Storm 1849 — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 19, 2025
Last Seen
December 19, 2025

Storm 1849 is a apt_group tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed December 19, 2025; most recent activity December 19, 2025.

Overview

Storm 1849 is an APT group implicated in a cyber intrusion affecting the UK Foreign, Commonwealth and Development Office (FCDO). Current reporting points to data exfiltration and an October breach, with attribution not yet confirmed—though some sources mention a potential China-linked actor. The case underscores the impact of state-sponsored, targeted intrusions on government networks and the broader cross-border espionage risk in cybersecurity.

Related Threat Clusters

  • UK Foreign Office Hacked; Chinese Group Suspected

    The UK Foreign Office was hacked in October, with government data reportedly stolen. Trade Minister Chris Bryant confirmed the breach and stated that the risk to individuals is considered low. Investigations are…

    25 articles · Updated December 19, 2025

Recent Intelligence Reports

  • Data stolen in cyber attack on Foreign Office — Ukauthority · December 19, 2025
  • UK confirms October hack on Foreign Office systems as investigation continues — Nationaltechnology · December 19, 2025
  • 'Not clear' who was behind FCDO hack, says minister, amid reports of China link — Theguardian · December 19, 2025

CVSS v3.1 Breakdown