
The European Union and Britain on Monday blamed a highly specialized unit of Russia’s Federal Security Service, or FSB, for a decade-long campaign of cyber-espionage and attempted sabotage targeting critical infrastructure, including power grids and defense networks, across Europe.
To counter the threat, the Council of the European Union imposed asset freezes and travel bans on nine individuals and four entities linked to the campaign. Britain issued parallel sanctions targeting 24 individuals and entities.
In a coordinated series of announcements, Western officials identified the 16th Center of the FSB as the orchestrator of several notorious hacking collectives, including the group known as Turla. The unit’s digital fingerprints have been traced to government networks and essential services across nearly a dozen European nations, including France, Germany, Poland, and Ukraine. However, the 16th Center itself was not added to this specific sanctions list.
The attribution marks a rare public unmasking of Russia’s state hacking apparatus.
In France, domestic security agencies separately identified Unit 61240, a specialized subdivision of the 16th Center, as the culprit behind a series of high-profile intrusions stretching back to 2010.
According to French authorities, the unit’s targets have included highly targeted attempts to compromise email accounts within the French Ministry of Defense in 2017. A year later, a cyberattack targeting the French Embassy in Moscow and in 2019, the breach of a secure server utilized by France's national judicial system. Last year, they recorded a successful data theft targeting a research institute closely partnered with the French defense industry.
Further east, the operations shifted from intelligence gathering to potentially lethal physical sabotage. In Poland, the FSB unit was accused of executing highly disruptive cyber-campaigns against combined heat and power plants.
Working in tandem with European allies, the British government revealed that the same Russian unit had attempted a catastrophic shutdown of Poland’s electricity grid. Had the cyberweapon succeeded, British officials estimated it could have severed power to approximately 500,000 people during the winter.
Britain's Foreign Secretary, Yvette Cooper, condemned the operations, characterizing them as a dangerous merger of state intelligence and cybercriminal networks designed to destabilize Western allies.
The blacklisted organizations highlight the blurred lines between Russian intelligence and private criminal enterprises, a nexus that NATO warned is becoming a cornerstone of Moscow's hybrid warfare strategy.
Among the newly designated entities are: Media Land LLC and ML.Cloud: Tech companies accused of leasing server infrastructure to ransomware and phishing syndicates. Z-Pentest – a pro-Kremlin hacktivist group that has actively targeted Western water and energy utilities.
Also Impuls – a firm tied directly to the GRU’s Unit 29155—a notorious Russian military intelligence squad historically associated with physical assassinations and European destabilization campaigns.
The sanctions also swept up key developers behind prolific malware strains like Trickbot, Conti, and LummaC2. Among those blacklisted was Ivan Kasyanenko, identified by European officials as a senior GRU officer embedded within Unit 29155.
NATO officials echoed the warnings, releasing a statement that accused the Kremlin of increasingly relying on a volatile mix of formal intelligence services, proxy criminal syndicates, private tech firms, and patriotic hacktivists to wage its quiet digital war against the West.
Source: Original article
