The Honeypot Paradox: Why the UK Keeps Getting Hacked by the Same Actors
The December breach, first reported by The Sun (though officially unconfirmed as Chinese), saw cyber gang Storm-1849 allegedly target Foreign Office servers in October. They accessed confidential documents and potentially tens of thousands of visa details, though government statements on 9 December confirming similar threats made no mention of visa data, and officials later disputed the visa claims.
The reported attack remained undisclosed for over two months, raising questions about detection capabilities and the true scale of compromise.
The government announced formal sanctions against two China-based companies for 'reckless and indiscriminate cyberattacks': Sichuan Anxun Information Technology (i-Soon) and Integrity Technology Group. The government statement confirmed these companies "provide technical assistance for others to carry out cyberattacks" and that i-Soon had "targeted over 80 government and private industry IT systems across the world."
Reuters reports the Prime Minister Keir Starmer is scheduled to visit Beijing and Shanghai on 29-31 January to "strengthen economic ties", the first British PM to visit China since Theresa May in 2018.
If visa applicants' data was stolen, it creates a roadmap of who's travelling, why, and where, which is intelligence gold for a state actor mapping foreign influence networks and identifying potential recruitment targets.
What is a State-Affiliated Hacker?
MI5 says state-sponsored hackers in this context are not necessarily direct government employees. Instead, they form part of a complex "ecosystem". This network includes private security firms, data brokers, and "hackers for hire" who operate commercially while providing technical assistance and information to Chinese intelligence services. This model provides the state with plausible deniability, as the actors appear to be private entities until their activities are formally linked to state interests.
To understand the nature of these attacks, imagine the UK’s digital infrastructure as a large estate, crammed with buildings. Rather than an army trying to blow up the front gates, the state hires private locksmiths to walk around the target’s perimeter every night. These locksmiths aren't using explosives; they are simply trying every door handle (phishing/cloud vulnerabilities) until they find one that was left unlocked by mistake. Once inside, they don't steal the furniture; they photograph every document in the filing cabinets (for example visa and voter data) so they can return to the estate, or blackmail its residents, whenever they choose.
The Prime Minister is currently considering allowing the building of a new, massive "super embassy" for the very group hiring these locksmiths, as he prepares to visit the locksmiths' employers to "strengthen economic ties". This creates a 'honeypot paradox': the UK is centralising more data into digital ID schemes even as its current 'filing cabinets' are being systematically photographed. This project, which will create the largest embassy site in Europe, is attracting global concerns about security.
2025 in Review
The following timeline details Chinese-affiliated cyber activity and government responses throughout 2025:
- 19 Dec 2025 Foreign Office Breach: On BBC Breakfast and Sky News. Trade Minister Sir Chris Bryant confirms an October hack; reports suggest tens of thousands of visa files were accessed by Storm-1849 (UAT4356).
- 9 December 2025: The UK government imposes sanctions on two China-based firms, i-Soon and Integrity Technology Group, for their roles in an "ecosystem" that supports state-linked cyber operations.
- November 2025: The NCSC Annual Review is published, re-stating that China remains a persistent and "highly sophisticated" threat to the UK's wide range of sectors.
- October 2025: Storm-1849 breaches FCO servers using phishing emails and cloud access. Separately, media reports suggest Chinese hackers have had decade-long penetration into UK critical infrastructure.
- September 2025: The NCSC exposes a covert botnet of over 260,000 devices operated by the "Flax Typhoon" group (Integrity Technology Group).
- September 2025: Claims emerge that Chinese spies used the Claude AI tool to automate cyberattacks, though some experts suggest this may be "marketing hype".
- August 2025: A joint international advisory links three Chinese companies to the "Salt Typhoon" campaign, which targeted global telecommunications and military infrastructure.
- February 2025: Doughty Street Chambers reports hundreds of attempts to hack the accounts of staff and lawyers, including Caoilfhionn Gallagher KC, who is known for work critical of the Chinese government.
We'd like your views:
- When basic phishing emails repeatedly defeat government cybersecurity, is the problem "sophisticated attackers" or fundamentally insecure systems with inadequate human oversight?
- Should UK organisations reconsider any partnerships with Chinese tech firms, even "commercial" ones, given the NCSC's assessment that this ecosystem "almost certainly" supports state intelligence operations?
- The Electoral Commission needed three years and £250,000 to recover from one breach—what's the cumulative cost of multiple attacks across government departments, and who's accountable when prevention fails repeatedly?
- Can Starmer simultaneously sanction Chinese cyber firms and pursue "strengthened economic ties" in Beijing, or is one position just diplomatic theatre?
- With state-sponsored hackers operating through private companies with plausible deniability, how do you defend against an adversary that's simultaneously a business partner and intelligence threat?
- If breaches often go undetected for months or years, how many current compromises are we unaware of, and what's the real scale of Chinese penetration of UK government systems?
- What would genuinely resilient government IT look like—systems designed with transparent human oversight and the ability to fail safely, rather than black boxes that get breached silently while claiming to be "secure"?



