Swedish prosecutors ended their investigation into the 2017 intrusion at the Swedish Sports Confederation after concluding that legal constraints prevented charges against the suspected operators, who were identified as acting on behalf of the Russian state. The Swedish Prosecution Authority, drawing on findings from the Swedish Security Service and foreign intelligence partners, attributed the breach to Russia's GRU and specifically its 85th Main Special Service Center, also known as Unit 26165. Investigators said the attackers stole Swedish athletes' medical records during an intrusion that ran from December 2017 to May 2018.
The case was tied to a broader Russian anti-doping influence campaign that targeted sports organizations including WADA, USADA, and FIFA, with stolen data later published online to undermine Western athletes and sports bodies. The attribution aligns with U.S. Justice Department charges against six GRU officers over a global hacking and destructive malware campaign, which included operations linked to the same Russian military intelligence apparatus and its cyber activities against international sporting and anti-doping institutions.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Justice filed charges against GRU intelligence service members over related hacking activity tied to the broader campaign targeting sports and anti-doping organizations. The Swedish article cites this as having occurred in October 2018.
Swedish prosecutors said Russia's GRU, specifically its 85th Center (Unit 26165), intruded into the Swedish Sports Confederation between December 2017 and May 2018. The attackers stole Swedish athletes' medical records as part of a broader anti-doping influence campaign.
Swedish authorities dropped their investigation into the intrusion, saying legal constraints prevented prosecutors from charging operators acting on behalf of a foreign power. At the same time, the Swedish Prosecution Authority formally blamed the Russian government and GRU Unit 26165 for the breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.