Standards, Regulations & Compliance
Europe Targets Officers of Unit 29155 of the Russian Main Intelligence Directorate
The European Union sanctioned on Monday three officers of a Russian military intelligence unit for their role in cyberattacks targeting Estonia in 2020.
See Also: Happening Tomorrow: Declutter Your Data, Declutter Your Business
The sanctions targeted Nikolay Korchagin, Vitaly Shevchenko and Yuriy Denisov, officers of the Unit 29155 of the Russian Main Intelligence Directorate, generally known as the GRU. The sanctions are tied to the unit’s 2020 hack of the Estonian government departments and the exfiltration of sensitive documents, including classified information.
Estonia in September 2024 publically attributed the attacks to Russia. The Estonia State Prosecutor’s Office issued an arrest warrant against the three GRU officers.
Denisov, a colonel in the Russian military, Shevchenko and Korchagin oversaw the operations of the 2020 hacks against Estonian public offices that were designed to compromise the country and its allies’ national security, said the European Council.
The sanctions entail asset freeze and travel restrictions. Denisov and Korchagin also face a criminal indictment in the United States for allegedly deploying WhisperGate malware against Ukrainian victim organizations. The U.S. government is offering up to $10 million for information on each of the defendants (see: US Broadens Indictments Against Russian Intelligence Hackers).
Unit 29155 is distinct in its focus on attempted coups, sabotage and assassination attempts, in addition to cyber activities. The unit is suspected of poisoning former GRU officer Sergei Skripal in 2018 and an attempted coup in Montenegro in 2016. The GRU unit pivoted to malicious cyber activities around 2020 to carry out espionage, hack and leak campaigns, and conduct sabotage by remotely wiping systems.
To tackle rising hybrid threats to the trading bloc, the EU in October 2024, expanded its cyber sanctions regime (see: EU Strengthens Sanctions Against Russian Hackers).
In December 2024, the council sanctioned 16 individuals and three organizations, including Unit 29155 (see: European Union Sanctions Russian Malicious Cyber Actors).