The UK Foreign Office confirmed it suffered a cyberattack discovered in October, with senior ministers publicly acknowledging the breach but withholding specific details pending the outcome of an ongoing investigation. While some media reports have speculated that Chinese state-sponsored actors were responsible and that visa application data may have been compromised, government officials have cautioned that these claims are unverified and that no evidence currently suggests individuals have been harmed. The Foreign Office stated that the security vulnerability was quickly addressed and that the investigation is focused on determining the full scope and impact of the incident.
The breach is particularly concerning due to the sensitive nature of the Foreign Office's systems, which handle classified diplomatic communications and intelligence. The attack occurred during a period of heightened diplomatic activity, raising concerns about potential exposure of critical statecraft information. Official attribution has not been made, but the sophistication of the attack has led to speculation about state-sponsored involvement. The incident highlights ongoing cyber risks to UK government infrastructure, with recent data showing a significant number of nationally significant cyber incidents handled by the National Cyber Security Centre over the past year.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
On December 19, 2025, trade minister Sir Chris Bryant confirmed in Parliament that the Foreign Office had been hacked. He said many reported details about attribution and the scale of data theft remained unverified and that the current assessed risk to individuals was low.
Initial press reports claimed Chinese-linked group Storm-1849, also known as UAT4356, was responsible and that visa or personal data had been stolen. These claims were widely reported but were not confirmed by UK officials.
After discovering the breach, the government said it moved quickly to close the vulnerability and contain the incident. The Foreign Office and the National Cyber Security Centre began investigating the attack and assessing any risk to individuals.
The UK's Foreign, Commonwealth and Development Office discovered a cyberattack in October 2025 affecting its network. Officials have not disclosed which systems were impacted or provided technical details of the intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetechrepublic.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.