EU Cyber Sanctions: From Cyber Diplomacy to Targeted Restrictive Measures

Cyber operations have become an increasingly important dimension of international security. They may disrupt critical infrastructure, interfere with public institutions, compromise classified information or affect essential services without crossing a territorial border in the traditional sense. For the European Union, this has raised a difficult foreign-policy question: how can malicious cyber conduct be met with concrete consequences when the perpetrators may operate outside EU territory, through complex networks involving State agencies, private companies, criminal organisations and technical intermediaries?

One element of the EU response is the horizontal sanctions regime against cyber-attacks, established in 2019 and progressively developed since then. The regime allows the Union to impose targeted restrictive measures against individuals and entities responsible for, involved in, or supporting serious malicious cyber activities. As of September 2026, it applies to 27 individuals and 11 entities.

From cyber diplomacy to cyber sanctions

The sanctions regime should not be viewed in isolation. It forms part of the broader EU Cyber Diplomacy Toolbox, created in 2017 as a framework for a joint diplomatic response to malicious cyber activities.

The Toolbox allows the Union and its Member States to deploy different Common Foreign and Security Policy instruments depending upon the nature and seriousness of the conduct concerned. These may include diplomatic engagement, political declarations, démarches, coordination with international partners and, where appropriate, restrictive measures. The framework was revised in 2023 with the aim of developing more sustained and coordinated responses to persistent cyber-threat actors.

Sanctions therefore constitute only one part of a broader diplomatic architecture. Their importance lies in their capacity to transform assessments concerning malicious cyber conduct into legally binding consequences for specifically identified actors.

The legal architecture of the regime

The horizontal cyber-sanctions framework was established on 17 May 2019 through two complementary legal instruments:

  • Council Decision (CFSP) 2019/797, adopted within the framework of the Common Foreign and Security Policy; and
  • Council Regulation (EU) 2019/796, which gives effect within the EU legal order to the financial restrictive measures requiring implementation under EU law.

Both instruments remain in force and have subsequently been amended as new individuals and entities have been added to the sanctions lists. The Regulation’s current consolidated version incorporates amendments adopted as recently as July 2026.

This dual legal structure follows the familiar architecture of EU autonomous sanctions. The CFSP Decision establishes the political and legal framework for the measures, while the Regulation makes the relevant economic restrictions directly applicable within the Union.

The regime is particularly significant because it is horizontal rather than country-specific. It is not directed against one State. Instead, sanctions may be imposed against persons and entities satisfying the relevant criteria regardless of their nationality or location.

What kind of cyber-attacks can trigger sanctions?

Not every malicious cyber activity falls within the regime.

The framework is directed principally at cyber-attacks having a significant effect that constitute an external threat to the Union or its Member States.

The external dimension may arise where an attack:

  • originates or is carried out from outside the EU;
  • uses infrastructure located outside the Union;
  • is carried out by persons or entities established or operating outside the EU; or
  • is conducted with the support, direction or control of persons or entities operating outside the Union.

The regime can also cover attempted cyber-attacks with a potentially significant effect.

Significance is not reduced to a simple numerical threshold. The legal assessment may involve the scope, scale, impact and severity of the disruption; the number of persons or Member States affected; economic damage; the amount or sensitivity of compromised data; and the broader consequences of the operation.

This makes the mechanism adaptable to the particular characteristics of cyber operations, where an intrusion affecting a relatively limited number of systems may nevertheless have major strategic consequences.

What interests are protected?

The range of protected interests is deliberately broad.

The Council identifies cyber-attacks affecting information systems connected with:

critical infrastructure, including infrastructure essential to the functioning of society or to citizens’ health, safety, security and economic or social well-being;

essential services, including energy, transport, banking, financial services, healthcare, drinking water and digital infrastructure;

critical State functions, including defence, government institutions, elections, internal security, economic and civil infrastructure and external relations;

classified information and systems used for its storage or processing; and

government emergency response teams.

The framework therefore extends well beyond conventional espionage against government networks. It can address attacks on the digital infrastructure on which modern societies and economies depend.

Who can be sanctioned?

Another important feature of the regime is the breadth of the listing criteria.

Sanctions are not limited to the individual who directly conducts an intrusion. They may also be imposed on actors providing financial, technical or material support, actors otherwise involved in the operation and persons or entities associated with those responsible. The Council’s 2019 framework expressly contemplated both completed and attempted attacks.

This matters because contemporary cyber operations frequently rely upon complex ecosystems.

A malicious operation may involve intelligence services, hacking groups, ransomware operators, malware developers, companies supplying offensive cyber capabilities, providers of infrastructure and so-called bulletproof hosting services. Focusing exclusively upon the person sitting behind the keyboard would therefore leave substantial parts of the operational infrastructure untouched.

The evolution of the EU regime increasingly reflects this ecosystem approach.

What measures are imposed?

Listed individuals are subject to a travel ban, preventing entry into or transit through Member State territory, subject to the exceptions provided by EU law.

Listed individuals and entities are also subject to an asset freeze.

