The EU places the Kremlin’s intelligence services behind multiple cyberattacks in Europe

The EU places the Kremlin's intelligence services behind multiple cyberattacks in Europe

The European Union has pointed to the Russian intelligence service FSB on Monday as one of the main responsible parties in Russia for the multiple cyberattacks that several European countries have been suffering in recent months and years, and has announced the imposition of sanctions on several Russian individuals and entities allegedly linked to this type of attacks.

Read more The heatwaves in May and June caused more than 2,700 deaths in the United Kingdom

Monday’s move is a coordinated action at the European level: while Brussels officially pointed the finger for the first time at the FSB and other services of the Eurasian country, the United Kingdom also announced new sanctions and France and Germany summoned Moscow’s representatives to explain this type of hybrid actions.

“The EU and its Member States condemn Russia’s malicious cyber activities and its use of a cyber ecosystem involving state and non-state actors, from intelligence services to cybercriminal groups, hacktivists and private companies,” said the EU’s High Representative for Foreign Policy, Kaja Kallas, in a statement on behalf of the community bloc.

In it, Brussels publicly points for the first time to the direct link between “malicious” cyber activities and the FSB. Specifically, it is the FSB’s Center 16, also known as military unit 71330, which the EU accuses of “controlling” various cyber threat groups such as Turla. “For years, the FSB has carried out a wide range of increasingly serious malicious cyber activities affecting the EU, its Member States and international partners, particularly Ukraine,” the statement says, citing among other malicious attempts the “infiltration of government networks and sabotage of critical infrastructure.”

Vladimir Putin
Vladimir Putin and then head of the Russian foreign intelligence service, Sergey Naryshkin [the second, in the second row], receive their spies in a prisoner exchange between Russia and the West in 2024.Kirill Zykov (REUTERS)

Among the most affected countries is France, where Center 16 “has conducted cyber espionage activities against strategic government entities since 2010 and against the defense industry in 2025.” Also Germany, where it has mainly attacked “government entities.” And Poland, where Center 16 has carried out “disruptive sabotage operations against critical infrastructure, including cogeneration plants.” According to the head of European diplomacy, the illicit activities of this group linked to the FSB have also been tracked in Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.

“We strongly condemn Russia’s actions and the misuse it makes of this cyber ecosystem, which targets public services and critical infrastructure, causing disruptions and economic losses,” the Estonian politician states in the joint declaration.

Two of the affected countries, France and Germany, also announced on Monday that they will summon the respective Russian ambassadors. In the first case, Paris plans to impose sanctions on Russian citizens and companies, according to French Foreign Minister Jean-Noël Barrot. “Today we will publicly condemn a large-scale cyber campaign carried out by Russia aimed at committing acts of sabotage and espionage against a dozen countries,” Barrot told the BFM television channel. In the same vein, Berlin has promised to respond firmly and apply additional sanctions.

Read more The PP of Madrid maintains its support for the mayor of Móstoles after his indictment for alleged sexual harassment

The United Kingdom has also joined the sanctions announced today against the Russian officials. “These sanctions strike directly at the heart of the cybercriminal networks driving the Russian state’s aggression. The UK and the EU thus send Russia the clear message that it cannot hide behind these subsidiary groups,” emphasized British Foreign Secretary Yvette Cooper. “From orders to criminals or attacks on companies, to sabotage of Poland’s power grid in the dead of winter, Russia is reaching ever lower levels in its attempt to undermine Europe’s security.”

The British government has also imposed individual sanctions on Lumma Stealer, the malware operated by a Russian cybercriminal network that allows the collection of sensitive information and large-scale system alteration. Russia, it adds, has used passwords and credentials stolen by this platform to carry out global cyberattacks supporting Kremlin objectives.

In the last six months, according to the UK’s National Crime Agency, there have been at least 2,100 victims of Lumma Stealer across the country.

Similarly, London has imposed sanctions on ten individuals who are part of the management and content design of Rybar LLC, the company behind the dissemination of false information about Ukraine and which has participated in interference acts in the electoral processes of Moldova and Armenia.

At the European level, the blacklist of sanctioned individuals has also been updated with nine new individuals and four more entities. The sanctions of the Twenty-Seven affect intelligence officers of the Central Intelligence Department of the army (GRU), “self-proclaimed hacktivist cybercriminals and private companies that contribute to Russia’s efforts to destabilize the EU, its Member States and its international partners.”

Read more Inside the White House: this is how Trump wields unchecked power to leave his mark on history

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *