Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions
Russia’s FSB, specifically its Center 16 signals intelligence arm, has been formally blamed for a cyberattack that threatened to cut heating to half a million people in Poland last winter. Following this attribution, the UK and EU have imposed coordinated sanctions targeting Russian cybercriminals, intelligence officers, and entities linked to the pro-Kremlin Rybar blog. These sanctions aim to disrupt Russia’s cyber ecosystem and its use of criminal networks to support espionage and disinformation campaigns. The attack highlighted Russia’s continued reliance on a broad cyber ecosystem to conduct malicious operations against Europe and its partners.
A cyberattack that threatened to cut heating to half a million people in Poland last winter has been formally attributed to Russia’s Federal Security Service (FSB), specifically its Center 16 signals intelligence arm. Following this attribution, the United Kingdom and the European Union have jointly implemented a package of cyber sanctions against Russian cybercriminals, intelligence officers, and entities connected to the pro-Kremlin Rybar blog. The EU stated that Russia continues to rely on a broad cyber ecosystem comprising intelligence agencies, cybercriminal groups, hacktivists, and private companies to conduct malicious operations against Europe and its partners.
According to the European Union, the broader range of activities have included “infiltration of governmental networks and sabotage of critical infrastructure” targeting “France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland.” Last December’s attack on Poland’s energy grid was described as “reckless” by British authorities, adding it was “another example of the Russian state’s irresponsible attempts to sow chaos across Europe.”
French authorities, through their Cyber Crisis Coordination Center (C4), detailed Center 16’s operations and identified 11 interception centers used by the agency’s signals intelligence arm across Russia, including Unit 61240, which the C4 said was focused on targeting France. The French report named two Russian companies, AO AST and NPP Gamma, that allegedly supported the unit’s offensive cyber operations. It also listed several French targets attacked by the FSB, including government ministry systems in 2014; the network of the French Embassy in Moscow in 2018; and a research institute working with the French defense industry in February 2025 from which a significant volume of data was stolen.
French authorities also said one of the newly sanctioned groups had claimed responsibility for destabilization efforts targeting the 2024 Paris Olympic and Paralympic Games. France said it would use all available means to respond to malicious cyber activity ahead of its 2027 elections. French Foreign Minister Jean-Noël Barrot added Monday that he would summon Russian Ambassador Aleksey Meshkov in the coming days. Barrot accused Russian security services of conducting cyberattacks for espionage and sabotage in about 10 European countries, including France, targeting government ministries, companies and operators of critical services.
The United Kingdom also sanctioned individuals behind the Lumma Stealer malware, which steals credentials from infected computers and has become one of the world’s most widely used information-stealing tools. British officials said Russia has used credentials stolen by Lumma to support espionage operations worldwide. According to the National Crime Agency, more than 2,100 victims in the U.K. have been infected by Lumma Stealer in the past six months.
The sanctions package also targets 10 individuals associated with the pro-Kremlin military blog Rybar, including senior executives and content creators. Britain accused the outlet of spreading disinformation about Ukraine and interfering in elections in Moldova and Armenia. The Kremlin has repeatedly denied engaging in offensive cyber operations. Russian President Vladimir Putin said last month European allegations of Russian sabotage and cyberattacks were baseless and aimed at justifying their own “aggressive plans” against Russia.
