Sector study · scan of 9 September 2026
Stolen staff passwords are circulating for a third of UK councils
We looked at 379 council websites across England, Wales, Scotland and Northern Ireland the way any member of the public could: from the outside, without logging in anywhere, trying a password or touching anything inside a council’s systems. What we found are spare keys under the mat, not break-ins.
Second edition, 15 September 2026. The exposed-service and software-weakness findings were re-examined and corrected; no score or average changed.
122 / 501
councils with staff passwords circulating / records
2
councils running software with an actively exploited weakness
7
councils with a risky service on their own hosting, 3 of them databases
63
councils not forcing visitors onto a secure connection
Why this matters
A council is the organisation a resident cannot choose not to deal with. Council tax, housing, school places, benefits, parking and social care all leave personal information with an authority the resident has no realistic option to take elsewhere. A message that appears to come from a council also carries the weight of an institution with legal powers, so it gets acted on quickly.
Yet councils sit outside the main UK cyber security regulations, with no dedicated regulator. What exists is a self-assessment framework rather than a duty.
Most published figures on this come from surveys, such as the government’s Cyber Security Breaches Survey, or from audit work carried out inside government, such as the National Audit Office’s. Both rely on what organisations report about themselves. This study asked nobody anything. Every number is an observation taken from outside with the same checks on every website: what a sector is showing to the world, rather than what it believes about itself.
What needs attention
Staff passwords in criminal collections: 122 websites, 501 records. About four records on a typical affected council — wide, not deep. These are keys to the council’s own systems, and the council can take them back today.
63 councils do not force visitors onto a secure connection, so anything typed into those pages can be read or altered on the way. This is the largest concrete job in the report.
Two councils run software with a weakness criminals are known to be using now, listed in the public catalogue of weaknesses being exploited in the real world rather than merely recorded somewhere. One sits on an address registered to the council itself, on web server software past the end of its supported life. Both sit inside the 11 councils whose weaknesses were read from version numbers only, which may already be patched.
Seven councils have a service answering the internet that probably should not be, such as remote access, file transfer or an admin tool, on the council’s own hosting. Three of them are databases, and the three sit inside the seven.
The first edition of this report said seventeen and thirteen. When we re-read the same evidence to establish whose equipment was answering, ten turned out to be a hosting provider’s own machinery, replying on dozens of ports for every customer behind it, all ten in England. No score or average changed.
These rows overlap and must not be added together. Between them they involve fewer than 200 of the 379 websites, which makes the list finishable rather than sector-wide. Every item needs checking privately before it is treated as fact.
What is going well
Not one ransomware listing, breach record or browser-safety warning anywhere in 379 scans.
227 councils, six in ten, tell other mail systems to refuse email forged in their name, and only 17 have not started. 378 of 379 publish the record identifying their own mail servers. Councils have largely done this with no law requiring it.
Only five exact scores fall in the lowest band, and all five are in England.
Scores
All 379 websites completed a scan. 293 produced an exact score, averaging 75.6. Counting a further 57 floor scores at their floor gives 72.9 across 350 — the most cautious figure available. Use 75.6 for the sector’s measured position and 72.9 for the cautious one.
Some council websites answer an automated visitor with a protection page rather than the real homepage. That is a security control working, not a fault. Where that was the only gap, the score is a floor: the true figure can only be the same or higher, never lower. For 29 websites a second piece was also missing, so no score is published — but their findings still count in every figure on this page.
What this is not
It is not a claim that any council has been broken into: we could not see inside one and did not try. It is not an audit, a penetration test or a compliance judgement. It is not a league table, and it does not rank the four nations. No council is named.
Privacy
243 of the 305 homepages we could read showed no cookie consent mechanism. That is a reason to open the site in a browser and watch, not a finding: there are innocent explanations, and the regulator tests exactly the behaviour an outside scan cannot see.
Separately, 46,137 records across 358 websites belong to residents’ own accounts on council services, from residents’ own infected devices. Nobody at the council can reset those; only the resident can.
Where to start
- Deal with the two actively exploited weaknesses this week. Confirm the running version before anything else, and go to the council privately first; the one on a hosting provider’s address needs the provider brought in.
- Check the seven exposed services, three of them databases. Confirm who owns each address and whether the hosting is shared with other customers. Where nothing was identified on the flagged port, the first question is whether anything is listening.
- Reset the staff passwords — reset, end active sessions and confirm multi-factor sign-in. Never test a recovered password.
- Force every visitor onto a secure connection on the 63 councils that do not, and test for compatibility before switching it on.
- Finish the forged-email work, carefully. The 17 councils whose email policy is missing or monitoring-only should list every legitimate sender and watch before enforcing, never jumping straight to refusal.
The other ten exposure cases answer from a website-protection service or a shared platform address. Those ports belong to the provider’s equipment, so they are a question for the provider, not work for a council.
Read the full report
27 pages, written for people who do not work in cyber security.
Read the full report (PDF, 27 pages)Or check a domain against the same external checksAdvisory only. Every figure describes what was visible from outside on 9 September 2026, with the exposure evidence re-read on 15 September 2026, and is not certification, an audit, a penetration test, legal or regulatory advice, or a compliance assessment. Produced with MyDomainRisk by Huro Data Technologies Ltd, which has a commercial interest in this analysis and declares it so readers can weigh it.