposing credentials belonging to a wide range of personnel—from junior officials to senior figures tasked with protecting national security. Among those impacted are a high-ranking military officer responsible for information security, a counterterrorism coordinator within the foreign ministry, and a specialist assigned to identify hybrid threats against the country. The compromised data includes not only passwords but also personal information such as phone numbers, dates of birth and IP addresses, amplifying the potential risk.
The timing of the disclosure is politically sensitive. Hungarians are heading to the polls to determine whether Prime Minister Viktor Orbán will secure a fifth consecutive term. The findings add a new dimension to ongoing debates about governance, transparency and national security under his leadership.
According to Bellingcat’s analysis, the exposed credentials were not the result of sophisticated cyber espionage but rather poor digital hygiene. Many government employees reused simple or easily guessable passwords for non-work-related accounts, including entertainment, dating and shopping websites. Common examples included variations of “Password,” sequences like “1234567,” and even highly predictable personal references such as surnames or favorite football figures.
The scale of the problem is significant. Investigators identified 795 unique email-password combinations across multiple breach databases. Notably, 641 of these were linked to just four central institutions, underscoring concentrated vulnerabilities within critical arms of government. The analysis did not include agencies operating under separate domains, such as the police or tax authorities, suggesting that the true extent of exposure could be even greater.
Within the Ministry of Interior, which oversees areas ranging from healthcare to law enforcement, 170 compromised accounts were identified. Some employees used passwords as simple as “Arsenal” or “Paprika,” while others relied on strings of just a few characters. One senior prison official reportedly used the password “adolf,” later changing it to a numeric code and then a pet’s name—both of which were also subsequently breached.
The Ministry of Defence fared little better, with 120 compromised records identified. Among them were credentials linked to a 2023 breach of NATO’s eLearning platform. The data revealed a pattern of weak password choices among military personnel, including nicknames, common phrases and predictable combinations. One colonel specializing in information security used “FrankLampard” as a password, while another senior official opted for a term translating to “cute.”
The Ministry of Foreign Affairs and Trade, responsible for Hungary’s diplomatic network, saw 107 email-password combinations exposed. The breaches span more than a decade, with some occurring as recently as early 2026. Affected individuals include diplomats stationed across Europe, the Americas and the Middle East. Passwords ranged from personal names paired with numbers to pop culture references like “Batman2013” and “frogger,” highlighting a widespread disregard for basic cybersecurity protocols.
Similarly, the Ministry of National Economy recorded 99 breaches, with an additional 145 linked to the former Ministry of Finance before its merger in 2025. Among the compromised accounts was that of a deputy state secretary who used “snoopy” as a password. Other officials relied on birthdates or the Hungarian word “Jelszo,” meaning “password.” In one case, a senior advisor’s credentials were breached four times, each with a different password—including one containing explicit language.
Beyond weak passwords, the investigation uncovered evidence of malware infections within government systems. Data from breach databases revealed that at least 97 machines across various departments had been compromised by credential-stealing software, with some infections recorded as recently as the past month. This suggests that vulnerabilities are not only historical but ongoing.
The findings echo earlier concerns about Hungary’s cybersecurity posture. In 2022, reports emerged that Russian intelligence services had infiltrated the Hungarian foreign ministry’s computer networks, accessing internal communications and classified data. Although officials initially denied the breach, subsequent reporting in 2024 revealed a warning letter from Hungary’s National Security Service describing thousands of compromised workstations and servers as “unreliable” and linking the attacks to Russia.
Analysts see the latest revelations as part of a broader pattern. Szabolcs Dull, a political analyst and former editor-in-chief of prominent Hungarian news outlets, argued that the government has consistently failed to prioritize data security. He noted that the new findings reinforce earlier suspicions about systemic vulnerabilities and a lack of accountability following previous incidents.
Cybersecurity experts also point to structural shortcomings. Kata Kincső Bárdos, a Hungary-based specialist, emphasized that basic safeguards such as strong, unique passwords and multi-factor authentication are essential, particularly in environments handling sensitive information. Without such measures, she warned, even a single compromised credential can provide attackers with direct access to internal systems.
Bárdos highlighted that cyber attackers often exploit the weakest links within an organization, targeting lower-level employees through phishing or credential theft before moving laterally across networks. This tactic makes widespread poor password practices especially dangerous, as it allows relatively unsophisticated attacks to escalate into major security breaches.
Despite the gravity of the findings, Bellingcat reported that it received no response from the Hungarian government’s spokesperson or the Prime Minister’s office when contacted for comment. The silence raises further questions about how authorities intend to address the vulnerabilities and whether any corrective measures are underway.
As Hungary navigates a pivotal political moment, the exposure of hundreds of government credentials underscores a deeper issue: the intersection of governance and cybersecurity in an increasingly digital world. The leaks reveal not just isolated lapses but a systemic failure to enforce even the most basic security standards—one that could have far-reaching implications for national security, public trust and Hungary’s position on the global stage.

