OPEN DOSSIER
13 JULY 2026
RO

ROMANIA · CYBER ATTRIBUTION

Romania confirms Turla targeted the country. Four essential facts remain undisclosed.

Romania’s Foreign Ministry says the FSB 16th Centre-controlled group conducted hostile cyber activity against the country. It does not publish the targets, date, method or effects. On the same day, the European Union and the United Kingdom exposed mechanisms through which Russian intelligence services expand their capacity: private companies, university recruitment, credentials stolen by criminal malware and ostensibly autonomous groups.

The attributions and relationships presented here are governmental findings and sanctions reasons published on 13 July 2026; they are not judicial determinations.

Open the dossier
9states named by the EU
2,100UK Lumma victims in six months
29distinct targets across UK and EU lists
3exposed pathways into Russian capacity

THE ROMANIA FILE

The confirmation exists. The public incident record does not.

The Romanian statement places the country inside the Turla campaign and describes possible objectives of the wider Russian ecosystem, from sensitive-data exfiltration to disruption of critical infrastructure. It does not say what happened in Romania. The gap between attribution and incident transparency is the immediate public-interest issue.

RO

INCIDENT FILE · ROMANIA

TARGETUNDISCLOSED

No Romanian institutions, companies, sectors or individuals are identified.

DATE AND DURATIONUNDISCLOSED

No entry date, dwell time or discovery date is provided.

METHODUNDISCLOSED

No vulnerabilities, access vectors, infrastructure or technical indicators are published.

EFFECTUNDISCLOSED

It is unknown whether data was taken, systems were affected or services were disrupted.

CAPACITY ARCHITECTURE

Three pathways through which the Russian state extends its reach

The public documents describe interfaces between intelligence services, companies, criminals and threat groups. Each pathway produces something different: personnel, access or the ability to operate through intermediaries.

Choose a pathway

These are parallel pathways. The published material does not establish that IMPULS recruitment, Lumma exploitation and FSB 16th Centre operations belonged to one command chain.

A company formally separate from the state turns universities into a recruitment pool for a GRU unit.

  1. 01
    GRU Unit 29155

    Officers fund and coordinate capability expansion.

  2. 02
    OOO IMPULS

    Operational cover, infrastructure, payments and links to external networks.

  3. 03
    Universities and academies

    The pool from which hackers and cyber specialists are recruited.

  4. 04
    Young operators

    Recruits working under experienced handlers.

POSSIBLE OUTPUT

Additional capacity and operations whose state connection is obscured behind a company.

NINE STATES, DIFFERENT RESOLUTION

Romania is named. Its case is not described.

The EU statement lists nine states targeted by the FSB’s 16th Centre. It provides examples for France, Germany and Poland. For the other six, including Romania, it publishes only the names. Romania’s national statement adds confirmation of Turla activity without operational detail.

France

CASE DESCRIBED

Espionage against government entities since 2010; defence industry in 2025.

Germany

CASE DESCRIBED

Government entities targeted.

Poland

CASE DESCRIBED

Disruptive sabotage against critical infrastructure, including combined heat and power.

Cyprus

NAMED ONLY IN THE EU STATEMENT

No operational example in the EU statement.

Netherlands

NAMED ONLY IN THE EU STATEMENT

No operational example in the EU statement.

Austria

NAMED ONLY IN THE EU STATEMENT

No operational example in the EU statement.

Slovakia

NAMED ONLY IN THE EU STATEMENT

No operational example in the EU statement.

Romania

NATIONAL CONFIRMATION, NO PUBLIC CASE

The Foreign Ministry confirms hostile Turla activity; target, date, method and effect remain undisclosed.

Finland

NAMED ONLY IN THE EU STATEMENT

No operational example in the EU statement.

THE WORDING TEST

Half a million people, two official descriptions

The United Kingdom and CERT Polska describe the same attempted sabotage of 29 December 2025 with different emphases. Read together, they show what happened and which calculation remains unpublished.

UK SUMMARY

Risk of losing electricity

The British government says the failed attack could have left 500,000 citizens without electricity in the depths of winter.

POLISH TECHNICAL REPORT

The described target was heat supply

CERT Polska says the combined heat and power plant supplied heat to almost half a million customers. The attempt to disrupt heat failed, while attacks on renewable sites did not stop electricity production.

SANCTIONS REGISTER

24 plus 13 does not equal 37

The UK and EU lists overlap. A name-by-name comparison finds eight shared designations and 29 distinct targets. The EU total of 13 comes from two legal acts: eight people and four entities under the cyber-attacks regime, plus Ivan Kasyanenko under the destabilising-activities regime.

