Digital front

Russia’s cyberwar is now out in the open: watch out for ports and the energy sector

In recent months, France, Germany, the UK and Brussels have directly accused the FSB and GRU of being linked to cyber-attacks on sensitive infrastructure. The ACN and the Coastguard also took part in the recent exercise, ‘Cyber Europe 2026’, coordinated by ENISA. This is a sign that the Mediterranean front needs to be monitored

6' min read

Translated by AI
Versione italiana

6' min read

Translated by AI
Versione italiana

On 13 July, Europe took a step forward, stepping up its rhetoric against the cyber world linked to Moscow. The European Union directly attributed to the FSB’s 16th Centre a campaign carried out via the TURLA group, cybercriminals, private companies and pseudo-hacker groups; France has identified Unit 61240 as responsible for operations targeting national strategic interests; NATO has described these activities as a threat to allied security; London has set its sights on GRU officers, front companies, malware developers and criminal infrastructure. This is no longer the story of individual hackers. It is the emergence of an industrial-scale operation capable of turning a stolen password, a vulnerable router or a small supplier into access to ministries, arsenals, energy grids, ports and election campaigns.

The sabotage supply chain

The Russian model works because it separates responsibility from capability. The FSB conducts long-term espionage; the GRU integrates cyber operations, military intelligence and hybrid actions; private companies recruit technicians and manage servers; ransomware groups generate access, revenue and disruptions; malware such as Lumma Stealer steals passwords, session cookies and cloud credentials; bulletproof hosting services keep infrastructure online that is resistant to requests from the authorities; ‘hacker’ groups claim responsibility for attacks and provide political deniability.

Loading...

The UK is reported to have identified Vyacheslav Stafeyev, Ivan Senin and Ivan Kasyanenko, and has pieced together the links between the cyber division of Unit 29155, cybercriminals and the company also used to recruit hackers and specialists from Russian universities and academies. London has also linked credentials stolen from Lumma to Russian espionage activities and identified at least 2,100 British victims over a six-month period. The strength of this architecture lies in its versatility. A criminal infection can become an intelligence access point; a ransomware attack can conceal the mapping of recovery procedures; a DDoS attack can distract defenders whilst another team penetrates the network; a sanctioned company can change its name, hosting provider and jurisdiction. Moscow does not need to monitor every operator every day: it must be able to protect, fund, recruit or utilise them when their access becomes strategically useful.

The Espionage Laboratory

France has demonstrated precisely what the FSB is after. Paris has attributed to Unit 61240 the compromise, since 2017, of email accounts belonging to the Ministry of the Armed Forces; in 2018, of the diplomatic network of the French Embassy in Moscow; in 2019, a server belonging to the justice system via a SharePoint vulnerability; and in February 2025, an institute working on sensitive defence technologies, from which a significant amount of data is said to have been exfiltrated. This sequence is no coincidence. Military emails reveal personnel, programmes and doctrine; diplomatic networks reveal confidential reports and negotiating positions; judicial systems contain identities and investigations; technology institutes expose patents, suppliers and industrial capabilities. France is a priority target because it brings together nuclear deterrence, the aerospace industry, shipbuilding, space, diplomacy and strategic autonomy.

The industrial multiplier

Germany is the European target with the greatest potential for economic disruption. An attack on a single German supplier can bring production facilities in several countries to a standstill, as the automotive, chemical, mechanical engineering, electronics, defence and logistics sectors all depend on thousands of highly specialised Mittelstand companies. The BSI (Bundesamt für Sicherheit in der Informationstechnik) described a persistently critical situation in 2025. Official figures reported around 950 ransomware attacks, with approximately 80 per cent of reported cases affecting small and medium-sized enterprises. The key strategic factor is the concentration of unique expertise within companies that are often unable to afford the same level of security investment as large corporations. Moscow could be seeking industrial designs, software, production capabilities, critical components, delivery times and bottlenecks in European rearmament. The most plausible entry points are IT suppliers, code repositories, remote maintenance, cloud accounts and engineering firms. To bring a factory to a standstill, there is no need to take control of a robot: it is enough to encrypt planning, stock, quality control or logistics data. Germany also serves as NATO’s land bridge. Railways, ports, freight terminals, fuel supplies, customs and civilian transport operators support the movement of troops towards Poland and the Baltic states. A disruption lasting just a few hours during a deployment would have greater military value than a much longer commercial blackout.

