/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The UK accuses a unit of Russia's FSB of using cyberattacks in a “sustained but unsuccessful” campaign to undermine democratic institutions since 2015

The British government accused a unit of Russia's Federal Security Service (FSB) on Thursday of using cyberattacks in a …

The Record Alexander Martin

Context & Ripple Effects

This accusation extends a documented UK pattern: the National Cyber Security Centre had previously linked Russian activity to attacks on British media, telecoms and energy sectors in its earlier warning on attacks across critical sectors.

It also sits alongside European efforts to publicly assign responsibility for influence-oriented cyber operations, including the EU's attribution of the Ghostwriter hack-and-leak campaign to the Russian government and its state hackers.

First-order effects

  • British democratic institutions and the FSB unit named by the government face a sharper public attribution, raising the operational and reputational cost of any continued activity.
  • The disclosure gives UK defenders a clearer basis to prioritize detection and hardening around the tactics associated with the alleged campaign.

Second-order effects

  • The subsequent joint US-UK allegation of a broader FSB campaign targeting UK elections and US networks turns a domestic attribution into a shared allied security concern, encouraging intelligence and defensive coordination.
  • Organizations beyond electoral bodies—especially operators of sensitive public-facing systems—have reason to treat intrusion and influence risks as connected rather than separate threats.

Third-order effects

  • If allied governments continue pairing detailed attribution with coordinated warnings, state-backed cyber activity is likely to be handled less as isolated espionage and more as a persistent threat to democratic and critical institutions.
  • The pattern points toward cyber resilience becoming a continuing institutional requirement for democracies, although the reported lack of success does not establish how effective future operations may be.

The trend: Public, allied attribution is becoming a core tool for countering long-running state-backed cyber operations aimed at democratic institutions.

Discussion

  • @msftsecintel @msftsecintel on x
    Microsoft continues to track and disrupt activity attributed to a Russian state-sponsored actor we track as Star Blizzard (SEABORGIUM), who has improved their evasion capabilities since 2022 while remaining focused on email credential theft. Get TTPs: https://aka.ms/...
  • @sixdub Justin on x
    Microsoft Threat Intelligence is sharing additional intelligence on Star Blizzard (overlaps Calisto / ColdRiver), who is active in espionage and IO. UK NCSC has just attributed them to FSB Center 18. The blog details ongoing campaigns and evasion https://www.microsoft.com/...
  • @imincorrigible @imincorrigible on x
    “The group linked to the FSB - and specifically the part of it known as Centre 18 - has been targeting the UK by stealing information from those in political and public life since at least 2015, it is believed. It is claimed the group remains active” Still no mention of Brexit.
  • @gordoncorera Gordon Corera on x
    NEW - The Russian Ambassador to the UK has been summoned as Moscow's FSB Security Service is accused of a sustained campaign to interfere in political life by hacking and stealing emails and data from those in public life. UK officials say the campaign has been unsuccessful.
  • @gordoncorera Gordon Corera on x
    Centre 18, a unit within FSB, identified as being accountable for a range of cyber espionage operations. Also known as Star Blizzard; Callisto Group, SEABORGIUM or COLDRIVER and is operated by FSB officers. One serving FSB officer is being sanctioned by UK.
  • @danwblack Dan Black on x
    Notable the US-UK trade leaks were confidently linked to COLDRIVER (and by extension, Center 18 of the FSB) in the briefing. Begs the question of whether the FSB is also responsible for Secondary Infektion (the series of forged letters that overlap tactically with the leaks)
  • @dmitryopines Dmitry Grozoubinski on x
    Putin: “Congratulations Comrade, you have succeeded in plunging the UK government into more chaos than I could have dreamed. Tell me, how did you do it?” FSB agent who spent the last ten years playing Angry Birds on his phone: [image]
  • @jimmysecuk Jimmy Rushton on x
    This is also long awaited official confirmation that Jeremy Corbyn did use documents stolen by the FSB during the 2019 general election. At the time, he called such claims “nonsense” and “conspiracy theories”, whilst refusing to reveal who had provided them to his campaign. [imag…
  • @mike_eckel Mike Eckel on x
    👀"Centre 18, a unit within Russia's FSB, has been identified as being accountable for a range of cyber espionage operations targeting the UK." https://www.gov.uk/... [image]
  • @eliothiggins Eliot Higgins on x
    Details of the various FSB hacks over the last 8 years, including the Institute for Statecraft hack that's continually used by certain people to attack Bellingcat, even though we've never had anything to do with them. https://www.gov.uk/... [image]