The FSB's Lubyanka Building in Moscow has been linked to a cyberattack on Poland's energy grid, which threatened to cut heating to half a million people last winter. The United Kingdom and European Union have imposed their first coordinated package of cyber sanctions against Russian hackers, blaming Center 16, the FSB’s signals intelligence arm, for acts of attempted cyber sabotage targeting Poland’s energy sector and water treatment facilities.
Russia's Cyber Sabotage
The allies have accused Center 16 of a wide range of malicious cyber activities with growing severity, including infiltration of governmental networks and sabotage of critical infrastructure targeting several European countries, including France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.
Poland's Energy Grid Attack
Last December’s attack on Poland’s energy grid came “very close” to causing a “blackout,” according to a senior minister. The attack was described as “reckless” by British authorities, who added that it was “another example of the Russian state’s irresponsible attempts to sow chaos across Europe.”
Initial attributions by cybersecurity companies ESET and Dragos had attributed the attack to a group tracked as Sandworm, linked to Russia’s military intelligence agency. However, this was disputed by CERT Polska, who traced the infrastructure behind the intrusion and matched it to a cluster linked to the FSB.
Sanctions and Condemnation
The EU has strongly condemned Russia’s behavior and misuse of the cyber ecosystem, targeting public services and critical infrastructure, causing disruptions and financial losses. The sanctions target more than 30 individuals and entities across Russia’s cyber ecosystem, including intelligence officers, private companies accused of recruiting hackers from Russian universities, and operators behind the Lumma Stealer credential-theft malware.
France has imposed additional sanctions and will summon the Russian ambassador over what it described as “persistent malicious cyber activities for espionage purposes.” A technical report from France’s Cyber Crisis Coordination Center detailed Center 16’s operations and identified 11 interception centers used by the agency’s signals intelligence arm across Russia.
International Response
The joint cybersecurity advisory published by the United States and co-signed by intelligence and security agencies from a dozen allied countries warned that Russian operators from Center 16 were scanning the internet for devices protected by default or weak credentials. The United Kingdom also sanctioned individuals behind the Lumma Stealer malware, which steals credentials from infected computers and has become one of the world's most widely used information-stealing tools.
British Foreign Secretary Yvette Cooper said the sanctions are intended to disrupt the cybercriminal ecosystem supporting Moscow's intelligence services. “These sanctions strike at the core of the cybercriminal networks propping up the Russian state's aggression, and the U.K. and EU are sending a clear message that Russia cannot hide behind its use of these proxy groups,” Cooper said.
The sanctions package also targets 10 individuals associated with the pro-Kremlin military blog Rybar, including senior executives and content creators. Britain accused the outlet of spreading disinformation about Ukraine and interfering in elections in Moldova and Armenia.
Russia's Denial
The Kremlin has repeatedly denied engaging in offensive cyber operations. Russian President Vladimir Putin said last month that European allegations of Russian sabotage and cyberattacks were baseless and aimed at justifying their own “aggressive plans” against Russia.
Source: The Record