Statement of attribution to Russia of malicious cyber activities targeting France for espionage purposes Russia Cyber security Statement On : July 13th 2026 France condemns the cyberattacks carried out by Russia in French territory and against its strategic interests in the strongest terms. For several years, France has been the target of persistent malicious cyber activities for espionage purposes, carried out by the 16th Centre of the Russian Federal Security Service (FSB), and specifically by Unit 61240, which is responsible for targeting France. Building on the intrusion set known as TURLA, the FSB has specifically targeted email accounts belonging to the Ministry for the Armed Forces since 2017, as well as the network of the Ministry for Europe and Foreign Affairs at the French Embassy in Moscow in 2018. In 2019, unauthorized access to a computer server belonging to an entity in the judicial sector was detected. In February 2025, a research institute specialized in sensitive technologies and working for the French defence industry was also targeted by cyberattacks carried out by the 16th Centre of the FSB, resulting in the exfiltration of a significant amount of data. This situation also affects many of our European partners. Today, the European Union (EU), on behalf of its 27 Member States, attributed a series of cyberattacks targeting several Member States over the past few years to the 16th Centre of the FSB. In Poland, this Russian actor carried out several cyberattacks aimed at sabotaging the water treatment system and the energy sector. France is directly involved in European solidarity efforts to prevent or respond to cyber incidents, including those related to the activities of this specific entity. In recent years, Russia has continuously intensified its malicious cyber activities, particularly targeting Ukraine and its allies. Russia is strengthening its own offensive cyber capabilities, while also relying on a diverse ecosystem of non-state actors, including so-called “hacktivist” groups, for destabilization purposes. In response to these actions, the European Union adopted a new package of sanctions on 13 July, under the EU‘s cyber regime, targeting 9 individuals and 4 entities that are part of this malicious cyber ecosystem, including a group that has claimed responsibility for destabilisation activities against the 2024 Paris Olympic and Paralympic Games. These cyber activities are one aspect of the growing hybrid threats targeting EU Member States in the context of Russia’s war of aggression against Ukraine: information manipulation campaigns, interference in democratic processes, airspace violations, and other destabilizing actions. Russia’s malicious cyber activities are unacceptable and unworthy of a permanent member of the United Nations Security Council. Furthermore, they are contrary to the principles of the normative framework for responsible state behaviour in cyberspace, which Russia has endorsed. France reaffirms its commitment to the United Nations normative framework and urges Russia to respect its commitments in this regard. Alongside its partners and within the framework of international law, France is determined to use all available means to anticipate, discourage and respond to destabilizing activities targeting it in cyberspace, including in the lead-up to the upcoming 2027 elections. The technical services of the Cyber Crisis Coordination Centre (C4) – which brings together the French Cybersecurity Agency (ANSSI), the domestic and foreign intelligence services (DGSI and DGSE), the General Directorate for Armaments (DGA), and the Cyber Defence Command (COMCYBER) – are today publishing a joint report on malicious cyber activities conducted by Russia against French interests through the TURLA intrusion set, drawing on imputation work on cyberattacks carried out within the C4.