24UK
13EU
−8SHARED
=29DISTINCT
  • Denis Degtyarenkoperson
    UKEU
  • Evgeniy Bashevperson
    UKEU
  • Ivan Kasyanenkoperson
    UKEU
  • Maksim Gordienkoperson
    UKEU
  • Maksim Voroninperson
    UKEU
  • OOO IMPULSentity
    UKEU
  • Roman Puntusperson
    UKEU
  • Yuliya Pankratovaperson
    UKEU
  • Aleksandr Kanperson
    UK
  • Aleksandr Mininperson
    UK
  • Aleksandr Shepelevperson
    UK
  • Alexander Volosovikperson
    EU
  • Daria Rosliakovaperson
    UK
  • Denis Vulfperson
    UK
  • Dmitriy Voronovperson
    UK
  • Evgeniia Grebnevaperson
    UK
  • Ivan Seninperson
    UK
  • ML.Cloudentity
    EU
  • Maksim Matveevperson
    UK
  • Marat Zhurkinperson
    UK
  • Media Land LLCentity
    EU
  • Natalia Chebotaevaperson
    UK
  • Olga Kuznetsovaperson
    UK
  • Sultan Omarovperson
    UK
  • Tatiana Kosterovaperson
    UK
  • Valeriia Zvinchukperson
    UK
  • Vitaly Kovalevperson
    EU
  • Vyacheslav Stafeyevperson
    UK
  • Z-Pentestentity
    EU

THE PUBLIC EVIDENCE CHAIN

From coordinated attribution to operational claims

The 13 July package provides a more detailed picture than an APT label. Each layer adds precision, while the underlying intelligence material remains classified.

Coordinated attribution

The EU and United Kingdom publish coordinated attributions; NATO takes note of them and condemns Russia’s cyber activity.

Named units and officers

The FSB 16th Centre, GRU units and senior figures appear in official documents.

Identified intermediaries

IMPULS, Lumma developers, hackers and influence networks are tied to concrete functions.

Operational claims

University recruitment, reuse of stolen credentials and attempted energy sabotage.

The public limit

Intelligence reports, complete indicators, victim files and some impact calculations are not published.

TERMS

Three concepts used in the dossier

APT

A cluster tracked over time through behaviour, infrastructure and tooling. The label does not always denote one stable team.

Infostealer

Malware that extracts passwords, cookies, crypto wallets and other data from a compromised device.

Operational intermediary

A person or organisation used for capability, access or cover without formally appearing as part of the state.

SOURCES AND STATUS

Documents supporting the dossier

  1. 01

    Ministerul Afacerilor Externe al României

    Condemnation of hostile cyber activities conducted by FSB-controlled groups

    Confirmation that Romania was targeted by hostile APT Turla activity and description of the state and non-state ecosystem.

    13 iulie 2026

    Open source
  2. 02

    Consiliul Uniunii Europene

    Statement denouncing Russia’s malicious cyber ecosystem

    Attribution to the FSB 16th Centre, the list of nine states and the EU political sanctions total.

    13 July 2026

    Open source
  3. 03

    Foreign, Commonwealth & Development Office

    UK and EU strike Russian cyber networks with new sanctions

    The 24 UK designations, reuse of Lumma credentials, the 2,100-victim figure and the Poland estimate.

    13 July 2026

    Open source
  4. 04

    Guvernul Regatului Unit

    Profile: GRU cyber and hybrid threat operations

    IMPULS’s role, recruitment from universities and publicly identified officers and recruits.

    updated 13 July 2026

    Open source
  5. 05

    Jurnalul Oficial al Uniunii Europene

    Council Implementing Regulation (EU) 2026/1714

    Eight people and four entities, with listing reasons for IMPULS, Lumma, hosting infrastructure and hacktivist groups.

    13 July 2026

    Open source
  6. 06

    Jurnalul Oficial al Uniunii Europene

    Council Implementing Regulation (EU) 2026/1710

    The separate listing of Ivan Kasyanenko under the destabilising-activities regime.

    13 July 2026

    Open source
  7. 07

    CERT Polska

    Energy Sector Incident Report, 29 December 2025

    Technical description of attacks on renewable sites, a manufacturing company and a combined heat and power plant.

    30 January 2026

    Open source
  8. 08

    Consiliul Nord-Atlantic

    Statement of condemnation of Russia’s malicious cyber activities

    Allied condemnation, solidarity with affected states and NATO’s acknowledgement of the UK and EU statements.

    13 July 2026

    Open source
  9. 09

    AGERPRES, pe baza informațiilor MAE

    Romania supplied information on people suspected of attacks through NoName

    Romania’s separate sanctions proposal and its unfinished procedural status.

    13 iulie 2026

    Open source

This dossier synthesises official statements, sanctions instruments and a technical incident report. Listing reasons describe findings by competent authorities and are not judicial determinations. The total of 29 distinct targets results from matching the UK and EU public lists by name. PEOPLE, ACCESS and INTERMEDIARIES are editorial labels organising mechanisms presented separately in the sources.