The Czech Republic says that the state-sponsored Chinese hacking group APT31 has targeted its foreign ministry's unclassified communications network since 2022
‘Malicious’ assault blamed on group known as APT31 that has been linked with Chinese state security ministry
Financial Times
Context & Ripple Effects
The Czech attribution adds a diplomatic-network case to the scrutiny already surrounding APT31: the US and UK had previously sanctioned a Wuhan-based company linked to the group over alleged targeting of critical-infrastructure organizations. It matters because the reported activity is described as persisting over multiple years, rather than as an isolated intrusion.
First-order effects
The public attribution raises the political and security cost for Prague and Beijing, while making the foreign ministry's unclassified communications environment an immediate focus of incident assessment and diplomatic risk management.
APT31's alleged association with China's Ministry of State Security makes the episode a state-to-state issue, not merely a technical compromise claim.
Second-order effects
Allied governments can use the attribution alongside the earlier US-UK action against an APT31-linked company when coordinating threat reporting, protective measures, or further responses.
Foreign ministries and the providers supporting their communications systems face stronger pressure to treat even unclassified diplomatic networks as high-value espionage targets.
Third-order effects
If repeated public attributions continue, diplomatic communications will become a more explicit arena of cyber deterrence: governments will pair defensive investment with coordinated naming, sanctions, and other state-level responses.
The broader structural shift is toward persistent competition for diplomatic intelligence below the threshold of overt confrontation, with attribution quality and allied coordination determining how costly such campaigns become.
The trend: State-linked cyber operations are increasingly targeting diplomatic communications as governments turn technical intrusion findings into coordinated geopolitical pressure.
Germany stands in solidarity with the Czech Republic in its attribution of China's malicious cyber attack against its Ministry of Foreign Affairs in Prague. Holding threat actors accountable is key to maintaining security and peace in cyberspace. https://www.nato.int/...
The Government of the Czech Republic has publicly attributed a malicious cyber campaign perpetrated by the cyberespionage actor APT31 targeting one of the unclassified networks of the Czech Ministry of Foreign Affairs to the People's Republic of China. [image]
2/2 Together with @strakovka, @NUKIB_CZ, @biscz, @VZpravodajstvi and the Office for Foreign Relations and Information, we have uncovered, investigated, and now publicly condemn the attack. [image]
Today, the EU holds a Chinese state-backed actor responsible for a malicious cyber campaign targeting Czechia. This is a clear and unacceptable violation of international norms. We stand firmly with Czechia. My statement on behalf of the EU → https://europa.eu/!xrDbyf [video]
1/2 We are exposing cybercriminals. China has been persistently trying to undermine our resilience and democracy. Through cyberattacks, information manipulation, and propaganda, it interferes in our society - and we must defend ourselves against it. [image]
The Government of the Czech Republic has publicly attributed a malicious cyber campaign perpetrated by the cyberespionage actor APT31 targeting one of the unclassified networks of @CzechMFA to the People's Republic of China. 1/ [image]
#NATO Allies stand in solidarity with the Czech Republic today, following a malicious cyber campaign attributed to the People's Republic of China. NATO observes with concern the growing pattern of malicious cyber activities stemming from China Statement: https://www.nato.int/...
🇪🇪 stands in solidarity with 🇨🇿. We urge all states to behave responsibly in cyberspace and uphold international norms. If threats persist, we are prepared to take concrete action. @CzechMFA
We share Czechia's deep concern about the increased scale & severity of malicious cyber activity by state-affiliated actors. We are deeply troubled by the activity Czechia has reported. We stand in solidarity with @CzechMFA against malicious cyber activity by state actors
APT31 is an active threat to Europe and the US. They have persisted through efforts to shed light on their operations, and will likely continue to carry out cyber espionage against governments, media, tech, and other sectors.
Today, the Czech Republic 🇨🇿 has exposed a malicious cyber campaign carried out by Chinese state-affiliated actors against @CzechMFA We will keep working closely with our Allies to hold #China 🇨🇳 and other state actors to account for their actions in cyberspace
Czechia accuses China of a cyber attack on its foreign ministry. Some naively belief that Irish neutrality protects the country from such attacks. The opposite is more likely to be the case.
The Netherlands expresses its support to the Czech Republic, which has publicly attributed a cyberattack on its critical infrastructure to state-sponsored cyber actors from China (APT31). 1/2
Statement of solidarity by the North Atlantic Council concerning the malicious cyber activities against the Czech Republic Tap to read the full statement ↓
Belgium strongly condemns the malicious cyber campaign targeting Czechia. Such actions are a blatant violation of international norms. We stand in full solidarity with our Czech partners. @BelgiumMFA
Germany stands in solidarity with the Czech Republic in its attribution of China's malicious cyber attack against its Ministry of Foreign Affairs in Prague. Holding threat actors accountable is key to maintaining security and peace in cyberspace.
Latvia expresses full solidarity with Czechia regarding the malicious cyber campaign against its Ministry of Foreign Affairs. We call all states to act responsibly in cyberspace in accordance with the international law, including the principle of due diligence.
The Czech government condemned China for carrying out a cyber campaign against one of the unclassified networks of the Czech Ministry of Foreign Affairs. “The malicious activity, which lasted from 2022 and affected an institution designated as Czech critical infrastructure, was […
The United States stands with 🇨🇿's attribution of the malicious cyber activities of the China-affiliated cyber actor APT31. The U.S. denounces these actions and calls upon the CCP to immediately cease any and all such activities.
We will continue to work with our allies to hold China and other state actors accountable for their actions in cyberspace. In March 2024, the UK publicly attributed China state-affiliated actors for the targeting of UK parliamentarians and the Electoral Commission. 2/2
Czechia has shared its attribution of a cyberattack on the Czech MFA. Together with partners + allies in EU and NATO, DK condemns this malicious cyber activity. We call on all states to comply with UN norms of responsible state behaviour. We stand in full solidarity with 🇨🇿
The Select Committee stands with @CzechMFA 🇺🇸🇨🇿 The CCP is waging a relentless campaign of cyber attacks, espionage, and coercion to undermine democracy across the globe. We echo Chairman @RepMoolenaar's address to the 2025 Prague Cyber Conference: the CCP is targeting our