It also sits alongside European efforts to publicly assign responsibility for influence-oriented cyber operations, including the EU's attribution of the Ghostwriter hack-and-leak campaign to the Russian government and its state hackers.
First-order effects
British democratic institutions and the FSB unit named by the government face a sharper public attribution, raising the operational and reputational cost of any continued activity.
The disclosure gives UK defenders a clearer basis to prioritize detection and hardening around the tactics associated with the alleged campaign.
Second-order effects
The subsequent joint US-UK allegation of a broader FSB campaign targeting UK elections and US networks turns a domestic attribution into a shared allied security concern, encouraging intelligence and defensive coordination.
Organizations beyond electoral bodies—especially operators of sensitive public-facing systems—have reason to treat intrusion and influence risks as connected rather than separate threats.
Third-order effects
If allied governments continue pairing detailed attribution with coordinated warnings, state-backed cyber activity is likely to be handled less as isolated espionage and more as a persistent threat to democratic and critical institutions.
The pattern points toward cyber resilience becoming a continuing institutional requirement for democracies, although the reported lack of success does not establish how effective future operations may be.
The trend: Public, allied attribution is becoming a core tool for countering long-running state-backed cyber operations aimed at democratic institutions.
Microsoft continues to track and disrupt activity attributed to a Russian state-sponsored actor we track as Star Blizzard (SEABORGIUM), who has improved their evasion capabilities since 2022 while remaining focused on email credential theft. Get TTPs: https://aka.ms/...
Microsoft Threat Intelligence is sharing additional intelligence on Star Blizzard (overlaps Calisto / ColdRiver), who is active in espionage and IO. UK NCSC has just attributed them to FSB Center 18. The blog details ongoing campaigns and evasion https://www.microsoft.com/...
“The group linked to the FSB - and specifically the part of it known as Centre 18 - has been targeting the UK by stealing information from those in political and public life since at least 2015, it is believed. It is claimed the group remains active” Still no mention of Brexit.
NEW - The Russian Ambassador to the UK has been summoned as Moscow's FSB Security Service is accused of a sustained campaign to interfere in political life by hacking and stealing emails and data from those in public life. UK officials say the campaign has been unsuccessful.
Centre 18, a unit within FSB, identified as being accountable for a range of cyber espionage operations. Also known as Star Blizzard; Callisto Group, SEABORGIUM or COLDRIVER and is operated by FSB officers. One serving FSB officer is being sanctioned by UK.
Notable the US-UK trade leaks were confidently linked to COLDRIVER (and by extension, Center 18 of the FSB) in the briefing. Begs the question of whether the FSB is also responsible for Secondary Infektion (the series of forged letters that overlap tactically with the leaks)
Putin: “Congratulations Comrade, you have succeeded in plunging the UK government into more chaos than I could have dreamed. Tell me, how did you do it?” FSB agent who spent the last ten years playing Angry Birds on his phone: [image]
This is also long awaited official confirmation that Jeremy Corbyn did use documents stolen by the FSB during the 2019 general election. At the time, he called such claims “nonsense” and “conspiracy theories”, whilst refusing to reveal who had provided them to his campaign. [imag…
👀"Centre 18, a unit within Russia's FSB, has been identified as being accountable for a range of cyber espionage operations targeting the UK." https://www.gov.uk/... [image]
Details of the various FSB hacks over the last 8 years, including the Institute for Statecraft hack that's continually used by certain people to attack Bellingcat, even though we've never had anything to do with them. https://www.gov.uk/... [image]