Skip to content

Sanctions against cyber-attacks

The EU can impose sanctions to deter and respond to cyber-attacks which constitute an external threat to the EU or its member states.

Cyber-attacks threatening the EU or its member states

In May 2019, the Council established a framework of sanctions allowing the EU to impose targeted restrictive measures to deter and respond to cyber-attacks which constitute an external threat to the EU or its member states.

More specifically, this framework allows the EU, for the first time, to impose sanctions on persons or entities that are responsible for cyberattacks or attempted cyber-attacks, which provide financial, technical or material support for such attacks or otherwise involved in such attacks.

This sanctions regime covers cyber-attacks which have a significant impact on and originate or are carried out from outside the EU, use infrastructure outside the EU, are carried out by persons or entities established or operating outside the EU or are carried out with the support of persons or entities operating outside the EU.

Sanctions include a ban on persons travelling to the EU and an asset freeze on persons and entities. Additionally, the provision of funds or economic resources, directly or indirectly, to the sanctioned individuals and entities or for their benefit is prohibited.

The sanctions regime currently applies to 27 individuals and 11 entities and was last extended until 18 May 2027.

Cyber-attacks which constitute a threat to EU countries include those affecting information systems relating to:

  • critical infrastructure essential to the vital functioning of society, or to citizens' health, safety, security and economic or social well-being
  • services necessary for essential social and economic activities, in particular energy, transport, banking, finance, healthcare, drinking water and digital infrastructure
  • critical state functions, in particular defence, the governance and functioning of institutions, public elections, economic and civil infrastructure, internal security and external relations, including diplomatic missions
  • the storage or processing of classified information
  • government emergency response teams

Individuals sanctioned under this sanctions regime include Russian nationals responsible for a series of cyber-attacks carried out against the EU and its member states, including the 2015 attack on the German Federal Parliament and the 2020 attacks against several government ministries in Estonia.

The entities sanctioned include companies facilitating malware attacks and providing hacking services and products used to compromise and access devices in EU member states. These entities are based in non-EU countries such as Russia, China and Iran.

Boosting cyber diplomacy

In June 2017, the EU established a Framework for a Joint EU Diplomatic Response to Malicious Cyber Activities (the ‘cyber diplomacy toolbox’). The framework allows the EU and its member states to use all measures under the Common Foreign and Security Policy (CFSP), including sanctions if necessary, to prevent, discourage, deter and respond to malicious cyber activities targeting the integrity and security of the EU and its member states.

The cyber diplomacy toolbox was revised in 2023 to allow the development of sustained, tailored, coherent and coordinated strategies towards persistent cyber threat actors.

The EU cybersecurity strategy adopted by the European Commission and European External Action Service in December 2020 reinforces the EU's diplomatic response to cyber-attacks.

In October 2024, the Council established a new framework for sanctions in response to Russia’s destabilising actions abroad.

This framework allows the EU to target individuals and entities engaged in actions and policies, including cyber-attacks, by the government of the Russian Federation, which undermine the fundamental values of the EU and its member states, their security, independence and integrity, as well as those of international organisations and third countries.

See also

Why the EU adopts sanctions

Why the EU adopts sanctions

Hybrid threats

Hybrid threats

Cyber defence

Cyber defence

Last review: 13 July 2026