The United Kingdom and European Union have jointly attributed last December’s cyberattack on Poland’s electricity grid to Russia’s Federal Security Service, formally naming FSB Center 16 — the service’s signals intelligence arm — as responsible for an attempted act of infrastructure sabotage that came within reach of cutting heating to roughly half a million people in the middle of winter. Monday’s announcement marks the first time the UK and EU have coordinated a cyber sanctions package against Russia, a shift that signals the two blocs are treating cyber-enabled infrastructure attacks as a category of threat that warrants a joint diplomatic response.
What Happened
The attack struck Poland’s energy sector in December 2025 and, according to a senior Polish minister at the time, came “very close” to causing a large-scale blackout. Beyond the electricity grid, FSB Center 16 was also linked to intrusions targeting Polish water treatment facilities — a sector that Polish domestic intelligence warned in May carried “a direct risk” to the continuity of water supply.
Initial technical attribution from ESET and Dragos pointed to Sandworm, the GRU-linked group responsible for Ukraine’s 2015 and 2016 grid attacks. That attribution was disputed by CERT Polska, whose infrastructure tracking linked the intrusion to a cluster associated with Center 16 rather than GRU military intelligence. Monday’s formal statement from the UK and EU adopted the FSB attribution.
The Sanctions Package
The coordinated measures target more than 30 individuals and entities across what EU foreign policy chief Kaja Kallas described as Russia’s “cyber ecosystem” — an umbrella spanning intelligence services, private companies, criminal groups, and hacktivists that Moscow uses for operations against European targets.
Specific named entities include operators behind the Lumma Stealer credential-theft malware operation, which has been widely deployed as an initial access tool across financial, healthcare, and government targets in Europe and North America. Individuals connected to the pro-Kremlin Rybar blog, which coordinates information operations in parallel with cyber activity, were also sanctioned.
The EU statement cited infiltration of governmental networks and sabotage of critical infrastructure targeting France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland as part of FSB Center 16’s documented activity profile. UK authorities described the Poland attack as “reckless” and called it another instance of “the Russian state’s irresponsible attempts to sow chaos across Europe.”
Why This Matters for Critical Infrastructure Operators
The formal UK-EU attribution of the Poland grid attack consolidates a picture that threat intelligence teams were already working with: FSB Center 16 is conducting deliberate pre-positioning and disruptive operations against European energy and water infrastructure, not just opportunistic espionage. The initial mis-attribution to Sandworm reflects a genuine intelligence challenge — overlapping TTPs, shared tooling, and Russia’s deliberate effort to obscure the operational boundaries between GRU and FSB cyber units.
The joint sanctions package is significant beyond its immediate targets. It represents the first time the UK and EU have synchronised a cyber-specific sanctions action, and it extends the target set to include private sector facilitators — companies that recruit hackers, infrastructure providers, and malware-as-a-service operators — rather than limiting sanctions to intelligence officers directly. That expansion of scope signals a deliberate attempt to raise the cost of Russia’s outsourced cyber model.
Recommended Actions
Energy and utilities operators in EU member states and the UK should treat the formal attribution as a prompt to review network segmentation between IT and OT environments, verify offline backup procedures for operational technology, and confirm incident response plans for scenarios involving heating and water supply disruption — the two systems directly targeted in the Polish campaign.
Security teams should note that Lumma Stealer’s sanctioned operators do not mean the malware is inactive. Lumma remains a high-volume threat distributed through phishing, malvertising, and cracked software channels. Credential harvesting from Lumma-infected endpoints has preceded access broker sales and subsequent ransomware deployment in documented incident chains.
Threat intelligence functions should update attribution frameworks to distinguish FSB Center 16 activity from Sandworm more precisely. The infrastructure indicators and TTPs associated with Center 16 differ from GRU toolsets and the distinction matters for response and notification obligations.