Premier Ministre S.G.D.S.N Agence nationale de la sécurité des systèmes d'information Paris, le 13 juillet 2026 N° CERTFR-2026-CTI-005 Affaire suivie par: CERT-FR Rapport menaces et incidents du CERT-FR Objet: Targeting and Compromise of French Entities Using the Turla Intrusion Set Gestion du document Référence CERTFR-2026-CTI-005 Titre Targeting and Compromise of French Entities Using the Turla Intrusion Set Date de la première version 13 juillet 2026 Date de la dernière version 13 juillet 2026 Source(s) Une gestion de version détaillée se trouve à la fin de ce document. Version française: 🇫🇷 Members of the Cyber Crisis Coordination Centre (C4) have observed the targeting and compromise of French entities using the Turla intrusion set operated by the 16th Centre of the Federal Security Service of the Russian Federation (FSB). Since at least 2004, this intrusion set has been implemented for intelligence-gathering purposes against strategic entities and individuals worldwide, including in France. The French intermediate and final victimology of the Turla intrusion set notably includes ministries, entities in the diplomatic, defence, justice, and technology sectors. Espionage campaigns associated with the Turla intrusion set against Ukraine, NATO countries, and EU member states continue in the context of Russia’s war of aggression launched on February 24, 2022. The malicious cyber activities of the 16th Centre of the FSB against France and its European partners are the subject today (13 July 2026) of two formal attribution statements by the French Minister for Europe and Foreign Affairs, on behalf of France, and by the High Representative of the EU for Foreign Affairs and Security Policy, on behalf of the EU and its Member States. Link to the Ministry for Europe and Foreign Affairs statement : https://www.diplomatie.gouv.fr/fr/presse-et-ressources/decouvrir-et-informer/actualites/attribution-a-la-russie-d-activites-cyber-malveillantes-a-des-fins-d-espionnage-en-france Download the report : Targeting and Compromise of French Entities Using the Turla Intrusion Set Gestion détaillée du document le 13 juillet 2026 Version initiale
The Turla intrusion set, operated by Russia's FSB 16th Centre, is actively targeting French government and strategic entities for intelligence gathering via unspecified compromise methods. The campaign is part of broader ongoing espionage activities against Ukraine, NATO, and EU member states. The French and EU governments have formally attributed these malicious cyber activities to Russia.