Russia’s cyberwar is now out in the open: watch out for ports and the energy sector
In recent months, France, Germany, the UK and Brussels have directly accused the FSB and GRU of being linked to cyber-attacks on sensitive infrastructure. The ACN and the Coastguard also took part in the recent exercise, ‘Cyber Europe 2026’, coordinated by ENISA. This is a sign that the Mediterranean front needs to be monitored
by 24Ore NextMed
ai preferiti su Google
Key points
On 13 July, Europe took a step forward, stepping up its rhetoric against the cyber world linked to Moscow. The European Union directly attributed to the FSB’s 16th Centre a campaign carried out via the TURLA group, cybercriminals, private companies and pseudo-hacker groups; France has identified Unit 61240 as responsible for operations targeting national strategic interests; NATO has described these activities as a threat to allied security; London has set its sights on GRU officers, front companies, malware developers and criminal infrastructure. This is no longer the story of individual hackers. It is the emergence of an industrial-scale operation capable of turning a stolen password, a vulnerable router or a small supplier into access to ministries, arsenals, energy grids, ports and election campaigns.
The sabotage supply chain
The Russian model works because it separates responsibility from capability. The FSB conducts long-term espionage; the GRU integrates cyber operations, military intelligence and hybrid actions; private companies recruit technicians and manage servers; ransomware groups generate access, revenue and disruptions; malware such as Lumma Stealer steals passwords, session cookies and cloud credentials; bulletproof hosting services keep infrastructure online that is resistant to requests from the authorities; ‘hacker’ groups claim responsibility for attacks and provide political deniability.
The UK is reported to have identified Vyacheslav Stafeyev, Ivan Senin and Ivan Kasyanenko, and has pieced together the links between the cyber division of Unit 29155, cybercriminals and the company also used to recruit hackers and specialists from Russian universities and academies. London has also linked credentials stolen from Lumma to Russian espionage activities and identified at least 2,100 British victims over a six-month period. The strength of this architecture lies in its versatility. A criminal infection can become an intelligence access point; a ransomware attack can conceal the mapping of recovery procedures; a DDoS attack can distract defenders whilst another team penetrates the network; a sanctioned company can change its name, hosting provider and jurisdiction. Moscow does not need to monitor every operator every day: it must be able to protect, fund, recruit or utilise them when their access becomes strategically useful.
The Espionage Laboratory
France has demonstrated precisely what the FSB is after. Paris has attributed to Unit 61240 the compromise, since 2017, of email accounts belonging to the Ministry of the Armed Forces; in 2018, of the diplomatic network of the French Embassy in Moscow; in 2019, a server belonging to the justice system via a SharePoint vulnerability; and in February 2025, an institute working on sensitive defence technologies, from which a significant amount of data is said to have been exfiltrated. This sequence is no coincidence. Military emails reveal personnel, programmes and doctrine; diplomatic networks reveal confidential reports and negotiating positions; judicial systems contain identities and investigations; technology institutes expose patents, suppliers and industrial capabilities. France is a priority target because it brings together nuclear deterrence, the aerospace industry, shipbuilding, space, diplomacy and strategic autonomy.
The industrial multiplier
Germany is the European target with the greatest potential for economic disruption. An attack on a single German supplier can bring production facilities in several countries to a standstill, as the automotive, chemical, mechanical engineering, electronics, defence and logistics sectors all depend on thousands of highly specialised Mittelstand companies. The BSI (Bundesamt für Sicherheit in der Informationstechnik) described a persistently critical situation in 2025. Official figures reported around 950 ransomware attacks, with approximately 80 per cent of reported cases affecting small and medium-sized enterprises. The key strategic factor is the concentration of unique expertise within companies that are often unable to afford the same level of security investment as large corporations. Moscow could be seeking industrial designs, software, production capabilities, critical components, delivery times and bottlenecks in European rearmament. The most plausible entry points are IT suppliers, code repositories, remote maintenance, cloud accounts and engineering firms. To bring a factory to a standstill, there is no need to take control of a robot: it is enough to encrypt planning, stock, quality control or logistics data. Germany also serves as NATO’s land bridge. Railways, ports, freight terminals, fuel supplies, customs and civilian transport operators support the movement of troops towards Poland and the Baltic states. A disruption lasting just a few hours during a deployment would have greater military value than a much longer commercial blackout.

