> ## Content Index
> Fetch the complete content index at: https://www.russianhackers.co/llms.txt
> Use this file to discover other available public pages before exploring further.

# The EU and UK Hit Russia With Their First Joint Cyber Sanctions
- URL: https://www.russianhackers.co/eu-uk-first-joint-cyber-sanctions-fsb-turla/
- Published: 2026-07-15T14:44:39.000Z
- Updated: 2026-07-15T16:31:21.000Z
- Description: The sanctions target FSB Centre 16, the arm of Russian intelligence behind one of the world's most durable hacking operations, over a decade of attacks on Europe including an attempt to black out Poland in winter.
- Author: Martin
- Tags: News, Hackers

On July 13, 2026, the European Union and the United Kingdom imposed their first joint package of cyber sanctions on Russia. The target is the arm of Russian intelligence that the two governments say runs the Turla espionage group: Centre 16 of the FSB. Both trace its campaign against European targets back to 2010.

## Who is under sanction

The EU publicly attributed years of network intrusions and infrastructure sabotage to FSB Centre 16 (also cited as the 16th Center and linked to military unit 61240). According to the EU, this directorate runs Turla, also known as Secret Blizzard and Waterbug, one of the longest-lived state hacking groups. Its European campaign began in 2010 with French government networks and has since been linked to intrusions in Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland.

## A decade of targets

The sanctions cite specific operations. In 2017 the group tried to break into email accounts at the French Defense Ministry. In 2018 it hit the French Embassy in Moscow, and in 2019 it breached a secure server in France's national judicial system. In 2025 it stole data from a research institute tied to the French defense industry. The most alarming episode on the list is a failed attack in December 2025 on Poland's power grid, which the two governments say could have cut electricity to 500,000 people in the depth of winter.

## State intelligence meets cybercrime

The package reaches well beyond the intelligence unit itself. Those sanctioned include the hosting company Media Land LLC and its ML.Cloud service, accused of providing the server infrastructure behind ransomware and phishing; Z-Pentest, a pro-Russian hacktivist group that has gone after water and energy utilities; and the firm Impuls, tied to GRU Unit 29155, along with a senior officer from that unit, Ivan Kasyanenko. The EU and UK also named malware developers linked to Trickbot, [Conti](https://www.russianhackers.co/fake-fsb-officer-conti-extortion/) and the LummaC2 stealer, drawing a direct line between the Russian state and the criminal underground.

## The measures and the reaction

The EU listed nine individuals and four entities; the UK designated 24 names. In practice the measures mean asset freezes and travel bans. EU High Representative Kaja Kallas made the attribution to Centre 16 public. UK Foreign Secretary Yvette Cooper said the Russian state was "sinking to new lows in its attempts to undermine European security," citing everything from directing criminals to striking Poland's grid in the depths of winter.

*Based on statements from the EU Council and the UK Foreign Office, and reporting by CyberScoop, France 24 and BleepingComputer.*