Lead story
Russia's FSB Attacked Poland's Power Grid. Now Europe Is Hitting Back With Sanctions.
On Sunday, the European Union and the United Kingdom jointly attributed a cyberattack on Poland's energy infrastructure to Center 16 — the FSB's signals intelligence arm — and immediately followed that attribution with a coordinated sanctions package. It's the first time the two blocs have imposed joint cyber sanctions, and the timing is pointed: the attack in question reportedly came close to cutting power to half a million Poles in the depths of winter.
What actually happened to Poland's grid?
The attack targeted both energy sector networks and water treatment facilities, according to the joint statement. The EU's broader accusations also rope in Turla — Russia's long-running espionage group — for a "wide range of malicious cyber activities with growing severity." The sanctions name specific Russian intelligence officers and entities with alleged links to the operations.
The attribution to Center 16 matters because it puts this firmly in the FSB's signals intelligence lane, rather than GRU sabotage units like Sandworm. Analysts have been watching for FSB expansion into destructive operations; this, if accurate, suggests the lines between espionage and sabotage are continuing to blur inside Russian intelligence.
Why coordinated attribution?
The joint EU-UK action is the more interesting development here. Post-Brexit, the two have often struggled to coordinate on foreign policy. A unified public attribution — complete with matching sanctions — signals that European cyber defence cooperation is holding up better than some predicted. The move follows a playbook the Five Eyes have been building out for years: name, shame, and sanction in near-simultaneous public statements to maximise political pressure.
Separately, the US government issued a fresh advisory this week warning that Russian state hackers are actively targeting network devices — routers specifically — to build residential proxy networks that obscure their infrastructure. CISA and Cisco's intelligence teams flagged critical infrastructure sectors including defence, communications, energy, finance, government, and healthcare as priority targets. The timing alongside the Poland attribution is almost certainly not a coincidence.
What to watch
First, whether Poland's attribution (Warszawa has been notably quiet on publicly naming Russia despite being the victim) aligns with the EU-UK position. Second, whether the US adds its own public attribution — Washington has a habit of joining allied cyber attribution statements and notably wasn't in the joint press release. Third, whether these sanctions translate into any real operational disruption for Center 16, or whether they remain largely symbolic.
The Australian angle
Australia sits in the Five Eyes and regularly co-signs these kinds of attribution statements, often through the Australian Signals Directorate. There's no indication Canberra has joined this particular statement yet, but watch for an ASD advisory in the coming days — the pattern on previous joint attributions (NotPetya, Volt Typhoon) has been AU joining within 24-48 hours. The CISA router advisory also carries direct relevance: ACSC has issued equivalent guidance on router security in the past, and Australian critical infrastructure operators under the SOCI Act would be well-advised to treat the US advisory as applicable here too.
