Europe

German intelligence warning against Russian GRU hacker group about targeting NATO and the EU

A cyber group associated with the 29155 unit of Russia’s military intelligence agency, the GRU, has prompted a warning from German intelligence due to its suspected involvement in a series of cyberattacks targeting NATO and the EU.

The warning was part of a coordinated effort with international agencies, including the FBI, U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the NSA, according to a report by Reuters.

On Monday, September 9, Germany’s Federal Office for the Protection of the Constitution (Bundesverfassungsschutz) publicly named the group, known as UNC2589, which also operates under aliases such as “Cadet Blizzard” and “Ember Bear.” 

The intelligence agencies accused the group of conducting espionage and sabotage, often damaging websites and leaking stolen data as part of its operations. 

These attacks, the agencies noted, are part of a broader pattern of cyber aggression aimed at destabilising Western institutions and extracting sensitive information.

Disruptive activities and cyber espionage of the Russian UNC2589 group

The poisoning of former Russian double agent Sergei Skripal and his daughter Yulia in the UK in 2018 clearly demonstrates this unit’s capability and willingness to engage in hostile activities beyond cyberattacks.

In 2020, Russian military intelligence hackers linked to the same unit launched a cyberattack that compromised tens of thousands of Estonian documents, including sensitive internal and trade secrets, underscoring the broad scope of its operations. 

Such breaches demonstrate the GRU’s intent to undermine not only political and military stability but also economic security within targeted nations.

The GRU is not only collecting intelligence, but also seeking to weaken the cohesion and functionality of Western alliances by targeting NATO and EU institutions.

The coordinated response from agencies like the FBI, CISA, and NSA signals a robust approach, but it also emphasises the need for vigilance and stronger cyber defences within NATO and EU institutions, which remain prime targets for future attacks.

Alex Khomiakov

My passion for journalism began in high school, and I have since devoted my career to reporting on issues that matter to people around the world. I believe that journalism has the power to effect real change in the world, and I am passionate about using my platform to give voice to those who are too often overlooked.

Recent Posts

Russia Cognitive Warfare in 2026: How Disinformation Became an Architecture of Influence

Recent reporting and analysis on Russian influence operations targeting the EU and Ukraine suggest a…

6 days ago

Russia’s FSB Accused of Using Fake Volyn Tragedy Documents to Strain Ukraine-Poland Relations

Ukraine’s Center for Countering Disinformation says Russia is using fabricated archival material and state media…

7 days ago

Re:Baltica: Kremlin-linked disinformation campaign escalated threats against the Baltics over drone claims

A Re:Baltica investigation says pro-Kremlin media and social media channels used unrelated security incidents in…

1 week ago

MV-lehti: How Finland’s Largest Pro-Kremlin Outlet Spreads Russian War Narratives

With nearly 900,000 monthly visitors, MV-lehti is the most-visited pro-Kremlin outlet in Finland — and…

3 weeks ago

Alexandra Jost Sanctions: How the EU Case Shows the Rise of Influencer-Led Kremlin Messaging

The EU’s designation of Alexandra Jost marks a wider shift in how European authorities are…

3 weeks ago

Geoestrategia.eu: How a Spanish Outlet Bypassed EU Sanctions to Keep Amplifying Russian Propaganda

A Spanish-language website with declared partnerships with RT and Sputnik has published more than 2,300…

3 weeks ago