The European Union and the United Kingdom have jointly imposed sanctions on Russian GRU officers and cybercriminals. The move targets a network of hacking groups accused of orchestrating large‑scale attacks on European critical infrastructure.
Key Takeaways
- EU and UK sanction 33 Russian individuals and entities
- Senior GRU officers and multiple cyber‑crime groups are named
- Sanctions aim to deter attacks on critical infrastructure and protect European security
The Council of the European Union announced today sanctions on nine individuals and four entities, explicitly naming Russian military intelligence (GRU) officers and organized cyber‑criminal networks. In parallel, the United Kingdom imposed its own measures on 24 people and entities, including senior GRU figures Vyacheslav Stafeyev, Ivan Senin and Ivan Kasyanenko, accused of directing cyber and hybrid operations.
Scope of the Joint Sanctions
Britain also targeted members of the IMPULS firm, alleged to recruit hackers from Russian universities, as well as actors linked to the Lumma Stealer malware campaign, which UK authorities say affected over 2,100 domestic victims in six months. Ten individuals associated with media outlet Rybar LLC were designated for disseminating anti‑Ukraine narratives and alleged election interference in Moldova and Armenia.
GRU‑Controlled Cyber Threat Groups
The EU Council publicly identified the 16th Centre of Russia’s Federal Security Service (FSB) as the command hub for several threat groups, notably the notorious Turla hacking group. Turla has been active since 2010, targeting government networks and critical infrastructure in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland. A recent failed strike on Poland’s energy grid, linked to Turla, could have left roughly 500,000 citizens without power during winter.
EU’s Official Statement
“Cybercriminals, self‑proclaimed hacktivists and private companies linked to Russia, including actors operating under its instructions, direction or control, have also carried out, enabled and facilitated a wide range of malicious activities. We strongly condemn Russia’s behaviour and misuse of this cyber ecosystem, targeting public services and critical infrastructure, causing disruptions and financial losses,” the Council said. The EU added that the restrictive measures are part of a broader effort to protect member states and international partners from destabilising Russian cyber operations.
Background and Future Outlook
In late December 2025, a cyber‑attack on Poland’s power grid, attributed to the state‑backed Sandworm group, deployed the destructive DynoWiper malware, damaging key operational technology (OT) equipment. More recently, Poland thwarted an attack on the National Centre for Nuclear Research (NCBJ), underscoring the heightened threat environment. These sanctions follow the European Commission’s January proposal for new cybersecurity legislation aimed at fortifying defenses against state‑sponsored threat actors targeting European critical infrastructure.