Lyce · Hybrid Watch

hw_ee66711ac84871cd

Russian state-linked hackers fully compromise Hungary’s Foreign Ministry networks.

In the spring of 2022 investigative reporting revealed that Russian intelligence services (including actors tied to the Federal Security Service (FSB) and Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU)) had gained persistent and deep access to Hungary’s Foreign Ministry computer networks, including the secure “VKH” encrypted diplomatic network. According to former internal officials, by the second half of 2021 the attackers had compromised the MFA’s internal correspondence systems and had also infiltrated the encrypted channels used for classified diplomatic communication. The breach reportedly allowed Russian actors to monitor Hungarian diplomatic deliberations, strategy toward EU/NATO policy, and even sensitive communications with allied states. The MFA’s internal security cables (obtained by the investigative outlet) show that ministry staff were unaware for long periods that their systems had been infected, and standard devices and credentials had been silently leveraged by the intruders. The incident highlights the geographic dimension (Budapest/missions abroad) and typology (cyber intrusion enabling espionage), as well as the dynamics: long-term infiltration, low-visibility compromise, and exploitation of government networks rather than immediate destruction or overt kinetic strike.

Occurrence
2022-03-29
Publication
2022-03-28T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
HU
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2022-03-28T22:00:00Z

    In the spring of 2022 investigative reporting revealed that Russian intelligence services (including actors tied to the Federal Security Service (FSB) and Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU)) had gained persistent and deep access to Hungary’s Foreign Ministry computer networks, including the secure “VKH” encrypted diplomatic network. According to former internal officials, by the second half of 2021 the attackers had compromised the MFA’s internal correspondence systems and had also infiltrated the encrypted channels used for classified diplomatic communication. The breach reportedly allowed Russian actors to monitor Hungarian diplomatic deliberations, strategy toward EU/NATO policy, and even sensitive communications with allied states. The MFA’s internal security cables (obtained by the investigative outlet) show that ministry staff were unaware for long periods that their systems had been infected, and standard devices and credentials had been silently leveraged by the intruders. The incident highlights the geographic dimension (Budapest/missions abroad) and typology (cyber intrusion enabling espionage), as well as the dynamics: long-term infiltration, low-visibility compromise, and exploitation of government networks rather than immediate destruction or overt kinetic strike.