Part I — Situation overview

The Hungarian State Treasury issued a statement on 11 August about the break-in affecting its systems. According to the statement “on the basis of the present information the attack did not affect client or citizen data, and no data loss occurred”, while the attacker obtained privileges in the IT network of the National Paying Agency — the agricultural and rural development professional area — and was unable to attack other areas successfully. The Treasury reported the matter to the police, is carrying out the damage response jointly with the National Cyber Defence Institute of the National Security Special Service, and reported the case to the data protection authority. Népszava, however, wrote that the attackers may also have obtained privileges leading to pension assessment and disbursement data, to municipalities’ account data and to population registers. The two claims stand side by side in the public sphere, and neither can be verified from outside.

According to press reports the course of the intrusion is textbook. The attackers exploited a known but unpatched software vulnerability on a web server, then obtained the master administrator keys of the central access control system, and deep in the network encrypted outdated databases protected by weak passwords. According to the analysis of the cyber defence company Yellow Cube, however, it was not the protective controls that failed but the response: after the attacker shut down the endpoint protection system, for five and a half days the alerts “arrived in an empty room”. The same analysis also refutes the mass data exfiltration: moving the quantity of data in question would have required sustained bandwidth of several gigabits, which is physically unfeasible within the time window of the intrusion. The public leak was an “evidence package” of some 70 megabytes, with an express remark that no ransom is being demanded. The list of re-used passwords speaks for itself: in the collection presented by 24.hu, of the 468 passwords examined 225 were simple name–date of birth combinations, alongside them Jelszó123, abcd1234 and similar patterns. The group to which the attack can be linked previously also attacked Romania’s land registry database.

On MIAK’s reading the main lesson of the case is not technological but institutional. As early as 2019 the State Audit Office warned about the risks of the IT network taken over from the pension insurance directorate; part of the critical software is developed and maintained by an external partner; and password usage shows that an enforced policy is missing. All this together means that the organisation was unable to say about itself what had happened to it — and this also translates outwards to the public: behind the sentence “no citizen data affected” there is no evidence that the citizen concerned could check. At a paying institution, provability is not an ancillary matter of convenience but the very condition of trust.

Part II — Literature foundation

The interpretative frame of the case is composed of three complementary sources. The EU’s NIS2 Directive (Directive 2022/2555 on network and information security) makes not technical protection but reporting discipline the backbone of the system: an early warning within 24 hours, an incident notification with the initial assessment within 72 hours, a final report with the root cause and the mitigating measures within one month — that is, the organisation has to not only defend itself but also account for itself. Article 33 of the General Data Protection Regulation (GDPR) carries the same logic through towards data subjects: a personal data breach has to be notified to the supervisory authority within 72 hours, and if this does not happen, the delay has to be separately justified; and recital 85 of the regulation lists item by item the harms — identity theft, financial loss, damage to reputation — against which rapid notification protects. In her volume The Age of Surveillance Capitalism the American social psychologist Shoshana Zuboff writes of an “unprecedented asymmetry” of knowledge and power: where one party knows everything about the other, while the other knows nothing about what is known of them, the distribution of knowledge itself becomes a question of power — and this description holds for state data assets just as much as for private ones. The detailed treatment of the literature — source by source, with quotations — can be found in the 6.4 Literature in detail section.

📖 Source: Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2); Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation); Shoshana Zuboff: The Age of Surveillance Capitalism

Part III — MIAK’s concrete proposal

MIAK proposes three measurable measures which together fill the gap that is most visible in the case: it is not protection that is missing in itself, but provability.

3.1 Compulsory multi-factor login and an enforced password policy in state critical systems (120 days)

MIAK proposes that the government prescribe, with a deadline of one hundred and twenty days, multi-factor authentication (login in two steps: alongside a password a second, device-bound proof) for every state critical system — with priority for payment, register and access control systems — as well as a technically enforced password policy which from the outset does not allow weak or previously leaked passwords to be saved. The requirement should also extend to external suppliers accessing the systems, as a contractual condition. After the expiry of the deadline compliance should be checked by the cybersecurity authority in a sampling audit, and the compliance rate published broken down by organisation. The proposal follows from programme point D5 on cybersecurity strategy, which prescribes a minimum standard for municipal and central systems alike, and is consistent with the NIS2 system of management responsibility (see 6.4.1).

