The UK and EU governments have targeted 24 individuals and entities in sanctions aimed at Russian networks believed to be operating cyber-attacks, interfering in elections, and spreading anti-Ukraine narratives.
The sanctioned entities are believed to be behind destructive cyber and hybrid operations, including cyber-criminals involved in proxy networks linked to the Russian Intelligence Services (RIS).
This includes sanctioning GRU senior leadership figures Vyacheslav Stafeyev, Ivan Senin and Ivan Kasyanenko for their role in directing GRU cyber and hybrid threat operations. GRU Unit 29155 cyber division worked with cyber-criminals, including the company IMPULS, to recruit hackers and cyber specialists from universities and academies across Russia.
In addition, the UK together with EU member states is today attributing the attack on Poland’s energy grid to Russia’s FSB Centre 16. This reckless attack failed, but could have caused 500,000 citizens to lose electricity in the depths of winter as the Russian state attempts to sow chaos across Europe.
“These sanctions strike at the core of the cybercriminal networks propping up the Russian state’s aggression, and the UK and EU are sending a clear message that Russia cannot hide behind its use of these proxy groups,” Foreign Secretary, Yvette Cooper said.
“From directing criminals to targeting businesses, and striking Poland’s energy grid in the depths of winter, the Russian state is sinking to new lows in its attempts to undermine European security.
“Together with our partners, Britain will continue to call out this behaviour, bolster our resilience and respond to the hybrid threat posed by the Russian state. This will not deter us from supporting Ukraine.”
Recommended reading
- UK CISOs Call for DeepSeek Regulation to Avoid Cyber Crisis
- UK Sanctions Chinese Firms Over “Reckless” Cyber-Attacks
- UK and Allies Link China to Cyber Campaigns Targeting Critical Networks
- Google Warns of China-linked Cyber-attacks Targeting Tech
The UK is also sanctioning individuals behind Lumma Stealer which enables cybercriminals to collect sensitive information from compromised devices at scale. The UK can reveal that Russia has used Lumma Stealer’s stolen credentials to conduct cyber espionage operations against targets globally to support the Kremlin’s objectives.
According to the National Crime Agency, within the last six months, there have been at least 2,100 Lumma Stealer victims in the UK.
New measures also target 10 individuals behind Rybar LLC including directors, senior management, and content designers. The media company is resourced by the Russian state and is responsible for spreading false narratives about Ukraine and interfering in European elections, including in Moldova and Armenia.





