ESSAY: 32 Russia-Linked Attacks Still Do Not Prove State Control
- Introduction A 2025 European Repository of Cyber Incidents report cited by RTL Today recorded 32 attacks linked to Russian actors and 4 linked to Chinese actors against EU member states.
- They are not a legal chain of command.
- An IP address does not carry a flag.
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction
A 2025 European Repository of Cyber Incidents report cited by RTL Today recorded 32 attacks linked to Russian actors and 4 linked to Chinese actors against EU member states. The figures are useful. They are not a legal chain of command. An IP address does not carry a flag.
Experts cited on 8 August 2026 warned that IP addresses, code language and timestamps cannot reliably distinguish a state-directed operation from one run by a criminal group that a state may tolerate or fail to stop. The digital trace is evidence. It is not a flag.
The report supplies a pattern, not a command order
The report supplies a pattern, not a command order
RTL Today, writing on 8 August 2026, cited the 2025 European Repository of Cyber Incidents report: 32 attacks were linked to Russian actors and 4 to Chinese actors against EU member states. The relevant terms are RTL Today, 2025 report, 32 attacks and 4 attacks. Linkage is not command.
Those figures establish a reported distribution in the repository’s account. They do not identify a document, an instruction or an official who ordered each operation. The reading stays anchored in 4 attacks, 32 attacks, 2025 report and RTL Today.
Russia-linked is not the same as Kremlin-directed
The assigned record uses the phrase linked to Russian actors, not a finding that the Russian state directed all 32 attacks. That wording carries an evidentiary caution that should not be erased for rhetorical convenience. The relevant terms are linked to Russian actors, Russian state, 32 attacks and state decision. Technical traces can narrow, not finish, attribution.
Attribution can be politically plausible and technically supported while still falling short of proof of command. The missing step is the connection between an observed operation and a state decision. The reading stays anchored in state decision, 32 attacks, Russian state and linked to Russian actors.
China-linked cases face the same test
China-linked cases face the same test
The repository also counted 4 attacks linked to Chinese actors against EU member states in 2025. A smaller number does not lower the need to distinguish an actor’s apparent origin from a government’s proven direction. The relevant terms are 4 attacks, Chinese actors, EU member states and 2025. A state claim needs more than a pattern.
The analytical rule must apply evenly. A preferred geopolitical conclusion is not a substitute for evidence that assigns responsibility through a defensible chain. The reading stays anchored in 2025, EU member states, Chinese actors and 4 attacks.
IP addresses can be routed and reused
The experts cited by RTL Today said IP addresses are among the technical clues that cannot by themselves resolve whether an operation was state-directed. An address can help investigators map activity without revealing who authorized it. The relevant terms are IP addresses, technical clues, state-directed and investigators. Thirty-two is a warning, not a verdict.
This is not an argument for ignoring infrastructure data. It is an argument against treating a locator as a signed confession. The reading stays anchored in investigators, state-directed, technical clues and IP addresses.
Code language is not an identity card
Code language is not an identity card
The article also names code language as a technical indicator with limits. A linguistic or programming trace can suggest a community of practice, but it cannot reliably establish whether a government directed a particular intrusion. The relevant terms are code language, technical indicator, government and intrusion. Four is a category, not a chain of custody.
The difference is more than academic. Code can be copied, reused or designed to mislead, so it must be tested alongside evidence that carries more direct responsibility. The reading stays anchored in intrusion, government, technical indicator and code language.
Timestamps describe activity, not authority
Experts likewise cited timestamps as data that cannot settle the key distinction. A time pattern may be consistent with a place or work schedule, but consistency is not proof of state involvement. The relevant terms are timestamps, time pattern, state involvement and operational instruction. A tolerated group is not automatically directed.
A schedule can support a hypothesis. It cannot, alone, identify the person or institution that gave an operational instruction. The reading stays anchored in operational instruction, state involvement, time pattern and timestamps.
