← Back to list

Spies, Malware, and Blackouts: EU Blames Secret FSB Unit for Decade of Cyber Sabotage

Russia is sharpening its weapons, probing and testing Western defences

James Marinero, MSc, MBA. in The Dock on the Bay · 2026-07-18 05:06 · 440 claps · 5.0 min read paywalled
#geopolitics #national-security #russian-intelligence #cybersecurity #cyber-espionage
Open on Medium ↗
Wiki topics: SOC · Sociology & Politics 🔒 · Cybersecurity 🏛️ · Politics

War in Europe

Spies, Malware, and Blackouts: EU Blames Secret FSB Unit for Decade of Cyber Sabotage

Russia is sharpening its weapons, probing and testing Western defences

A Russian bot farm uncovered in Ukraine (Ukraine Police)

A Russian bot farm uncovered in Ukraine (Ukraine Police)

There is a war under way, a full-on, almost hidden war. A war which stretches beyond Ukraine. And it is widening and deepening.

Russia is sharpening its cyberweapons, thrusting and testing European defences. Europe recognises the threat and is increasing its military budgets, too slowly some would say as even the UK’s Minister of Defence indicated recently when he resigned.

Labour’s John Healey provided his personal statement following his resignation in the House of Commons. Healey warned of the consequences of inaction on the part of the UK, citing the increasing likelihood of a war with Russia by 2030, per NATO.

Yes, Europe is preparing for war with Russia by 2030 if Ukraine has not by then put Russia back in its box. And yes, Ukraine is doing the heavy lifting right now with Europe is increasing its support.

The classical lesson about war has been too long neglected:

The price of appeasement always goes up.

But, as I said, Russia has long been sharpening its weapons, and this week the public was made well aware of it.

A decade of disruption

The European Union has identified the 16th Centre of Russia’s Federal Security Service (FSB) as the primary entity responsible for a sustained campaign of cyber interference across the continent.

This unit, which operates with high levels of discipline, serves as the command structure for various digital threat actors, including the group known as Turla. Investigations by European authorities indicate that this infrastructure has been active since 2010, managing a transition from passive espionage to active sabotage.

The intelligence agency does not operate in isolation but instead coordinates a complex ecosystem of state intelligence officers, non-state cybercriminal groups, self-proclaimed hacktivists, and private companies. You have heard about them, I’ve written about them for several years now. State-affiliated groups such as Cozy Bear (APT29).

By leveraging these diverse proxies, the FSB has maintained a persistent presence within the networks of member states, effectively blurring the lines between traditional intelligence gathering and offensive digital warfare.

Targets and methods of interference

The reach of this campaign spans numerous European nations, with particular focus on France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.

In France, strategic government bodies have been under observation since the beginning of the decade, with recent activities extending to the domestic defence industry. Domestic security agencies separately identified Unit 61240, a specialised subdivision of the 16th Center, as the culprit behind a series of high-profile intrusions stretching back to 2010.

Germany has seen similar targeting of its governmental infrastructure, while Poland has faced more aggressive, disruptive actions. In one notable incident, the FSB unit attempted to compromise Poland’s energy grid during the winter months. Had the operation succeeded, it could have deprived half a million citizens of electricity.

The methods employed are varied, ranging from the infiltration of sensitive government networks to the physical disruption of critical services, such as combined heating and power plants. These operations are designed to test the resilience of national infrastructure while gathering intelligence to further foreign policy objectives.

The UK has also been hit. Like France, it is a key target as it is a nuclear state. Russian-affiliated hackers infiltrated British government institutions, exfiltrating sensitive identification data belonging to public sector employees. This breach, discovered in early June 2024, compromised information including names, job titles, email addresses, and authentication credentials.

The FSB 16th Centre has also targeted critical infrastructure control and management systems in the UK.

The UK’s critical national infrastructure has been hit by more than 200 cyber incidents over the past year and state-linked assailants were behind three-quarters of the attacks, according to the state cybersecurity body.

