Posted

Russia expands its cyber war against Europe

From 24 to 26 August, Norway’s government digitalisation agency Digdir fended off a cyberattack that Norwegian officials described as the largest in recent months. The attack disrupted logins through ID-porten to dozens of government services, including MinID, Altinn and E-innsyn. According to Norwegian media, Digdir documents were also among the hackers’ targets. A pro-Russian group calling itself Server Killers claimed responsibility and explicitly linked the attack to Oslo’s signing of a strategic partnership agreement with Kyiv and to the continuation of financial support for Ukraine into 2027.

The fact that the hackers publicly stated a political motive, rather than disguising the operation as an attempt at financial gain, is unusual. Still, the incident is only one episode in a broader campaign by hacking groups linked to the Russian state. Over the past year these groups have significantly widened both the geography of their attacks and the scale of the damage they inflict. European governments now openly acknowledge the scope of this activity. On 13 July, French Foreign Minister Jean-Noël Barrot said Moscow had conducted a “large-scale cyber campaign” of sabotage and espionage against a dozen countries. The same day, the EU and the United Kingdom for the first time imposed a joint sanctions package on 24 individuals and organisations described as proxy networks of Russian intelligence services responsible for cyberattacks in Europe. Among those sanctioned were senior officers of Russian military intelligence (the GRU), Vyacheslav Stafeev, Ivan Senin and Ivan Kasyanenko.

August this year again confirmed the trend: in its hybrid war against Europe, Russia continues to scale up cyberattacks on government institutions. In Germany, the most high-profile episode of the summer was the attack on Berlin’s government network.

In late August, Governing Mayor Kai Wegner confirmed an extortion demand from the cyber group Rhysida, which operates on a ransomware-as-a-service model. The attack took place between 7 and 12 August and was detected on 14 August. Senate departments for transport, urban development and construction were then disconnected for several days from Berlin’s government network, Landesnetz. Official figures put the volume of stolen data at between 5.79 and 6 terabytes, including more than 46,500 contracts as well as passwords. The hackers demanded 30 bitcoin (about €2 million) in exchange for not publishing the data. The Berlin Senate refused to pay. There is no direct proof that Rhysida is tied to Russian intelligence services, but the geography of its attacks and the choice of targets point to links with the Russian milieu and possible state cover.

France, for its part, faced several cyberattacks of different kinds this summer. In August, an attack on the Directorate General of Public Finances (DGFiP) led to a leak of data on 678,000 taxpayers. The attackers obtained information on taxable income and the family status of individuals. Earlier, a cyberattack on France’s National Institute of Statistics and Economic Studies (INSEE) exposed the personal data of 12,800 current and former staff. In July, France officially attributed a multi-year cyber-espionage campaign against state institutions to the group Turla (also known as Snake, Uroburos, Secret Blizzard or Ceres), which specialists link to the FSB’s 16th Centre, also known as military unit 71330. Analysis of Turla’s methods indicates that the primary goal was not financial profit but the collection of intelligence. The group targeted not only ministries but also defence bodies, judicial institutions and leading technology companies.

Poland this year showed how vulnerable even the health sector can be. In August, Digital Affairs Minister Krzysztof Gawkowski reported a massive leak of personal data affecting nearly 19 million people after an attack on MyDr, a company that handles electronic medical records for hospitals. The incident came against the backdrop of Poland’s official accusation that Russia carried out a hacking campaign against the country’s energy sector in December 2025. According to Gawkowski, Russia then launched numerous attacks aimed at cutting off electricity, bringing the country to the brink of a major blackout.

Victims of Russia-linked cybercriminals are not limited to government agencies. Over the summer, the Russia-linked group Cl0p claimed to have stolen data from nearly 50 companies worldwide. Those affected included appliance maker Philips, energy group Shell, IT services firm Fiserv and industrial conglomerate General Electric. The attack illustrates a trend noted by cybersecurity analysts: instead of hitting a well-protected corporation directly, attackers increasingly go after a weaker contractor or software supplier. A single compromised link in the supply chain can then affect dozens of companies at once.

How systemic the cyber threat from Russia has become was shown by the annual study of Germany’s Bitkom association of information and telecommunications industries, presented on 26 August together with Sinan Selen, president of the Federal Office for the Protection of the Constitution (BfV). According to the survey, 96 percent of German companies polled in 2026 experienced data theft, industrial espionage or sabotage, or suspected they had become victims. Of those affected, 52 percent traced the attack to China and 49 percent to Russia, both figures up sharply from 46 percent for each country in 2025. Bitkom estimates the total annual damage to the German economy from such activity at €211–270.8 billion. In August, Politico reported that the European Union had for the first time officially confirmed attempts by hackers linked to foreign states to break into the messenger accounts of senior EU officials. Intelligence services in several EU countries had already warned of such campaigns. Dutch services in particular linked the attacks directly to Russia.

Taken together, the incidents in Norway, Germany, Poland and other EU member states against government agencies and private corporations demonstrate the systemic nature and scale of the cyber threat originating from Russia. The activity of hacking groups linked to Russian intelligence services goes far beyond isolated attacks. It has become an instrument of hybrid warfare that combines sabotage, espionage and economic pressure on Europe. The consequences are not limited to lost files or temporary outages of government services. Cyberattacks inflict multimillion-euro losses on European economies and businesses, paralyse public institutions, create risks for critical infrastructure and put the personal data of millions of citizens at risk. Stolen information can be used for further espionage, blackmail, attacks on partners and new cyber operations. That is why the defence of digital infrastructure must not be a reaction to the latest incident, but a permanent element of Europe’s policy of deterring Russia’s hybrid aggression.