In addition, EU persons and companies are prohibited from making funds or economic resources available, directly or indirectly, to listed persons and entities or for their benefit.

These measures are targeted: they are directed at specified individuals and entities rather than at the population or economy of a particular country.

The crucial distinction between sanctions and attribution

One of the most interesting legal characteristics of the EU cyber-sanctions regime concerns its relationship with attribution.

When the EU imposed its first cyber sanctions in July 2020, the Council expressly stated that targeted restrictive measures should be distinguished from the attribution of responsibility to a third State.

The distinction is fundamental.

Placing an individual or entity on an EU sanctions list requires the Council to determine that the listing criteria contained in the relevant EU legal instruments are satisfied. Attribution of a cyber operation to a State for the purposes of the international law of State responsibility raises a different legal question, governed by different rules and potentially carrying different consequences.

The adoption of sanctions therefore does not necessarily amount to a determination that the underlying conduct is legally attributable to a particular State under international law.

At the same time, attribution and sanctions can form part of the same broader diplomatic response. The Cyber Diplomacy Toolbox expressly allows the EU and its Member States to combine different instruments, and recent EU practice demonstrates an increasing willingness to coordinate public attribution, diplomatic measures and restrictive measures where appropriate.

This flexibility may be one of the principal advantages of the regime: it enables the Union to impose legal consequences on identifiable actors without making formal attribution of State responsibility a necessary precondition for every sanctions decision.

From the first listings to the expansion of 2026

The first EU cyber sanctions were imposed on 30 July 2020 against six individuals and three entities involved in several major cyber operations.

The underlying incidents included the attempted cyber-attack against the Organisation for the Prohibition of Chemical Weapons, as well as the attacks commonly known as WannaCry, NotPetya and Operation Cloud Hopper.

The regime was subsequently expanded.

In October 2020, the Council imposed measures in connection with the 2015 cyber-attack against the German Bundestag. Further listings followed, including measures in 2024 involving members of the Callisto, Armageddon and Wizard Spider groups and, in January 2025, three individuals associated with cyber-attacks against Estonia.

But 2026 represents a particularly important stage in the development of the regime.

On 16 March 2026, the Council sanctioned three entities and two individuals in connection with cyber-attacks against Member States and EU partners. The listings included the China-based companies Integrity Technology Group and Anxun Information Technology, as well as the Iranian company Emennet Pasargad. According to the Council, the activities concerned included hacking services targeting critical infrastructure, the compromise of large numbers of devices and cyber operations affecting European services and citizens.

A further major package followed on 13 July 2026, when the Council imposed measures on actors forming part of what it described as Russia’s cyber ecosystem. The measures addressed persons and entities involved in malware attacks, ransomware, phishing and other operations targeting critical infrastructure and essential services.

Among the entities targeted were providers of infrastructure facilitating malicious cyber operations, illustrating particularly clearly the movement from sanctioning only direct perpetrators toward targeting the wider technical ecosystem that enables cyber-attacks.

The July measures were also significant from the perspective of international coordination. The EEAS described them as the EU’s largest cyber-sanctions package to date and noted that, for the first time, EU cyber sanctions were adopted in parallel with measures under the United Kingdom’s cyber-sanctions regime.

Where the regime stands today

Following the 2026 additions, the horizontal EU cyber-sanctions regime currently covers 27 individuals and 11 entities. The existing listings have been extended until 18 May 2027, while the underlying legal framework has been prolonged until 18 May 2028.

The geographical scope of the listings is itself revealing. The Council currently refers to sanctioned actors and companies located in or connected with countries including Russia, China and Iran.

Yet describing the regime merely in geographical terms would miss its principal legal innovation. The central organising principle is not nationality but conduct and involvement in malicious cyber operations.

A distinctive instrument of EU external action

The EU cyber-sanctions regime occupies an unusual position at the intersection of sanctions law, cybersecurity and international law.

It is not a cybersecurity regulation comparable to instruments governing network security within the internal market. Nor is it a mechanism establishing criminal responsibility for cybercrime. And it does not constitute a general system for determining the international responsibility of States for cyber operations.

It is, instead, an instrument of EU external action.

Its function is to identify individuals and entities associated with serious malicious cyber activities and to subject them to targeted economic and mobility restrictions.

The evolution of the regime also reveals a broader transformation in EU sanctions practice. Increasingly, sanctions are directed not merely against traditional State officials or formally constituted organisations, but against the networks, companies, technical providers and intermediaries that make hostile activities possible.

In cyberspace, this distinction is especially important. The boundary between State and non-State activity can be deliberately blurred. Intelligence agencies may interact with private companies, criminal groups or technically independent operators. Cyber infrastructure may be supplied by commercial entities several steps removed from the final operation.

The horizontal architecture of the EU regime allows restrictive measures to follow these networks rather than being confined by traditional territorial categories.

Seven years after its establishment, the regime has therefore evolved from an initially cautious sanctions mechanism into a more developed instrument of European cyber diplomacy. The major question for the coming years will not simply be whether the EU adds further names to its sanctions lists. More significant will be how the Union develops the relationship between technical evidence, polit


Leave a Reply