Tibor Jager states the boundary plainly
Tibor Jager states the boundary plainly
Dr Tibor Jager of the University of Wuppertal was quoted as saying, “Technical data alone cannot settle that distinction.” The distinction is between a state operation and activity by a criminal group tolerated or not stopped by a state. The relevant terms are Tibor Jager, University of Wuppertal, technical data alone and criminal group. Official attribution is a separate political act.
That sentence supplies the essay’s central rule. The data may be essential, but the word alone is doing the legal work that headlines often omit. The reading stays anchored in criminal group, technical data alone, University of Wuppertal and Tibor Jager.
Jörn Müller-Quade frames a methodological problem
Professor Jörn Müller-Quade of the Karlsruhe Institute of Technology was among the cybersecurity experts consulted for the report. His inclusion signals that the problem is methodological, not merely a dispute over a single country. The relevant terms are Jörn Müller-Quade, Karlsruhe Institute of Technology, methodological and cybersecurity experts. Sanctions do not disclose every intelligence source.
Method matters because the same indicators must withstand use against adversaries, allies and private actors alike. A rule that works only for a desired conclusion is not a rule. The reading stays anchored in cybersecurity experts, methodological, Karlsruhe Institute of Technology and Jörn Müller-Quade.
Thorsten Holz adds another expert caution
Thorsten Holz adds another expert caution
Dr Thorsten Holz of the Max Planck Institute for Security and Privacy in Bochum was also cited in the account. The source presents several experts converging on the limits of technical-only attribution. The relevant terms are Thorsten Holz, Max Planck Institute, Bochum and technical-only attribution. A report year is not a new incident date.
Multiple experts do not turn uncertainty into certainty. They show why the uncertainty is structural: the available artifacts do not naturally contain the identity of a sovereign decision-maker. The reading stays anchored in technical-only attribution, Bochum, Max Planck Institute and Thorsten Holz.
Toleration and direction are different allegations
RTL Today’s experts distinguish a group directed by a state from one that a state may tolerate or fail to stop. Those propositions can produce different legal and diplomatic consequences. The relevant terms are directed by a state, tolerate, legal consequences and official control. One Luxembourg case shows the missing endpoint.
The gap should not be papered over. Proving negligence, permissiveness or sanctuary is not identical to proving an instruction, a mission or official control. The reading stays anchored in official control, legal consequences, tolerate and directed by a state.
The experts call attribution a judgment
The experts call attribution a judgment
The limitations state that the experts regard state attribution as “ultimately a judgment rather than proof”. That does not mean judgment is arbitrary; it means the final conclusion combines technical and contextual evaluation. The relevant terms are ultimately a judgment rather than proof, technical, contextual evaluation and final conclusion. No public attribution is not proof of innocence.
A judgment can be careful, well-supported and necessary. It still should not be described as if a single technical artifact had ended the question. The reading stays anchored in final conclusion, contextual evaluation, technical and ultimately a judgment rather than proof.
The 2025 date constrains the claim
The 32 and 4 figures come from a 2025 report, although RTL Today’s article appeared in August 2026. They describe the repository’s prior-year picture, not a newly measured surge on the publication date. The relevant terms are 32, 4, 2025 report and August 2026. Evidence has levels; policy should say which one.
Date discipline matters in cyber reporting because old incident counts can be made to sound like fresh attacks if the reporting year and the article date are blurred. The reading stays anchored in August 2026, 2025 report, 4 and 32.
The source gives no technical file for each incident
The source gives no technical file for each incident
The assigned record says RTL Today did not provide detailed technical proof for each of the reported 32 attacks or 4 attacks. That limits any attempt to audit individual attributions from the article alone. The relevant terms are detailed technical proof, 32 attacks, 4 attacks and case-by-case. Europe’s credibility lives in that distinction.
A public account can accurately relay an aggregate report without containing the forensic material needed for a case-by-case legal finding. The absence must be named, not silently filled. The reading stays anchored in case-by-case, 4 attacks, 32 attacks and detailed technical proof.
