Lyce · Hybrid Watch

hw_f15da557d8fcd8a2

French authorities officially attribute major cyber-operations to Russia’s military intelligence service.

On 29 April 2025 the French government publicly attributed a series of cyber-attacks to GRU, Russia’s military intelligence service, marking the first time France made such direct attribution. The announcement followed investigations by French cybersecurity and intelligence services (ANSSI, DGSE, DGSI) which identified at least ten French entities targeted by Russian-linked intrusions since 2021. These operations were aimed at French diplomatic networks, defense-industry firms and other strategic sectors. The geography is nationwide in France, emphasising that even states distant from Russia’s immediate border remain within the hybrid-warfare footprint. For France, this is a wake-up call: industrial and government IT systems are part of the front line. The public attribution also signals a shift in strategy — France is now more openly naming Russian actors and treating cyber-operations as part of its defence posture. The incident illustrates that hybrid warfare may not leave visible damage, but the erosion of strategic resilience and intelligence access is real. The effect includes increased costs of cybersecurity, potential disruptions of critical functions and increased tension in diplomatic relations.

Occurrence
2025-04-29
Publication
2025-04-28T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
FR
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2025-04-28T22:00:00Z

    On 29 April 2025 the French government publicly attributed a series of cyber-attacks to GRU, Russia’s military intelligence service, marking the first time France made such direct attribution. The announcement followed investigations by French cybersecurity and intelligence services (ANSSI, DGSE, DGSI) which identified at least ten French entities targeted by Russian-linked intrusions since 2021. These operations were aimed at French diplomatic networks, defense-industry firms and other strategic sectors. The geography is nationwide in France, emphasising that even states distant from Russia’s immediate border remain within the hybrid-warfare footprint. For France, this is a wake-up call: industrial and government IT systems are part of the front line. The public attribution also signals a shift in strategy — France is now more openly naming Russian actors and treating cyber-operations as part of its defence posture. The incident illustrates that hybrid warfare may not leave visible damage, but the erosion of strategic resilience and intelligence access is real. The effect includes increased costs of cybersecurity, potential disruptions of critical functions and increased tension in diplomatic relations.