The United Kingdom and European Union imposed their first joint cyber sanctions package against Russian state operators, proxy hackers, and influence actors, formally attributing an attempted attack on Poland’s energy grid to Russia’s FSB Centre 16. Officials said the failed operation could have cut electricity to as many as 500,000 people during winter, and linked the same Russian cyber ecosystem to intrusions targeting water treatment facilities, government networks, defense organizations, and other critical infrastructure across Europe. The EU also publicly identified the FSB’s 16th Centre as controlling several threat groups, including Turla, and cited a failed attack on Poland’s critical infrastructure.
The sanctions cover 24 individuals and entities, including GRU leaders Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko, as well as IMPULS, which Western officials said helped GRU Unit 29155 recruit hackers and cyber specialists. The package also targets operators tied to Lumma Stealer, which UK authorities said has been used to harvest stolen credentials for espionage and affected at least 2,100 UK victims in six months, and 10 people linked to Rybar LLC, accused of supporting pro-Kremlin disinformation and election interference in Moldova and Armenia. France separately announced additional sanctions, released a technical report on Centre 16 activity, and said it would summon the Russian ambassador over ongoing cyber espionage and sabotage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The UK NCSC and international partners released a joint advisory warning that sectors including energy, communications, defense, finance, government, and healthcare face elevated risk from FSB Centre 16 activity. The advisory described the actor's abuse of weak SNMP configurations and Cisco Smart Install and recommended disabling SNMPv1/v2, moving to SNMPv3 with authPriv, and disabling Cisco Smart Install.
As part of the sanctions action, the EU publicly identified the FSB's 16th Centre as controlling several threat groups, including Turla. Officials linked these Russian-linked actors to cyberespionage and sabotage activity across Europe.
The UK and EU announced a coordinated sanctions package targeting Russian state actors, proxy cybercriminals, and disinformation operators. Those sanctioned included GRU officers, IMPULS, actors tied to Lumma Stealer, and individuals linked to Rybar LLC.
A cyberattack targeting Poland's energy grid was blocked in December. UK and EU officials later said the failed operation could have left up to 500,000 people without electricity in winter.
France announced additional sanctions, published a technical report on Center 16's operations, and said it would summon the Russian ambassador. French officials said the move responded to persistent cyber espionage and sabotage activity.
The United Kingdom and European Union publicly attributed the attempted cyber sabotage against Poland's energy sector to Russia's FSB Centre 16. The attribution also tied the actor to broader targeting of government networks and critical infrastructure across Europe.
A 29 December 2025 cyberattack in Poland was reported to have used previously unseen OT-focused data-wiping malware against more than 30 wind and solar farms, a combined heat and power plant, and a manufacturing company. The attack did not disrupt electricity or heat supply.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
occrp.org
Open sourcecyberveille.ch
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourceconsilium.europa.eu
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.