The risk of concentration

The United Kingdom, for its part, combines nuclear deterrence, intelligence, global finance, cloud computing, data centres and critical infrastructure – much of which is privately owned. During the 2024–2025 cycle, the National Cyber Security Centre received 1,727 reports, opened 429 incidents requiring direct assistance, and classified 204 cases as nationally significant and 18 as highly significant; there had been 89 nationally significant cases the previous year. The most valuable targets could be the Dreadnought submarine programme, AUKUS, the Global Combat Air Programme with Italia and Japan, defence suppliers, the City, telecommunications, the healthcare system and data centres. London has classified the latter as critical national infrastructure because they underpin healthcare services, finance, public administration and entire digital supply chains.

The risk here is concentration: a single dominant entity – be it a cloud provider, a management platform or a major supplier – can leave dozens of organisations vulnerable. The attack on a National Health Service supplier contracted by the UK government in 2025 led to the postponement of over 11,000 appointments and elective procedures, demonstrating how an external company can become a national point of failure.

The Mediterranean Front

Italia faces a different kind of vulnerability: fragmentation. Ports, energy, healthcare, transport, defence and local authorities depend on thousands of public and private entities with varying levels of security. The National Cybersecurity Agency recorded 1,253 cyber incidents in the second half of 2025, 30 per cent more than in the first half, whilst incidents affecting the healthcare sector rose by around 47.4 per cent compared with the previous year. Until now, the risk to ports has remained under the radar. Trieste, Genoa, La Spezia, Livorno, Naples, Taranto, Augusta, Ravenna and Gioia Tauro combine commercial, energy, naval and logistical functions. Access to these systems could reveal military movements, block gates, alter documentation or cause congestion without causing physical damage. The Italian Coastguard, as part of the ‘Maritime Cyber Risk’ project, defines cybersecurity as an essential component of maritime security and the protection of critical infrastructure. Furthermore, on 12 June 2026, the Ministry of Infrastructure and Transport and the ACN took part in Cyber Europe 2026, an exercise coordinated by ENISA that simulated large-scale cyber-attacks against European rail and maritime operators. This confirms that the scenario of a coordinated attack against maritime and rail transport is not merely a media construct: it is already being used by Italian and European authorities to test realistic crisis management. Another sensitive issue is the actual architecture of the port. A modern port is not synonymous with the Port System Authority. It is an ecosystem comprising terminal operators, shipping lines, freight forwarders, shipping agents, customs, border police, rail operators, road hauliers, warehouse managers, fuel suppliers, maintenance contractors, telecommunications companies and digital platforms. Operations rely on systems for berth planning, container handling, cargo manifests, gate control, vehicle recognition, customs authorisations and rail routing. It is this interdependence that makes lateral movement technically possible. Finally, there is the issue of energy. Italy’s diversification away from Moscow has geopolitical significance: gas pipelines, LNG terminals, storage facilities, electricity distribution and renewables demonstrate just how resilient Europe has become to Russian energy blackmail. Major operators have advanced defences; the weak points are maintenance staff, local distributors, suppliers’ VPNs, network equipment and legacy industrial systems. The healthcare sector and local authorities round out the landscape. A ransomware attack on a regional hospital or a local council does not need to cause a national catastrophe to have a strategic impact: it is enough to delay treatment, disrupt payments, block civil registry and public services, increase mistrust and drain state resources.

Brussels under scrutiny

The cloud, payments, data centres, satellites, energy and logistics are transnational; the response, however, remains largely national. It is in this gap – between the initial local alert and the recognition of a European-wide campaign – that Russia can manoeuvre. Sanctions and attributions are not enough. Europe should begin to consider the implementation of phishing-resistant authentication, supplier vetting, industrial segmentation, isolated recovery environments, manual capabilities, coordinated server seizures, the tracking of financial flows and joint NATO–EU responses. NATO has already stated that it is ready to use the full range of its capabilities against persistent cyber threats. However, the current perception of the problem is still far from envisaging direct NATO involvement.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti