The EU and UK Hit Russia With Their First Joint Cyber Sanctions
The sanctions target FSB Centre 16, the arm of Russian intelligence behind one of the world's most durable hacking operations, over a decade of attacks on Europe including an attempt to black out Poland in winter.
On July 13, 2026, the European Union and the United Kingdom imposed their first joint package of cyber sanctions on Russia. The target is the arm of Russian intelligence that the two governments say runs the Turla espionage group: Centre 16 of the FSB. Both trace its campaign against European targets back to 2010.
Who is under sanction
The EU publicly attributed years of network intrusions and infrastructure sabotage to FSB Centre 16 (also cited as the 16th Center and linked to military unit 61240). According to the EU, this directorate runs Turla, also known as Secret Blizzard and Waterbug, one of the longest-lived state hacking groups. Its European campaign began in 2010 with French government networks and has since been linked to intrusions in Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland.
A decade of targets
The sanctions cite specific operations. In 2017 the group tried to break into email accounts at the French Defense Ministry. In 2018 it hit the French Embassy in Moscow, and in 2019 it breached a secure server in France's national judicial system. In 2025 it stole data from a research institute tied to the French defense industry. The most alarming episode on the list is a failed attack in December 2025 on Poland's power grid, which the two governments say could have cut electricity to 500,000 people in the depth of winter.
State intelligence meets cybercrime
The package reaches well beyond the intelligence unit itself. Those sanctioned include the hosting company Media Land LLC and its ML.Cloud service, accused of providing the server infrastructure behind ransomware and phishing; Z-Pentest, a pro-Russian hacktivist group that has gone after water and energy utilities; and the firm Impuls, tied to GRU Unit 29155, along with a senior officer from that unit, Ivan Kasyanenko. The EU and UK also named malware developers linked to Trickbot, Conti and the LummaC2 stealer, drawing a direct line between the Russian state and the criminal underground.
The measures and the reaction
The EU listed nine individuals and four entities; the UK designated 24 names. In practice the measures mean asset freezes and travel bans. EU High Representative Kaja Kallas made the attribution to Centre 16 public. UK Foreign Secretary Yvette Cooper said the Russian state was "sinking to new lows in its attempts to undermine European security," citing everything from directing criminals to striking Poland's grid in the depths of winter.
Based on statements from the EU Council and the UK Foreign Office, and reporting by CyberScoop, France 24 and BleepingComputer.
Written by
Read next
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack
On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
Crypto Theft Fell to $972M in H1 2026, but North Korea's Share Climbed to Two-Thirds
In the first half of 2026, attackers stole about $972 million from the cryptocurrency industry across 207 incidents, according to a mid-year report from analytics firm TRM Labs. The figure is down by more than half from the same period in 2025, when losses were put at $2.3 billion. Despite the overall decline, the share tied to North Korea has actually grown. Analysts attribute roughly $643 million, about 66% of the half-year total, to the Lazarus Group and its TraderTraitor subunit. Almost all
Fake FSB Officer Tried to Shake Down the Conti Ransomware Gang
A Moscow man allegedly posed as an FSB officer and demanded money from one of the most dangerous ransomware crews in history. He is now in jail.
$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out
In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack
On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday
Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl