August 2, 2026 | Kyiv Post
Russia’s Cyber War Against the West
August 2, 2026 | Kyiv Post
Russia’s Cyber War Against the West
Russian weapons do not always need to explode. They may simply arrive in your inbox. As Moscow refines its cyber arsenal, digital espionage is increasingly the Kremlin’s weapon of choice for advancing its geopolitical ambition. Last week, the US, with international allies, issued a warning that underscores a troubling evolution in Russia’s cyber espionage playbook. A newly disclosed campaign by the Russian state-supported group Laundry Bear has “targeted and compromised Western government and commercial organizations.”
The warning signs are becoming harder to ignore. In July, the United Kingdom and the European Union imposed sanctions package after attributing cyberattacks against Poland to Russian actors. The measures target Russian state entities and affiliated criminal networks accused of conducting cyber operations, interfering in democratic elections, and spreading disinformation aimed at weakening support for Ukraine across Europe. On July 13, the US issued a cybersecurity advisory urging operator of critical infrastructure to strengthen their defenses against Russian cyber threats.
Many European partners jointly wrote and published the recent warning which identified Center 16 as the group responsible for targeting Western critical infrastructure. Also known as Military Unit 71330, Center 16 belongs to Russia’s Federal Security Service (FSB). As one of Russia’s most sophisticated cyber actors, Center 16 conducts cyber operations to gain access to online systems across the globe allowing them to collect sensitive data and cause functional disruptions to Western infrastructure. According to the advisory, Center 16 identifies and exploits vulnerabilities in Western routers to enter critical infrastructure sector networks. The unit was responsible for the attack on Poland’s energy grid in December 2025.
None of this is new. The latest campaign fits a well-established Russian pattern of using cyber operations to undermine Western governments, collect intelligence, and prepare the battlefield. To name just a few examples, after Russia’s seizure of Crimea in 2014, the Kremlin disrupted Ukraine’s power grid, conducted hack-and-leak operations during the 2017 French presidential election, unleashed the destructive NotPetya malware that caused billions of dollars in global damage, and carried out spear-phishing campaigns targeting the Georgian government and private sector in 2018 and 2019.
The Kremlin views cyberspace as a central battlefield of modern conflict. Following New Generation Warfare doctrine, Russia partakes in actions just below the threshold of war.
Putin has repeatedly framed cyberspace as a key domain of modern conflict stating that if NATO conducted cyber operations against Russia, “we will do the same thing.”
In response to the Western warnings of Center 16 cyber operations, the Kremlin released commentary which denied Russian cyber aggression. Russian Foreign Ministry spokesperson, Maria Zakharova said that the warnings are propaganda: “Their true goal is to cement Russophobia, create an alarmist atmosphere necessary to transform Europe into a ‘besieged fortress,’ and justify further hostile measures.”
The Kremlin asserted that NATO was the true cyber aggressor, although the only examples they could provide were NATO’s recognition of cyberspace as a military domain, cyber exercises, and aid for Ukraine. Rather than contesting the evidence behind Western assessments of Center 16, the Kremlin employed a familiar information strategy: portraying Russia as the victim of Western aggression and a defensive actor rather than the perpetrator.
The irony does not stop there. As Russia wages an aggressive cyber campaign against the West, Moscow has also positioned itself as a champion of global cyber rules. Last year, the United Nations adopted a cybercrime treaty championed by Russia. Now, Moscow is pushing for a new international information security treaty through the UN. The message is clear: Russia wants a seat at the table where the rules of cyberspace are written even as it is accused of exploiting that very space to target its adversaries. We are effectively asking the fox to guard the digital henhouse.
Make no mistake: Russia’s cyber operations will continue. They are only one part of a broader campaign to pressure the West. As Putin faces setbacks in Ukraine, the Kremlin’s use of irregular tools will intensify. Cyberattacks provide Moscow with a low-cost, difficult-to-attribute method of applying pressure while maintaining plausible deniability, especially as negotiations on ending Russia’s aggression against Ukraine continue. These attacks allow Russia to exploit fears of escalation and influence Western policymakers. The timing of heightened cyber threats also coincides with elections in the United States.
The latest warnings from Western intelligence agencies should be treated as a warning shot, not routine cybersecurity guidance. Russia is already testing Western defenses and exploiting vulnerabilities as a tool of strategic competition. The choice facing the West is clear: strengthen resilience now or continue reacting after Russia has already gained the advantage.
Dr. Ivana Stradner serves as a research fellow with the Barish Center for Media Integrity at the Foundation for Defense of Democracies. Her research focuses on Russia’s security strategies and military doctrines to understand how Russia uses information operations for strategic communication.