Ministers confirm breach at UK Foreign Office but details remain murky
- Reference: 1766142855
- News link: https://www.theregister.co.uk/2025/12/19/uk_foreign_office_hack/
- Source link:
Trade minister Sir Chris Bryant told [1]Times Radio on Friday that "there certainly has been a hack" but it is too early in the government's investigation to confirm other widely reported details.
The news first broke in [2]The Sun on Friday. The tabloid claimed that Chinese state-sponsored attackers were behind the intrusion and stole details related to tens of thousands of visa applications.
[3]
However, Sir Chris said many of the details reported by the British red top are speculative.
[4]
[5]
"The front page of The Sun is slightly over-egging the details that are available at this stage," he said. "But the one thing I do want to reassure people about is that in our initial investigation we are pretty confident that no individual will be harmed.
"As you said, potentially people's visa applications might have been attacked, but that is somebody speculating."
[6]
Sir Chris said that there has been nothing thrown up by the investigation thus far that suggests any individual would be harmed or compromised.
"There certainly has been a hack, I can say that. I'm not able to say whether it is directly related to Chinese operatives, or indeed the Chinese state.
"We have been engaged in an investigation since October. Just as with [7]JLR , [8]M&S , the [9]British Library , and a whole series of other cyberattacks, it does take some time to get to the bottom of exactly what's happened."
[10]
The Register asked the Foreign, Commonwealth, and Development Office (FCDO) for more information about the attack, including which systems are under investigation and how the attackers – pending attribution – were able to access them.
A government spokesperson simply responded: "We have been working to investigate a cyber incident. We take the security of our systems and data extremely seriously."
Sir Chris told Sky News: "We managed to close the hole, as it were, very quickly. There was a technical issue in one of our sites, I gather, and we're fairly confident that there's a low risk of any individual actually being affected by this."
The news of the attack comes just days after security researchers at Check Point Software said Chinese cyber-espionage groups have compromised several dozen victims in their bid to expand spying efforts on European governments.
Check Point did not list any of the governments involved, but [11]said those behind the attacks are compromising servers and laying the ground for future operations.
[12]NHS tech supplier probes cyberattack on internal systems
[13]JLR: Payroll data stolen in cybercrime that shook UK economy
[14]UK to Europe: The time to counter Russia's information war machine is now
[15]UK finally vows to look at 35-year-old Computer Misuse Act
Of the four major geopolitical adversaries, the UK has repeatedly singled out China as an "epoch-defining challenge."
GCHQ director Anne Keast-Butler told CYBERUK in 2024 that more resources were spent on tackling the threat presented by China than any other UK intelligence mission.
"China poses a genuine and increasing cyber risk to the UK," she [16]said at the time.
"China has built an advanced set of cyber capabilities and is taking advantage of a growing commercial ecosystem of hacking outfits and data brokers at its disposal.
"The PRC is looking to shape global technology standards in its own favor, seeking to assert its dominance within the next 10 to 15 years.
"Which is why the UK's intelligence community is working alongside our allies in the Five Eyes and beyond, and also in partnership with our industry and academic colleagues to deter and combat cyber threats from nation-states and hostile actors."
China is seen as the long-term threat, while Russia is the problem of today – the acute and powerful threat that requires significant resources and cooperation to tackle.
In her [17]first speech since taking over as MI6 director, Blaise Metreweli said this week that the UK is currently operating between peace and war, referring more broadly to geopolitical adversaries, but later cited a "grey zone" it shares with Russia, which is just below the threshold of war. ®
Get our [18]Tech Resources
[1] https://x.com/TimesRadio/status/2001927616463344055
[2] https://www.thesun.co.uk/news/37681625/china-hackers-stole-secret-files-foreign-office/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aUWEqZUDMMRSFcaI87jcDgAAAU8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aUWEqZUDMMRSFcaI87jcDgAAAU8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aUWEqZUDMMRSFcaI87jcDgAAAU8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aUWEqZUDMMRSFcaI87jcDgAAAU8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2025/12/15/jlr_payroll_data_stolen_in/
[8] https://www.theregister.com/2025/11/05/ms_pegs_cyberattack_cleanup_costs/
[9] https://www.theregister.com/2025/05/01/ico_brit_library/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aUWEqZUDMMRSFcaI87jcDgAAAU8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2025/12/16/chinas_ink_dragon_hides_out/
[12] https://www.theregister.com/2025/12/18/nhs_tech_supplier_cyberattack/
[13] https://www.theregister.com/2025/12/15/jlr_payroll_data_stolen_in/
[14] https://www.theregister.com/2025/12/09/uk_europe_russia_information/
[15] https://www.theregister.com/2025/12/09/uk_computer_misuse_act/
[16] https://www.theregister.com/2024/05/16/the_uks_alarm_over_china/
[17] https://www.gov.uk/government/speeches/speech-by-blaise-metreweli-chief-of-sis-15-december-2025
[18] https://whitepapers.theregister.com/
Four major geopolitical adversaries
So that is Russia, China,
USA and home-grown incompetence?
Re: Four major geopolitical adversaries
I'm glad you bring the USA into this. The USA is indeed our adversary, as it is to every other country.
Re: Four major geopolitical adversaries
Don't forget India.
A couple of thoughts
1. Does the FCO use Cisco? If so, heads should roll. And I don't mean into the House of Lords.
2. I am more concerned about the endemic penetration of the UK by the USA than I am by China.
Britain can hardly point a tut-tutting finger at China. The small matter of the Opium wars, forcing China to buy very addictive drugs. Y'know, drug peddling on an industrial scale. But somehow Britain is the good guy. Then there is Hong Kong. No democracy there until Britain is on the cusp of leaving. Good old Chris Patten. Voted out by his electorate, then promptly made a peer so he could carry on as though democracy is for others but not for him.
someone probably emailed an Excel spreadsheet by mistake
So it's a hack!
Everyone got their cyber attack bingo cards ready?
Paraphrasing is acceptable -
No evidence of personal data being affected - check
We take the security of our systems and data seriously - check
technical issue - check
Just waiting on "sophisticated attack" for a line
And wait a few weeks and they'll admit that everything was taken even PMs holiday snaps, and the hack was actually the Chinese being offer full access after a tour of the data centre and complementary snacks.
Blindspot
MI6 director is focusing on Russia (which is correct), but has a complete blackspot when it comes to BlackRock, Microsoft and other corporations slowly taking over sovereignty over the UK.
They don't use bullets as weapon, but good old aged steaks and wine.
Re: Blindspot
It's called "inward investment" and announced as a good thing..
Re: Blindspot
Because ministers don't understand what inward investment is. If foreign company invests X billions, they are hoping to extract X+Y back. That is a short term gain and long term loss to the country.
Don't forget about foreign "lobbied" policies like Digital ID that nobody voted for.
Only slightly, it must be bad then ?
The Sun is slightly over-egging the details that are available at this stage," he said.