DOCUMENTING HYBRID WARFARE / — incidents / UPDATED LATEST: 
Sabotage Watch SABOTAGEWATCHHybrid Threat Monitor
Cyber

EU and UK sanction FSB Centre 16 over a decade of cyber operations against European critical infrastructure

13 July 2026 · Brussels, Belgium
Satellite Imagery © Esri

What happened

On 13 July 2026 the Council of the European Union listed nine individuals and four entities under its cyber sanctions regime for attacks and destabilising activities directed against the European Union and its member states, imposing asset freezes and travel bans. The United Kingdom acted the same day against 24 individuals and entities.

The measures publicly attributed the long-running Turla espionage operation, also tracked as Secret Blizzard and Waterbug, to the 16th Centre of Russia's Federal Security Service. According to the accompanying statements, reported by CyberScoop and Euronews, the unit has run operations since at least 2010 against government bodies and critical infrastructure in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland. The cited activity includes espionage against French state institutions, targeting of the French defence industry since 2025 and destructive operations against Polish critical infrastructure, among them an attack on Poland's power grid reported to have put supply to around half a million people at risk.

EU High Representative Kaja Kallas said Russia-linked cybercriminals, self-declared hacktivists and private companies had carried out malicious activities. UK Foreign Secretary Yvette Cooper said the sanctions struck at the core of the cybercriminal networks supporting Russian state aggression.

Assessment

This is the first time the European Union has formally named FSB Centre 16 as the body behind Turla, and the first fully coordinated EU and UK package aimed at Russia's cyber ecosystem. A sanctions listing is an executive determination by governments based on intelligence, not a judicial finding, and none of those named has been tried. The direct effect is limited to asset freezes and travel bans, but the naming lowers the political cost of future attribution and puts a decade of intrusions into European government and energy networks on the record.

This dossier summarises open-source reporting and is updated as the investigation develops. Read the original report via the source link.