3,000 Government Passwords Hacked in Security Fiasco But Ministers Still Expect Citizens to Hand Over Their Private Details
The government's push for mandatory digital ID becomes increasingly questionable as new research from tech company Nordpass reveals over 3,000 UK public sector passwords have been exposed in 2024-25 alone. The scale is staggering:
- Ministry of Justice: 195 (total breaches)
- Ministry of Defence: 111
- Department for Work and Pensions: 122
- HM Revenue and Customs: 63
- Home Office: 62
- UK Parliament: 70
This comes as MI5 Director General Ken McCallum warns of unprecedented cyber threats from China, Russia and Iran, reporting a 35% increase in state threat investigations and "more volume and more variety of threat than I've ever seen". The timing couldn't be worse: the government announced plans for a mandatory digital ID scheme requiring all UK workers to prove their right to work through a centralised digital system.
Security experts are calling the scheme "a catastrophe in waiting," particularly concerning given that the government's existing One Login system lost its Digital Identity and Attributes Trust Framework certification this year. A whistleblower revealed the system lacks basic governance and risk management, with development outsourced to Romania without cybersecurity consultation.
The government's own track record is damning. The Cabinet Office warned of serious data protection issues in November 2022, and the National Cyber Security Centre identified significant shortcomings in September 2023. Yet ministers are attempting to race ahead with a that will centralise the personal data of every working person in Britain.
The petition protesting against Digital ID cards is approaching 3,000,000.
We'd like your views:
- How can the government justify centralising citizen data when it cannot secure existing systems?
- Is pushing ahead with digital ID while under unprecedented cyber attack a strategic blunder?
- What happens to national security when hostile states can access centralised identity databases?
- Should mandatory digital ID be delayed until government cybersecurity fundamentals are addressed?
- Are we creating the exact "bigger, shinier target" that security experts warn against?
Sources:
- NordPass Password Security Research 2025: https://nordpass.com/public-sector-passwords-leak/
- MI5 Annual Threat Assessment, October 2024: https://www.mi5.gov.uk/news/director-general-speech-2024
- UK Government Digital ID Announcement: https://www.gov.uk/government/news/new-digital-id-scheme-to-be-rolled-out-across-uk
- Do not introduce Digital ID cards:
https://petition.parliament.uk/petitions/730194


