Over 500 Aberdeen City Council employee passwords have been exposed in a cybersecurity incident affecting local authorities across Britain.
Aberdeen City Council has been identified as the worst-affected local authority in a major cybersecurity breach that has seen more than 3,000 passwords belonging to British civil servants leaked onto the dark web since the beginning of 2024.
According to a report by password management firm NordPass, using threat exposure management platform NordStellar, Aberdeen City Council recorded 538 total password exposures – significantly higher than any other local authority examined. The leak included 23 unique passwords associated with the council’s aberdeencity.gov.uk email domain.
The disclosure comes as cybersecurity experts warn of a “particularly dangerous” threat to public institutions and national security, with the exposed data potentially enabling phishing attacks and unauthorized access to sensitive systems.
Aberdeen City Council employs approximately 8,000 staff across 166 sites throughout the city, providing essential services including education, social care, housing, and community safety. The council has invested heavily in digital transformation in recent years, implementing its “Being Digital” strategy to modernize core IT infrastructure and improve online services.
Widespread Government Exposure
The NordPass research, which monitored passwords from public sector institutions across six countries, found that four UK local authorities were among the most affected organisations.
Beyond local government, several national departments were significantly impacted. The Ministry of Justice emerged as the most targeted UK government body, with 195 exposed passwords, followed by the Department of Work and Pensions with 122 leaked credentials, and the Ministry of Defence with 111 compromised passwords.
“Exposure of sensitive data, including passwords, of civil servants is particularly dangerous,” said Karolis Arbačiauskas, head of product at NordPass. “Compromised passwords can affect not only organisations and their employees but also large numbers of citizens. Moreover, such incidents may also pose serious risks to a country’s strategic interests.”
The Mechanics of Password Exposure
Cybersecurity experts emphasise that the scale of password exposure does not necessarily reflect an organisation’s internal security measures. Many leaks originate from external sources where employees have registered using their work email addresses, rather than from direct breaches of government systems.
“These figures are often influenced by external factors,” Arbačiauskas explained. “Larger organisations, with more employees, naturally have a bigger digital footprint, which statistically increases the likelihood of credentials being exposed in a breach. In many cases, a single malware infection on an employee’s personal device or the compromise of a popular third-party website can expose dozens of accounts.”
Vakaris Noreika, head of product at NordStellar, warned that even a single active compromised account could provide hackers with “a direct attack vector” to sensitive government systems. “Moreover, we found hundreds of thousands of email addresses with other exposed data like names, last names, phone numbers, autofills, and cookies,” he said. “This data can be exploited for phishing attacks and pose significant risks.”
Rising Threat Landscape.
Scotland’s 32 local authorities are currently in the process of implementing enhanced cybersecurity measures, with procurement body Scotland Excel launching a £13 million framework in early 2025 for a shared security operations centre solution. The initiative, developed in cooperation with the Digital Office for Scottish Local Government, aims to provide 24/7 monitoring and rapid response to security incidents.
Recommended Protections
Cybersecurity professionals stress that organizations must implement comprehensive password policies to mitigate the risks posed by credential exposure. Key recommendations include establishing organization-wide password policies, avoiding password reuse across multiple accounts, and enabling multi-factor authentication (MFA) on all systems.
“If these passwords were not changed after their appearance on the dark web and multi-factor authentication (MFA) is not enabled, attackers could potentially access the email accounts and other sensitive information of these civil servants,” Arbačiauskas warned.
Research indicates that MFA can prevent up to 99.2% of account compromise attacks, making it one of the most effective defences against unauthoriaed access. The technology requires users to verify their identity through multiple factors—typically a password combined with a code sent to a registered device or a biometric identifier.
Aberdeen City Council has previously demonstrated commitment to IT security improvements, having launched investigations into past cybersecurity incidents. In 2017, the council’s website was temporarily hijacked by hackers, prompting a review of security systems.
The National Cyber Security Centre recommends that individuals and organizations regularly monitor for compromised credentials, change passwords immediately upon notification of a breach, and implement password managers to generate and securely store complex, unique passwords for each account.