Western intelligence agencies have for the first time publicly identified a specialized Russian cyber unit responsible for a sustained campaign of espionage and sabotage targeting critical infrastructure across Europe. The European Union and Britain jointly announced sanctions against individuals and entities linked to the 16th Center of Russia’s Federal Security Service, a shadowy group accused of orchestrating attacks on power grids, defense networks, and government systems for over ten years.
The sanctions, which include asset freezes and travel bans on nine people and four organizations, aim to disrupt a sprawling network that blends state intelligence operations with criminal hacking groups. British officials revealed that the same unit attempted to disable Poland’s electricity grid, a move that could have cut power to half a million people during winter. French authorities separately identified a subunit, Unit 61240, as responsible for breaches of the Defense Ministry, the embassy in Moscow, and judicial servers.
Among the blacklisted entities are tech firms Media Land LLC and ML.Cloud, accused of leasing servers to ransomware gangs, as well as the pro-Kremlin hacktivist group Z-Pentest, which targeted water and energy utilities. The list also includes developers of malware like Trickbot and Conti, alongside Ivan Kasyanenko, a senior GRU officer tied to assassination squads.
NATO officials warned that Moscow increasingly relies on a mix of official spies, criminal proxies, and private companies to wage a quiet digital war aimed at destabilizing Western allies. The exposure of this unit marks a rare formal attribution of state-backed cyber operations, as Europe braces for further hybrid attacks.