3.2 An independent, public post-incident review report after every serious state incident (90 days)

In aviation safety it has been the established model for decades that an accident is investigated not by the operator but by a body organisationally separate from it, that the report is public, and that the establishment of liability is the subject of a separate procedure. MIAK proposes that after every serious cyber incident affecting a state critical system such a report be produced within ninety days, with compulsory content elements: the chronology of the attack, the exploited vulnerability and the date on which it became known, detection and response times, the data sets that became accessible, and a log-based demonstration of which data sets can and which cannot be asserted to be intact. This last is the essence: reassurance of the “no citizen data affected” type is a claim only if there is log evidence behind it; otherwise it is hope. The report should also include the delimitation of operator and supplier responsibility. The proposal builds on programme points D5 and A6, and its legal model is the NIS2 final reporting obligation — MIAK’s proposal goes further in that it also prescribes the publicity of the report.

3.3 A payment-continuity contingency plan for pension and family support benefits (from the first quarter of 2027, exercised annually)

The gravest real risk of the attack was not data theft but the paralysing of payments. MIAK proposes that from the first quarter of 2027 there be a documented contingency procedure laid down in law for the case in which the central payment system becomes unavailable for several days: a segregated, regularly refreshed copy of entitlements that can also be restored offline, an agreed banking data-carrier format for disbursement, and a legal rule under which, in the event of a system outage, the last assessed amount can be disbursed automatically, with reconciliation taking place afterwards. The plan has to be tried out annually in a live exercise, and the result of the exercise — the recovery time — published. The logic of the KI10 proactive state service programme point applies here in reverse: if the state can assess a benefit automatically, then it must also be able to keep disbursing it automatically when its system is damaged.

The common principle of the three proposals is provability. In cybersecurity protection will never be complete — the question is whether the organisation notices the break-in, whether it can say what happened, and whether it can operate even when its system is damaged. The Zuboffian asymmetry (see 6.4.3) closes shut precisely where these three capabilities are missing: the state knows a great deal about the citizen, while the citizen knows nothing about what happened to the data concerning them.

Part IV — Expected effects and risks

Dimension Expected effect Risk
Public administration The enforced login rule eliminates the entry route that goes with simple passwords; responsibility becomes clear between operator and supplier In the short term introduction causes administrative disruption and a significant support burden, especially for older users or those who log in rarely
Society The public post-incident review reduces guesswork and panic, and prepares citizens for targeted phishing A detailed technical report may unintentionally provide an attack pattern; publication therefore has a narrow, justified band of delay
Budget The one-off investment need of the contingency plan and the audit is small compared with the damage caused by a payment outage of several days The outlay is politically “invisible”: it prevents an event which, if it works well, never occurs
Supplier market The contractual security requirement filters out unprepared providers and improves the maintenance discipline of state systems The field of competitors may narrow, which can raise prices and increase dependence on a few large providers

The most important trade-off runs between transparency and defence. A detailed, public incident report may indeed contain information usable against other systems — MIAK’s proposal therefore asks not for unlimited publicity but for compulsory content elements, and, where justified, a pre-fixed delay of at most a few months. The second trade-off is between speed and precision: the 24-hour early warning by its nature gives an uncertain picture and has to be corrected later. This is not a fault but the system’s mode of operation — and precisely for that reason the reporting cascade has to be carried through to the final report, because the first statement will almost certainly be inaccurate. The present case shows this well: the tension between the claims “no data affected” and “they also accessed the pension system” is exactly the uncertainty that a final report has to resolve.

Part V — Measurability and summary

5.1 What is worth tracking? (proposed KPIs)

MIAK proposes four performance indicators (KPIs) for tracking:

  • Average detection time in state critical systems — instead of the five-and-a-half-day “blind” period of the present case it is worth setting detection within 24 hours as a target by 2028, according to the indicator contained in programme point D5.
  • Coverage of multi-factor login in critical systems — proposed target: 100% in the audit following the deadline of proposal 3.1, published broken down by organisation.
  • Compliance rate with the 24- and 72-hour notification deadlines — proposed target: above 90%, in an annual aggregate, in the report of the cybersecurity authority.
  • Log reconstruction rate — the proportion of accesses that can be traced back from logs after an incident. It is this indicator that tells us how far it can be asserted with proof that a data set was not compromised; proposed target: above 95%.

5.2 Summary

MIAK’s request is concrete: let the government make multi-factor login compulsory in state critical systems within one hundred and twenty days, and in the Treasury matter let the independent post-incident review report be completed and published within ninety days — in the form in which it distinguishes provably intact data sets from merely presumed intact ones. From the public MIAK asks that the case be read not from the person or nationality of the attacker but from the organisational response: the alert ignored for five and a half days says more about the state of Hungarian public IT than any technical detail.

In this matter two of MIAK’s foundational values move. Transparency, because in a cybersecurity matter publicity is not a luxury: in the case of a paying institution those concerned can protect themselves from the next step — targeted phishing — only if they know what data of theirs may have come into unauthorised hands. And data-drivenness, because a claim of the “no data affected” type is either based on log evidence or it is not a claim but a hope; the difference is measurable, and MIAK’s proposals make precisely this difference visible.


