The EU blacklists Russian intelligence group members it says were responsible for spying on and hacking targets across the EU and Ukraine from as early as 2010
Moscow's Federal Security Service is behind the cyber espionage and sabotage campaigns, EU says.
Politico
Context & Ripple Effects
The EU has previously publicly attributed the Ghostwriter hack-and-leak campaign to the Russian government, while reporting has also documented suspected Russian access to EU diplomatic systems and targeting of European policy and research organizations.
This blacklist extends that pattern from public attribution to named intelligence-group members. It arrives amid EU cybersecurity officials’ warnings that disruptive attacks tied to Russia-backed groups have increased.
First-order effects
The listed members of the group face immediate official identification by the EU as participants in a long-running espionage and sabotage campaign linked to the Federal Security Service.
EU institutions and member-state cyber authorities gain a clearer common attribution basis for treating related activity against EU and Ukrainian targets as a state-linked threat.
Second-order effects
The action raises pressure on member states to align threat intelligence, incident response, and protective measures around the identified Russian-linked activity rather than handle cases as isolated intrusions.
Organizations previously exposed to Russian-linked targeting—including EU bodies, research groups, and policy institutions—have further reason to prioritize monitoring for the group’s tactics and associated infrastructure.
Third-order effects
If the EU continues pairing cyber attributions with blacklists, cyber diplomacy is likely to become a more routine tool for imposing political costs on state-linked operators, even when technical disruption remains difficult.
The pattern also points to a more persistent security operating environment for European institutions: public attribution can improve coordination, but it is unlikely by itself to eliminate espionage or sabotage campaigns.
The trend: The move is part of the EU’s broader shift toward treating state-linked cyber operations as an enduring geopolitical threat that warrants coordinated public attribution and targeted sanctions.
Today, the NCSC, alongside international allies, has published a new advisory on defending against the threat from Russian state intelligence actors. To read more on the threat and how to mitigate it ⬇️ https://www.ncsc.gov.uk/... [image]
The EU and NATO statements have once again exposed Russia's malicious cyber activities. We call on Russia to immediately refrain from conducting cyberattacks and to respect international law. Read more ⤵️ https://www.gov.pl/...
Today, the EU adopted its cyber sanctions package and exposed malicious cyber actors in Russia, incl. the FSB. Finland condemns Russia's malicious cyber activities and the misuse of the cyber ecosystem. In response, I have summoned the Ambassador of the Russian Federation.
The EU today adopted its largest cyber sanctions package ever and exposed malicious actors within the Russian cyber ecosystem, including the FSB. Sweden and the EU will continue to deter and respond to Russia's threats to the EU and its Member states. https://www.consilium.europa…
Today, Ukraine joins the North Atlantic Council's Statement condemning Russia's malicious cyber activities. Russia's criminal war is fought not only on the battlefield in Ukraine. It also targets the critical infrastructure of Allies through malicious cyber operations,
Russia continues to conduct cyber-attacks against the EU, its Member States, and our partners. Today, the EU is exposing not only Russia FSB, but also the wider ecosystem of actors Russia relies on to carry out these attacks. We are also sanctioning individuals and entities who […
#ICYMI: Russian intelligence services continue to target current and former U.S. government and military officials, journalists, and other high-profile individuals by posing as support personnel on messaging apps like Signal and WhatsApp. These malicious cyber actors seek to [ima…
We're sanctioning Russia at speed and scale. Today's measures, together with the upcoming 21st sanctions package, will add 250 individuals and entities to the Russia sanctions regime. This is our biggest round of individual designations since Moscow's 2022 full-scale invasion, …
Bottomline: after a 6 months wait, a joint attribution and a bunch of sanctioned individuals. That's an awfully normal response to a worryingly unusual attack, if you ask me. What message do we think that sends? What Stringer Bell would call « a 40-degree day ». therecord.medi…
There are new Internet services sanctions in the UK: — https://www.gov.uk/... I've been through them, and I did not spot any new domains/URLs for blocking. — https://decoded.legal/...