The POST incident shows the unresolved endpoint
The article recalls a 2023 attack on Luxembourg postal operator POST, but says Luxembourg authorities made no official attribution. The example illustrates how an incident can be known while responsibility remains publicly unresolved. The relevant terms are 2023, POST, Luxembourg and no official attribution.
No attribution is not evidence that no actor exists. It is evidence that the public record has not supplied an official conclusion about who was responsible. The reading stays anchored in no official attribution, Luxembourg, POST and 2023.
France’s statement is an official attribution act
France’s statement is an official attribution act
The fact block lists a French foreign ministry statement attributing malicious cyber activity to Russia. Such a statement is a government act of attribution, distinct from a technical indicator observed by a private analyst. The relevant terms are French foreign ministry, Russia, official attribution and diplomatic weight.
Official attribution can carry diplomatic weight even when intelligence details remain undisclosed. It should be described as an official position, not confused with a publicly complete criminal proof file. The reading stays anchored in diplomatic weight, official attribution, Russia and French foreign ministry.
The EU sanctions package is a policy response
The sources include an EU cyber sanctions package concerning Russia’s malicious cyber ecosystem. Sanctions are a policy instrument through which the European Union publicly responds to conduct it attributes and condemns. The relevant terms are EU cyber sanctions package, European Union, Russia and policy instrument.
A sanctions decision may rest on information not reproduced in a news article. Its existence does not eliminate the conceptual difference between political responsibility and legal proof of command in every incident. The reading stays anchored in policy instrument, Russia, European Union and EU cyber sanctions package.
A repository count is not a court judgment
A repository count is not a court judgment
The European Repository of Cyber Incidents supplies the count cited by RTL Today. It is not identified in the fact record as a court issuing binding findings on the responsibility for each operation. The relevant terms are European Repository of Cyber Incidents, court, binding findings and legal procedure.
That institutional distinction should shape the verbs we use. A repository can record, link and classify; a court evaluates evidence under a defined legal procedure. The reading stays anchored in legal procedure, binding findings, court and European Repository of Cyber Incidents.
Technical evidence still has real value
The experts did not say that IP addresses, code language and timestamps are useless. They said those clues alone cannot settle whether a state directed the operation. The relevant terms are IP addresses, code language, timestamps and broader assessments.
That is a demanding but practical position. Technical signals can narrow possibilities, test narratives and support broader assessments without being asked to perform a task they cannot complete alone. The reading stays anchored in broader assessments, timestamps, code language and IP addresses.
The legal question is control
The legal question is control
The decisive issue described in the report is whether a state directed an operation, not merely whether an attacker appeared Russian or Chinese. Control, instruction and responsibility require a more specific showing than resemblance. The relevant terms are state, Russian, Chinese and control.
This is why attribution language matters. A phrase that is adequate for a threat assessment may be inadequate for a legal claim of state direction. The reading stays anchored in control, Chinese, Russian and state.
Public certainty can outrun the public evidence
The article’s limits warn that the cited experts do not treat attribution as a fact established in the legal sense. That warning applies even where the geopolitical context makes a Russia-linked or China-linked explanation persuasive. The relevant terms are legal sense, Russia-linked, China-linked and public record.
The discipline is not weakness. It is the refusal to convert a plausible conclusion into a type of proof the public record has not supplied. The reading stays anchored in public record, China-linked, Russia-linked and legal sense.
Europe must separate exposure from overstatement
Europe must separate exposure from overstatement
The EU can expose malicious activity, cite Russia or China, and impose sanctions where its institutions judge the evidence sufficient. The fact record supports those as distinct public actions, not as interchangeable evidentiary labels. The relevant terms are Russia, China, sanctions and evidentiary labels.
Clear distinctions make policy harder to dismiss. When language is exact, an adversary cannot exploit a careless leap from linkage to command. The reading stays anchored in evidentiary labels, sanctions, China and Russia.
The standard should be applied without favoritism
The methodological caution offered by Jager, Müller-Quade and Holz does not depend on whether the suspected actor is a rival state or a friendly one. The technical limitation is built into the nature of the evidence. The relevant terms are Jager, Müller-Quade, Holz and technical limitation.
