CSIDB logo
Threat actor

Storm 1849

Attribution profile

Type
Spy
Location
China
Known incidents
4 incidents
Sources
0 sources
First seen
2025-09-01
Last seen
2025-12-22
Updated
2026-07-18 06:39
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Storm 1849 is a threat actor identified by the alias Storm 1849 and has been associated with operations originating from China. Public reporting links the group to attempts to access confidential information held by UK government entities, specifically referencing the Foreign, Commonwealth and Development Office. The targeting described in the sources focuses on governmental sectors within the United Kingdom, indicating a geographic focus on UK institutions. No further details about the actor’s internal structure, size, or broader geographic reach are provided in the available material.

Attribution discussions in the sources describe Storm 1849 as a China‑linked group, though officials have explicitly stated that a direct connection to Chinese state actors could not be confirmed. Consequently, while the actor is publicly characterized as having ties to China, no definitive state nexus or affiliation with a known criminal consortium has been established. The group’s activities have been noted in two separate UK government cyber incidents: one in October 2025 where officials confirmed a breach of government systems that was quickly contained, and another in December 2025 where an investigation was launched after media reports suggested access to thousands of confidential documents, including possible visa‑related data. In both cases, authorities emphasized that the risk to individuals appeared low and that investigations were ongoing.

The publicly reported material does not specify any particular malware families, initial access vectors, or tooling employed by Storm 1849, so no technical tactics, techniques, or procedures can be detailed from the given sources. Similarly, no information is provided about financial motives, disruption objectives, or the scale of the actor’s operations beyond the described government‑focused incidents. The profile therefore remains limited to the confirmed facts of the actor’s alias, its alleged China linkage, the observed targeting of UK government bodies, and the two cited intrusion events without speculation on unconfirmed attributes.

Incidents

Attributed incidents are available to members.

4 incidents

Sources

Sources available to members: 0 sources.

CSIDB