Security Stop-Press: UK Government’s One Login Vulnerable to Undetected Attacks

Written by Pronetic

Pronetic is a leading provider of core IT support for ISO 27001, Cyber Essentials and Cyber Essentials Plus compliance.

May 21, 2025

A government-commissioned red teaming exercise has found that One Login, the UK’s flagship digital identity platform, can be compromised without triggering any alerts.

The test, carried out by the National Cyber Security Centre’s Cross-Government Red Team, revealed serious gaps in the system’s ability to detect and respond to intrusions. One Login is intended to provide a single, secure sign-in for services like tax, pensions and benefits.

Over 2 million users are already enrolled, but the findings raise concerns about whether the platform is safe for wider rollout. A Cabinet Office spokesperson said the exercise was “routine best practice” and confirmed improvements are being made, but offered no technical details.

Experts say silent compromise of a national identity system could expose millions to fraud, data theft or service disruption, especially if undetected for long periods.

Although this was a simulated attack and no real data was exposed, the key concern is that One Login failed to detect the breach, showing a weakness in spotting intrusions. For businesses, the lesson is that detection matters as much as prevention. Regular testing and active monitoring are vital to catch threats before they cause damage.

You May Also Like…

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Why Choose Pronetic

We Are ISO 27001 & Cyber Essentials Plus Certified

Be reassured that we have been externally audited. You can have complete peace of mind that the team managing your IT systems and safeguarding your data are independently vetted annually.

Seamless & Comprehensive IT Support

Our investment in people, tools and processes, continuously improved, ensures that we don’t just deliver exceptional I.T. support but include your compliance to Cyber Essentials or ISO 27001 “baked-in”. Yes, that means no more annual headaches and stress when your certification comes round.

Expert Support Money Back Guarantee

We're confident in the value we deliver. That's why we offer a 90-day, no-quibble money-back guarantee. If, for any reason, you're not completely satisfied with our IT support services, we'll provide a full refund and cancel your contract without any hassle.

Book Your Free IT Strategy Call Now!

Simply Fill In The Form Below To Receive Your Free IT Strategy Call:

By submitting this form, you consent to us using your personal information to contact you. For more information please see our privacy policy.