EU Sanctions against Russia’s hybrid activities

The European Union’s response to Russian hybrid activities has developed into a distinct sanctions regime with an increasingly broad reach. Rather than focusing exclusively on Russia’s military aggression against Ukraine, the framework addresses forms of destabilisation that operate across the boundaries between external security, cyber operations, information manipulation, interference with democratic processes and attacks on critical infrastructure.

The regime was established on 8 October 2024 through Council Decision (CFSP) 2024/2643 and Council Regulation (EU) 2024/2642. It therefore forms a legally autonomous component of the wider EU sanctions architecture concerning Russia, alongside the measures adopted in response to the war against Ukraine, threats to Ukraine’s territorial integrity and human-rights violations in Russia.

As of September 2026, the framework applies to 80 individuals and 20 entities, while the individual restrictive measures have been extended until 9 October 2026.

From military aggression to hybrid destabilisation

The distinctive feature of the regime lies in the conduct that may justify a designation.

The Council may target persons and entities responsible for, involved in, supporting, benefiting from or facilitating actions attributable to the Russian government that undermine or threaten democracy, the rule of law, stability or security in the EU, its Member States, international organisations or third countries.

The relevant activities extend well beyond conventional military operations. They include interference with electoral processes, attempts to destabilise constitutional order, violent demonstrations, coercion and intimidation, foreign information manipulation and interference, malicious cyber activities, sabotage of critical infrastructure, unauthorised territorial incursions and the instrumentalisation of migrants. The regime also covers certain activities connected with the exploitation of armed conflict or instability in third countries.

This breadth is important. “Hybrid threats” are not treated as a single category of conduct but as a combination of instruments that may be deployed together: cyber operations may accompany disinformation campaigns; sabotage may be supported by surveillance activities; financial intermediaries may facilitate destabilising networks; and nominally private actors may contribute to policies attributable to a state.

The sanctions framework is designed to follow those connections.

The traditional core: asset freezes and travel restrictions

The starting point remains the model familiar from other EU sanctions regimes.

All funds and economic resources belonging to, owned, held or controlled by listed persons and entities must be frozen. EU operators are also prohibited from making funds or economic resources available, directly or indirectly, to or for the benefit of those listed.

Listed individuals are additionally subject to travel restrictions under the CFSP Decision.

These measures are accompanied by the usual architecture of exemptions and derogations. The Regulation contains provisions relating, among other matters, to basic needs, legal services, humanitarian assistance, judicial and arbitral proceedings and specific transactions authorised by national competent authorities. It also establishes reporting and cooperation obligations and prohibits participation in circumvention schemes.

In this respect, the regime fits comfortably within the established structure of EU targeted sanctions.

What makes it more innovative is what came next.

The 2025 expansion: sanctions against the infrastructure of hybrid operations

On 20 May 2025, the Council substantially broadened the framework. The change moved the regime beyond the traditional model of listing individuals and legal entities and introduced mechanisms capable of targeting assets and infrastructures used to conduct or facilitate destabilising activities.

A first innovation concerns tangible assets.

Article 1a of Regulation 2024/2642 allows the EU to prohibit transactions involving specifically listed assets such as vessels, aircraft, real estate, ports, airports and physical elements of digital and communications networks.

Such assets may be listed when they are used, for example, in activities endangering critical infrastructure, in operations violating air, maritime or land-traffic rules, or in espionage, surveillance, transportation of military material or information-manipulation activities attributable to or benefiting the Russian government.

This represents an important development in EU sanctions practice. The legal object of the restriction no longer needs to be simply a natural person or legal entity. The Union can potentially target the physical instrument through which destabilising conduct is carried out.

Financial and crypto intermediaries can also be targeted

A second significant development concerns financial infrastructure.

Article 1b allows the EU to impose transaction bans on certain credit institutions, financial institutions and crypto-asset service providers established outside the Union where they facilitate or support persons engaged in destabilising activities.

The same mechanism may apply to entities providing technical or operational assistance to such actors.

This provision is particularly significant because hybrid activities frequently rely on complex networks of intermediaries rather than on a direct relationship between a state authority and the actor carrying out the operation.

The EU framework is therefore increasingly directed not only at the immediate perpetrator but also at the financial, technical and logistical ecosystem that makes destabilising activity possible.

Broadcasting restrictions and information manipulation

The framework also contains specific instruments addressing the information environment.

