4 min read

Fifteen Years, Nine Countries: The EU and UK Name the FSB Behind Europe's Infrastructure Sabotage Campaign- 275

Fifteen Years, Nine Countries: The EU and UK Name the FSB Behind Europe's Infrastructure Sabotage Campaign- 275

July 14, 2026

The United Kingdom and European Union have taken a step neither has taken before: attributing years of cyberattacks against critical infrastructure across nine European countries to a single Russian intelligence unit, and answering it with their first-ever joint cyber sanctions package. The immediate trigger was a December 2025 intrusion that came close to cutting power to half a million people in Poland during winter — but the formal attribution announced this week reaches far beyond that single incident, naming Russia’s Federal Security Service as the architect of a sustained campaign of sabotage and espionage that Brussels says has been running since 2010.

 The attack that forced the issue targeted Poland's power grid last December, attempting to disrupt communication between renewable energy hardware and distribution operators through a destructive wiper tool. Poland's energy minister confirmed the intrusion in January; British officials later described it as coming "very close" to causing an actual blackout in the depths of winter. The attribution itself evolved in a telling way. Cybersecurity firms ESET and Dragos initially linked the intrusion to Sandworm, the GRU-affiliated military intelligence unit responsible for Ukraine's 2022 and 2023 blackouts. That attribution was subsequently revised after Poland's own national CERT traced the attacking infrastructure and matched it instead to a cluster linked to the FSB — specifically Centre 16, the agency's signals intelligence division, also referred to in French reporting as the 16th Center. The correction matters less as a forensic footnote than as a signal of how contested and iterative attribution has become even among close allies, and of how readily responsibility for Russian state cyber operations can be misassigned between its two principal intelligence services.

a simple attribution-correction comparison.

What the EU and UK chose to describe this week was not an isolated grid intrusion but a campaign. Brussels dated the operation's origins to 2010 and named nine confirmed target countries — France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland — while pointedly leaving the list open-ended. France's own technical report, compiled by its Cyber Crisis Coordination Center, added granularity that the EU's public statement withheld: eleven signals-intelligence interception centers operating across Russia, a specific sub-unit designated Unit 61240 tasked with targeting France, and two ostensibly private Russian companies, AO AST and NPP Gamma, identified as material supporters of the unit's offensive operations. French targets named in the report span more than a decade, from government ministry intrusions in 2014 through the compromise of the French embassy network in Moscow in 2018 to the theft of a substantial volume of data from a defense-affiliated research institute as recently as February of this year. French officials went further still, attributing a destabilization effort against the 2024 Paris Olympics to one of the newly sanctioned groups and warning that the same apparatus is expected to be active ahead of France's 2027 elections. Poland, meanwhile, disclosed a parallel line of attack against its water treatment facilities and railway infrastructure, both flagged in recent months as posing direct operational risk.

map for the country scope

The sanctions package that accompanied the attribution illustrates how thoroughly the FSB's operations have blurred the line between state and criminal capability. Among those newly designated are serving GRU and FSB-linked officers, but also the operators of Lumma Stealer, one of the world's most widely deployed credential-theft tools, which British authorities say Russian intelligence has used directly to harvest access for espionage operations — more than 2,100 victims identified in the UK alone over six months. Also sanctioned was a company accused of running a university recruitment pipeline that channels cybersecurity talent from Russian academic institutions into state-directed hacking operations, alongside figures tied to the pro-Kremlin outlet Rybar over disinformation and election interference in Ukraine and, separately, in Moldova and Armenia. This is not incidental overlap. It reflects a deliberate Russian operating model in which intelligence services task nominally independent criminal and commercial actors to do sensitive work at arm's length, preserving a layer of deniability that formal state attribution is now explicitly designed to strip away.

Structural hierarchy for the FSB apparatus

That the EU chose not to publish the names of the individuals and entities it sanctioned — an unusual degree of restraint by the standards of prior sanctions announcements, and one that stood in visible contrast to the UK's willingness to name senior GRU figures directly — suggests the two allies are not yet fully aligned on how publicly to prosecute this argument, even as they act jointly. The accompanying technical advisory, co-authored by the UK's National Cyber Security Centre alongside the United States and a dozen other partner agencies, was more concrete: it identified systematic scanning for network devices still running SNMPv1 and SNMPv2 with default or weak community strings as Centre 16's principal method of gaining a foothold, alongside exploitation of Cisco Smart Install, and recommended organizations in communications, energy, finance, government, healthcare, and the defense industrial base move to SNMPv3 with authenticated encryption without delay. Taken together, the week's disclosures mark less a single retaliatory act than the formal opening of a new phase in how the EU and UK intend to contest Russian state cyber activity — naming the institution behind it, sanctioning the ecosystem that sustains it, and treating fifteen years of dispersed national incidents as what officials now say they always were: one campaign.