Part VI — Justifications and further sources

6.1 The press framing by spectrum

The economic band foregrounded the institutional and contractual background. Taking over Népszava’s information, Portfolio highlighted the exposure of municipal account management and the several hundred billion in balances, as well as the detail that the State Audit Office had warned as early as 2019 about the risks of the network taken over from the pension insurance systems, and that part of the critical software is maintained by an external partner. This framing points towards the chain of responsibility.

The public affairs and left-liberal band took the story in two complementary directions. 24.hu placed organisational culture at the centre, first by giving voice to a cybersecurity expert, then with an analysis presenting password usage, which made the case tangible at the level of everyday omissions. Telex placed the official Treasury response at the centre of its headline, that is, the question whether citizen data was accessed. HVG brought the wider technological context, with articles on the vulnerability of mobile network identity cards and on the machine detection of attacks.

The conservative band did not bring the topic into focus on this day — the front pages of Magyar Nemzet and Mandiner were occupied by the day’s public-law dispute and the election of the President of the Republic. This absence is in itself a signal: the operability of a paying institution is not a party-political question, yet it found a place only in those bands that write about institutional operation anyway. According to MIAK this is precisely the subject area to which the whole spectrum should apply the same yardstick — under the next government too.

6.2 Facts and data

Datum Value Source
Duration for which the alerts went unnoticed 5.5 days (after the shutdown of endpoint protection) Yellow Cube analysis, 24.hu, 10 August 2026
Size of the public leak approx. 70 MB “evidence package”, without a ransom demand Yellow Cube analysis, 24.hu
The alleged total volume of data 229.1 TB — within the time window it would have required sustained bandwidth of 7.5 Gbps, and can therefore be ruled out Yellow Cube analysis, 24.hu
Share of weak passwords in the sample examined 225 of 468 passwords were name + date of birth combinations Yellow Cube analysis, 24.hu
Earlier warning by the State Audit Office 2019 (data protection risks of the network taken over from the pension insurance directorate) Népszava, Portfolio, 11 August 2026
Method of the intrusion a known, unpatched software vulnerability on a web server, then obtaining the master administrator keys of the central access control system Népszava, Portfolio
Notification deadlines under NIS2 24 hours (early warning) / 72 hours (incident notification) / 1 month (final report) EU Directive 2022/2555, Article 23
Notification deadline under the GDPR 72 hours to the supervisory authority EU Regulation 2016/679, Article 33

Of the data, the most important is the relation between the first and the last. The NIS2 reporting cascade presumes that the organisation knows about the significant event within 24 hours. In an operation where alerts reach nobody for five and a half days, this deadline is conceptually unsustainable — not because reporting is slow, but because the starting point, becoming aware, slips. This connection is what justifies proposal 3.1 extending beyond login control to monitoring operation as well.

6.3 Policy dimensions

  • Digitalisation and AI regulation (programme points) — the cybersecurity strategy (programme point ID: D5) provides the direct basis for proposals 3.1 and 3.2, including the requirement of a national security monitoring centre, a compulsory annual audit and half-yearly exercises; data governance (programme point ID: D18) regulates the access regime for data handled in the public sector;
  • Public administration and e-government (programme points) — the integration logic of one-stop digital administration (programme point ID: KI1) requires strong authentication precisely because a single login opens several systems; the proactive state service (programme point ID: KI10) provides the theoretical background of the 3.3 continuity proposal;
  • Social policy (background material) — an outage in the pension and family support payment chains affects the most vulnerable households fastest, and therefore the continuity plan is also a social policy question;
  • Transparency and anti-corruption policy (programme points) — the strengthening of checks and balances (programme point ID: A6) provides the principle of publicly measuring institutional performance, which proposal 3.2 extends to incident handling.

6.4 Literature in detail

6.4.1 The EU’s NIS2 Directive

The core of the structure of Directive 2022/2555 is not the technological prescription but reporting discipline. Article 23 of the directive prescribes a three-stage cascade for essential and important entities: “without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning”, thereafter within 72 hours an incident notification with the initial assessment of the incident, its severity and impact, and finally, no later than one month, a final report containing a detailed description of the incident, the type of root cause and the mitigation measures applied. The preamble of the directive separately stipulates that the notification obligation should not divert resources from incident handling itself — that is, the legislator deliberately designed the system so that the rapid, imprecise first signal can be refined later.

