CSIDB logo
Incident

Ministry of Foreign Affairs of the Czech Republic

Incident posture

Attack window
Jul 2025
Location
Czechia
Status
Unknown
CIA posture
Available to members
Updated
2026-07-18 07:15

Linked entities

Victim
Ministry of Foreign Affairs of the Czech Republic
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An Asian cyber‑espionage group conducted a extensive spying operation that breached government and critical‑infrastructure networks in more than thirty countries, using tailored phishing emails and unpatched vulnerabilities to gather sensitive information. In the Czech Republic the attackers performed reconnaissance on the Army, police, Parliament and the Ministry of Foreign Affairs of the Czech Republic after a meeting between the Czech president and the Dalai Lama, exfiltrating emails and other confidential data from the compromised systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In July 2025, Czech President Petr Pavel met with the Dalai Lama. In the following weeks, the hackers conducted reconnaissance on Czech government targets including the Army, police, Parliament and Ministry of Foreign Affairs, according to the report. The attackers used highly-targeted and tailored fake emails and known, unpatched security flaws to gain access to these networks. According to the Palo Alto Networks report, they infiltrated networks of seventy organisations across thirty‑seven countries. These victims included five national law enforcement and border control agencies, three ministries of finance, one country’s parliament and a senior elected official in another state. The intruders hoovered up sensitive information, spied on emails, financial dealings and communications about military and police operations. They also stole information about diplomatic issues and remained undetected in some systems for months.

Palo Alto Networks researchers confirmed that the group successfully accessed and exfiltrated sensitive data from some victims’ email servers. The company said it notified the victims and offered them assistance. The US Cybersecurity and Infrastructure Security Agency said it was aware of the campaign and was working with its partners to stop hackers from exploiting any of the vulnerabilities identified in the report. Representatives of the FBI and CIA declined to comment on the matter. The NSA did not respond to a request for comment. The Czech National Cyber and Information Security Authority did not respond to a request for comment on the report. The Chinese Embassy in Prague has previously rejected allegations about attacks against the Czech Republic as unsubstantiated.

Sources

Sources available to members: 1 source.

CSIDB