Richard Horne, the chief executive of the National Cyber Security Centre (NCSC), said hostile states such as Russia, China and Iran were increasingly targeting systems behind the UK’s key services.

Examples of critical national infrastructure include the UK’s nuclear deterrent, power plants, hospitals and airports.

Horne said the UK was engaged in an “ongoing contest with capable adversaries”.

“This contest is not confined to a compact space. It is not like a wrestling match in a closely defined territory, as some have suggested,” he said in a speech at the Royal United Services Institute. — The Guardian

The broader threat landscape

The FSB does not operate alone in its pursuit of destabilisation; it functions alongside other Russian intelligence branches, such as the Main Directorate of the General Staff, commonly known as the GRU. The directorate is reputedly Russia’s largest foreign intelligence agency and has been involved in many well-documented overseas assassinations.

While the 16th Centre focuses on its specific mandate, the GRU has been found to employ units like Unit 29155 to recruit technical talent from Russian universities and collaborate with private entities. This collaborative approach allows the Russian state to scale its operations, utilising malware-as-a-service (MaaS) models and recruiting specialists to perform tasks that might otherwise be beyond the reach of a single agency.

This model of hybrid warfare integrates cyber activities with broader political and military goals, ensuring that even failed attempts at sabotage serve as a form of pressure against the European bloc. The reliance on these external networks allows the state to maintain a degree of deniability while sowing division and chaos.

Coordinated response and sanctions

In response to these developments, the EU and the UK have implemented a joint package of sanctions, representing the first such coordinated effort to confront this persistent digital threat.

The measures target nine individuals and four entities directly linked to the FSB’s 16th Centre, as well as several officers and organisations associated with the GRU. These sanctions are intended to impose tangible costs on those responsible for the orchestration of cyber espionage and physical infrastructure attacks.

Several member states have also taken diplomatic action, including the summoning of Russian ambassadors to express formal condemnation of these activities. By exposing the internal structures of these intelligence units and imposing restrictive measures, European nations aim to bolster their resilience and signal that continued attempts to undermine their security will be met with a unified, multinational response.

Among the newly designated entities are:

  • Media Land LLC and ML.Cloud: Tech companies accused of leasing server infrastructure to ransomware and phishing syndicates. Z-Pentest — a pro-Kremlin hacktivist group that has actively targeted Western water and energy utilities.
  • Impuls — a firm tied directly to the GRU’s Unit 29155 also historically associated with physical assassinations and European destabilisation campaigns.
  • The sanctions also include key developers behind prolific malware strains like Trickbot, Conti, and LummaC2. Among those blacklisted was Ivan Kasyanenko, identified by European officials as a senior GRU officer embedded within Unit 29155.

This collective stance marks a shift in how the continent approaches the protection of its critical systems against foreign state-directed interference.

Conclusions

War is here in Europe and it’s not just a kinetic war in Ukraine.

If Putin’s Russia is not stopped and ejected from Ukraine it will become a kinetic war on a wider European front, most likely with an attack on the Baltic States.

It’s not a message that European politicians are keen to publicise. The public don’t usually vote for those whose platform is ‘war is inevitable and we must tool up now’.

[embed]Spies, Malware, and Blackouts: EU Blames Secret FSB Unit for Decade of Cyber Sabotage The EU and Britain have unmasked a specialized Russian intelligence unit behind a decade of cyber-espionage, revealing…www.occrp.org


메타데이터
post_id
9c5d6880dc92
slug
spies-malware-and-blackouts-eu-blames-secret-fsb-unit-for-decade-of-cyber-sabotage-9c5d6880dc92
url
https://medium.com/the-dock-on-the-bay/spies-malware-and-blackouts-eu-blames-secret-fsb-unit-for-decade-of-cyber-sabotage-9c5d6880dc92
canonical_url
https://medium.com/the-dock-on-the-bay/spies-malware-and-blackouts-eu-blames-secret-fsb-unit-for-decade-of-cyber-sabotage-9c5d6880dc92
author_url
https://medium.com/@james-marinero
status
ok
fetched_at
2026-08-19 01:22:14