Measured against this frame, the Treasury case is interesting at two points. On the one hand, the closing stage of the triple cascade — the detailed final report with the root cause — is exactly the document that MIAK’s proposal 3.2 would make public; today the directive prescribes it for the authority, not for the public. On the other hand, the cascade as a whole starts from the moment of becoming aware: where the alerting chain is broken, the statutory deadlines may even be formally met while in substance nothing has happened. This gap between formal compliance and actual security is one of the most important, rarely measured risks of Hungarian public administration.

📖 Source: Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2)

6.4.2 The General Data Protection Regulation

Under Article 33 of the GDPR the controller notifies a personal data breach to the competent supervisory authority “without undue delay and, where feasible, not later than 72 hours after having become aware of it” — unless the breach is unlikely to result in a risk to the rights of natural persons; if notification is made later, the delay has to be justified. The notification has to contain the nature of the breach and the categories and approximate number of data subjects and of the data concerned. And recital 85 of the regulation lists item by item what this speed protects against: loss of control over personal data, discrimination, identity theft, financial loss and damage to reputation.

This enumeration is precisely the risk list that experts also named in the present case: the main danger is not direct, unauthorised movement of money but targeted phishing committed with the confidential data obtained. On the GDPR’s logic, therefore, the yardstick for informing data subjects is not whether harm has occurred but whether a high risk exists. MIAK’s proposal 3.2 turns this into a practical requirement: the report has to say, data set by data set, what is proven and what is not — because only from this can the person concerned decide what to watch out for.

📖 Source: Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation)

6.4.3 Shoshana Zuboff: The Age of Surveillance Capitalism

The central thesis of Zuboff’s volume is that actors handling large data assets enjoy “an extraordinary asymmetry of knowledge and power unprecedented in human history”, and that its significance can best be grasped as the privatisation of the division of social learning — of who knows what about whom. Zuboff’s analysis is about technology companies, but the conceptual frame is transferable to state data assets too, because the source of the asymmetry is the same: one party sees the full picture, while the other does not even know what picture exists about them.

In the Treasury matter this asymmetry takes concrete form. The state handles pension assessment, family support and municipal account data; the citizen, however, cannot even check whether the data concerning them was accessed. According to MIAK it is precisely for this reason that improving protection is not enough: to restore trust, part of the asymmetry has to be dismantled, namely by the citizen learning afterwards, from a credible, independent source, what happened. This is the real reason for proposal 3.2 — not the naming of those responsible, but the minimal restoration of informational balance.

📖 Source: Shoshana Zuboff: The Age of Surveillance Capitalism

6.5 International comparison

The model of independent, public incident investigation is not a theoretical construction. In the United States the Cyber Safety Review Board (CSRB) was created expressly on the pattern of aviation safety accident investigation, and has issued public reports on major incidents of public interest — the structure of the reports (chronology, root cause, recommendations) is exactly what MIAK’s proposal 3.2 asks for. In the United Kingdom the annual report of the National Cyber Security Centre publishes incident statistics broken down by sector, which makes the performance of successive years comparable. Estonia — which rebuilt its system after the 2007 series of attacks — provides a model on the continuity side: in the data embassy model, authenticated copies of state registers are also available in a data centre abroad, which serves exactly the aim of proposal 3.3.

What these models have in common is that none of them places the emphasis on defensive technology, but on the capability to recover and to account. This change of perspective is particularly justified in the Hungarian case because, according to the analyses, here too it was not the controls but the response that failed.

Digitalisation and AI regulation

  • D3 — Digital citizenship
  • D5 — Cybersecurity strategy
  • D18 — Data governance and open data intermediaries

Public administration and e-government

  • KI1 — One-stop digital administration
  • KI10 — Proactive state service

Transparency and anti-corruption policy

  • A6 — Strengthening checks and balances

Proposed new programme point: A payment-continuity contingency procedure for social benefits — for the Social policy area.

6.7 List of sources

Press sources (MIAK press monitor, 12 August 2026 — topic 6):

Knowledge-base references (books and official legal sources):

  • 📖 Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2)
  • 📖 Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation)
  • 📖 Shoshana Zuboff: The Age of Surveillance Capitalism

Note: the local file path of the sources does not appear in the visible text of the blog — only the author and the title, or the designation of the legal source.

MIAK internal materials:

  • MIAK policy area: Digitalisation and AI regulation (programme points; programme point ID: D5, D18)
  • MIAK policy area: Public administration and e-government (programme points; programme point ID: KI1, KI10)
  • MIAK policy area: Social policy (background material)
  • MIAK press monitor, 12 August 2026 — topic 6, score: 84/100

Additional public data sources:

  • ENISA — Threat Landscape annual report
  • National Cyber Defence Institute — incident reporting statistics
  • Cyber Safety Review Board (United States) — public incident investigation reports

Generation metadata