The UK is facing renewed scrutiny over the security of its government and defence systems following two separate incidents involving the exposure of sensitive information, according to reports by The Telegraph and The Sun.
In the most recent physical security lapse, highly sensitive unredacted British Army documents were discovered at a recycling site in northern England, The Sun reported. The files were linked to Catterick Garrison, the British Army’s largest base, and were reportedly found in a recycling bin at Catterick Bridge by a member of the public before being handed to journalists.
According to the report, the documents contained soldiers’ names and ranks, guard duty shift patterns, weapons storage information, incident reports and internal security procedures. The material was not anonymised or shredded, raising concerns that sensitive operational data had been improperly disposed of in public waste.
The Sun reported that Colonel Philip Ingram, a former senior British Army intelligence and security officer, described the incident as a clear security failure. He said such material should have been destroyed securely and warned that its exposure indicated a lack of procedural care in handling classified defence information.
The discovery comes amid broader concerns about UK military readiness and resource constraints, including maintenance delays affecting the Royal Navy’s Astute-class nuclear-powered attack submarines, all of which are reportedly currently in port due to a backlog. The report also references recent political tensions over defence funding, including the resignation of former Defence Secretary John Healey following disputes over budget allocations.
Separately, The Telegraph reported an ongoing cyber intrusion involving Russian-linked hackers who have infiltrated UK government email systems and compromised credentials belonging to officials across multiple departments, including the Foreign Office and local authorities.
The cyberattack, described by researchers as “FortiBleed,” is linked to vulnerabilities in Fortinet firewall systems used widely across government and infrastructure networks. According to The Telegraph, more than 80,000 firewalls were affected, with attackers exploiting stolen credentials to bypass security protections and gain access to sensitive systems.
The breach reportedly includes login details and passwords for staff at British embassies overseas, as well as local government offices in the UK. The compromised data is believed to be circulating on dark web marketplaces, with some access credentials reportedly offered for sale at prices reaching tens of thousands of dollars.
Cybersecurity experts cited in the report warned that the stolen credentials could enable deeper infiltration into government systems and critical infrastructure, including healthcare and energy networks. Concerns have also been raised about potential risks to the National Health Service, with experts suggesting that similar intrusion patterns have previously preceded ransomware attacks affecting patient care and hospital operations.
The UK’s National Cyber Security Centre (NCSC) has issued an alert confirming a “brute force” attack on Fortinet systems and urged organisations to update passwords, audit networks and isolate compromised devices. The agency also recommended enrolling in its Early Warning service to detect malicious activity at an earlier stage.
While there is currently no confirmed evidence of direct state involvement, The Telegraph noted that Russian-linked hacker groups have previously been associated with cyber operations targeting Western infrastructure, and UK intelligence officials have warned of growing connections between state interests and proxy cyber actors.

