VORANT. Threat Intelligence Sign in Get the full feed

France, EU attribute Turla espionage to FSB

high threat government-nationaldefensetechnology

France and the EU formally attributed cyber-espionage against French ministries, defense, and diplomatic entities to Turla, run by the FSB's 16th Centre.

The French Cyber Crisis Coordination Centre (C4) and ANSSI report sustained targeting and compromise of French entities by the Turla intrusion set, attributed to the 16th Centre of Russia's FSB. Active since at least 2004, Turla has been used for long-term intelligence collection against strategic government, diplomatic, defence, justice, and technology targets in France and allied nations. The campaign forms part of a broader pattern of Turla espionage activity against Ukraine, NATO members, and EU states that has intensified since Russia's 2022 invasion of Ukraine.

Notably, this disclosure coincides with formal, coordinated attribution statements issued on 13 July 2026 by the French Minister for Europe and Foreign Affairs and the EU's High Representative for Foreign Affairs and Security Policy, publicly naming Russia's FSB as responsible for the malicious cyber activity. Such joint state-level attribution is uncommon and signals a high-confidence assessment linking Turla operations directly to Russian intelligence services, elevating the political and diplomatic significance of the campaign beyond typical technical threat reporting.

No technical indicators, malware samples, or specific vulnerabilities were disclosed in this summary; a fuller technical report is referenced as available for download. The primary intelligence value here is the confirmation of long-running, state-directed espionage against core French government functions and critical sectors amid ongoing geopolitical tension with Russia.

Mentioned in this report

Threat actors Turla

Source reporting: https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free