Under Article 1c, EU operators may be prohibited from broadcasting, facilitating or otherwise contributing to the distribution of content produced by entities included in the relevant annex. Broadcasting licences and distribution arrangements may be suspended, and advertising in content produced or broadcast by the listed entities may be prohibited.

This aspect has become particularly visible in the Council’s 2026 listing practice.

On 29 January 2026, six additional individuals were sanctioned in connection with Foreign Information Manipulation and Interference, or FIMI. Four more individuals were added on 16 March. On 21 April, the Council imposed restrictive measures on two additional entities, Euromore and the Foundation for the Support and Protection of the Rights of Compatriots Living Abroad, known as Pravfond, on the basis of their alleged involvement in propaganda and disinformation activities.

Earlier measures had also targeted both information-manipulation networks and malicious cyber activities. In December 2025, for example, the Council listed twelve individuals and two entities in connection with FIMI and cyber operations.

The trend is clear: information operations are increasingly being treated within the EU sanctions system as a security issue capable of triggering economic restrictive measures.

But this is not merely a “disinformation sanctions regime”

Reducing the framework to disinformation would nevertheless miss its broader significance.

The Council expressly identifies sabotage, cyberattacks, disruption of critical infrastructure, electoral interference and the instrumentalisation of migrants among the forms of hybrid activity covered by the regime.

The Regulation goes further by allowing restrictions against vessels, aircraft, communications infrastructure and financial or technical intermediaries.

The architecture is therefore better understood as an attempt to construct a sanctions toolbox for activities occurring below, beside or outside the conventional paradigm of armed conflict.

The object of the measures is not necessarily military conduct as such. What matters is the destabilising character of the activity and its attribution, benefit or connection to policies of the Russian government.

A separate regime within the broader Russia sanctions architecture

This distinction is legally important.

The EU currently operates several different sanctions regimes involving Russia. Measures addressing the war against Ukraine, Ukraine’s territorial integrity, human-rights violations and hybrid activities may overlap politically and factually, but they rest on different listing criteria and legal instruments.

The hybrid-activities regime should therefore not be regarded simply as another “package” of economic sanctions adopted in response to the war.

It is a thematic sanctions regime with its own rationale.

Its development suggests that EU restrictive measures are increasingly being adapted to situations in which security threats are deliberately dispersed across civilian, digital, financial and informational environments.

The legal questions will become increasingly important

The expansion of the regime also raises significant legal issues.

The broader the concept of hybrid activity becomes, the more important it is to establish a sufficiently precise link between the listed person, entity or asset and the conduct relied upon by the Council.

Questions of attribution may be particularly difficult where activities are undertaken by nominally private actors, media organisations, intermediaries or informal networks rather than by organs of the Russian state.

The same applies to concepts such as “support”, “facilitation” and association, which substantially extend the potential reach of restrictive measures beyond those directly carrying out the relevant conduct.

These issues inevitably intersect with procedural rights, the obligation to state reasons, judicial review by the EU Courts and the requirement that listings be supported by a sufficiently solid factual basis.

They may become particularly sensitive where sanctions concern information activities, media organisations or other conduct capable of engaging fundamental rights, including freedom of expression.

A significant evolution in EU sanctions policy

The regime adopted in 2024 and expanded in 2025 therefore marks an important evolution in the Union’s use of restrictive measures.

EU sanctions are no longer directed only at states, military structures, economic sectors or persons connected with conventional armed aggression. They are increasingly being used against networks, infrastructures and enabling mechanisms associated with forms of coercion deliberately designed to remain below or outside the traditional categories of interstate conflict.

That development does not remove the need for careful legal scrutiny. On the contrary, the wider and more flexible the sanctions instrument becomes, the greater the importance of clearly defined listing criteria, adequate evidence and effective judicial protection.

The EU regime concerning Russia’s destabilising activities is therefore significant not merely because of the number of persons currently listed. It provides an indication of how the Union is adapting the law of restrictive measures to an environment in which cyber operations, sabotage, financial networks, information manipulation and interference with democratic processes increasingly form part of the same security landscape.

Legal framework: Council Decision (CFSP) 2024/2643 and Council Regulation (EU) 2024/2642, as subsequently amended and consolidated. The current consolidated version of Regulation 2024/2642 available on EUR-Lex is dated 13 July 2026.


Leave a Reply