A consistent standard protects Europe’s own claims. It demonstrates that responsibility is assigned through reasons, not through the convenience of a geopolitical story. The reading stays anchored in technical limitation, Holz, Müller-Quade and Jager.
The 32 cases are still a strategic alarm
The 32 cases are still a strategic alarm
A reported total of 32 Russia-linked attacks against EU member states in 2025 is a serious strategic alarm. Refusing to call it conclusive proof of state control does not make the pattern less relevant to European security. The relevant terms are 32 Russia-linked attacks, EU member states, 2025 and European security.
The two statements can coexist: the pattern demands defensive attention, and the legal claim demands a stronger evidentiary bridge. The reading stays anchored in European security, 2025, EU member states and 32 Russia-linked attacks.
The 4 China-linked cases resist the same shortcut
The reported 4 China-linked attacks belong in the same analytical framework. A lower count cannot justify a lower standard for saying that China itself directed a particular operation. The relevant terms are 4 China-linked attacks, China, lower count and state instruction.
Consistency prevents selective rigor. It keeps the difference between an attributed actor and a demonstrated state instruction intact across cases. The reading stays anchored in state instruction, lower count, China and 4 China-linked attacks.
The missing proof must remain visible
The missing proof must remain visible
The fact block offers no technical dossier, no exposed command order and no judicial finding for each incident in the counts. It therefore cannot bear a definitive legal assertion that a state ran every attack. The relevant terms are technical dossier, command order, judicial finding and definitive legal assertion.
That boundary is the point of the essay, not a loophole. Evidence becomes stronger when the missing link is identified rather than hidden under confident language. The reading stays anchored in definitive legal assertion, judicial finding, command order and technical dossier.
Attribution is strongest when it names its level
A careful statement can say an incident was linked, an official government attributed activity, or a court proved responsibility. Those verbs describe different levels of conclusion. The relevant terms are linked, attributed, proved and chain of command.
The public deserves to know which level is being invoked. It is the difference between reporting a threat and claiming to have established its chain of command. The reading stays anchored in chain of command, proved, attributed and linked.
Conclusion
The European Union is right to expose and sanction malicious cyber activity when it reaches an evidentiary threshold. But political attribution, technical assessment and legal proof are different acts. Confusing them does not make Europe safer; it makes every public accusation easier to contest. The standard protects the accusation from collapse.
Thirty-two Russia-linked incidents are a serious signal. They are not, by themselves, a courtroom answer to who issued an order. The harder standard is not a gift to hostile states. It is the discipline that keeps Europe’s response credible when the evidence is challenged.
Signature
Signed Maxime Marquette, columnist
Columnist's Transparency box
Editorial positioning
This column takes a pro-Western editorial position while keeping the stated source limits visible.
Its argument is based on the assigned fact block and does not add unverified facts, quotations or motives.
Methodology and sources
The article uses only the facts, figures, attribution and URLs supplied for this assignment.
Where a source is an analysis, poll, tracker or media report, it is described as such rather than as an official determination.
Nature of the analysis
Interpretation is separated from reported fact; it does not turn a claim, estimate or unresolved issue into a settled conclusion.
The conclusion states an editorial judgment about the available record and identifies what remains unproven.
Sources
Primary sources
The sources include repository and official attribution material; the assigned record does not provide detailed technical proof for every counted incident.
Source categories are retained exactly as available in the assigned fact record.
European Repository of Cyber Incidents — 2025 report
French foreign ministry attribution statement — source page
European External Action Service cyber sanctions package — source page
Secondary sources
RTL Today expert report — 8 August 2026
SWP Cyber Activity Balance paper — 2025
Attribution commentary listed in the fact record — source page
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). ESSAY: 32 Russia-Linked Attacks Still Do Not Prove State Control. MadMax. https://mad-max.co/en/article/essay-32-russia-linked-attacks-still-do-not-prove-state-control
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.