Timeline - Sanctions against cyber-attacks
-
2026
13 JulyNew sanctions in response to Russia's cyberattacks and malicious activities
The Council decided to impose sanctions on nine Russian individuals and four entities responsible for and involved in cyberattacks that pose an external threat to EU member states and malicious activities against the EU and its member states
Those sanctioned include individuals and entities involved in malware attacks, ransomware operations, phishing campaigns and other cyberattacks targeting critical infrastructure and essential services.
-
2026
11 MayCouncil extends sanctions regime against cyber-attacks
The Council decided to extend the sanctions against actors involved in cyber-attacks threatening the EU and its member states until 18 May 2027.
The EU is deploying these sanctions to deter malicious cyber activities and uphold the international rules-based order by ensuring that those responsible are held to account.
-
2026
16 MarchNew sanctions in view of cyber-attacks against the EU
The Council adopted sanctions against three entities and two individuals responsible for cyber-attacks carried out against EU member states and EU partners. The entities listed include companies based in Iran and China.
-
2025
12 MayCyber-attacks: Council extends sanctions and legal framework
The Council today decided to prolong the sanctions against cyber-attacks threatening the EU and its member states for a further year, until 18 May 2026.
The legal framework for these measures is extended for three years until 18 May 2028.
-
2025
27 JanuaryNew sanctions in response to malicious cyber activities against Estonia
The Council adopted additional sanctions against three Russian individuals responsible for a series of cyber-attacks carried out against the Republic of Estonia in 2020.
The individuals listed are officers of the General Staff of the Armed Forces of the Russian Federation (GRU) Unit 29155.
-
2024
24 JuneEU adopts new sanctions against cyber-attacks
The Council adopted sanctions against six individuals involved in cyber-attacks affecting information systems related to critical infrastructure, critical state functions, the storage or processing of classified information and government emergency response teams in member states.
Sanctioned people include members of the Callisto, Armageddon and Wizard Spider groups.
-
2022
16 MayCyber-attacks: Council extends sanctions regime
The Council decided to prolong the framework for restrictive measures against cyber-attacks threatening the EU and its member states for a further three years, until 18 May 2025.
This framework allows the EU to impose targeted restrictive measures on persons or entities involved in cyber-attacks which cause a significant impact, and constitute an external threat to the EU or its member states.
-
2021
17 MayCyber-attacks: Council extends sanctions regime
The Council decided to prolong the framework for restrictive measures against cyber-attacks threatening the EU or its member states for another year, until 18 May 2022.
This framework allows the EU to impose targeted restrictive measures on persons or entities involved in cyber-attacks which cause a significant impact, and constitute an external threat to the EU or its member states.
-
2020
22 OctoberSanctions over Bundestag cyber-attack
The Council decided to impose restrictive measures on two individuals and one entity responsible for the 2015 cyber-attack on the German Federal Parliament (Bundestag). This cyber-attack targeted the parliament's information system and affected its ability to operate for several days.
-
2020
30 JulyEU imposes the first ever sanctions against cyber-attacks
The Council decided to impose restrictive measures against six individuals and three entities responsible for or involved in various cyber-attacks.
The sanctions imposed include a travel ban and an asset freeze, while EU persons and entities are forbidden from making funds available to those listed.
-
2019
17 MayCyber-attacks: Council establishes sanctions framework
The Council established a framework which allows the EU to impose targeted restrictive measures to deter and respond to cyber-attacks which constitute an external threat to the EU or its member states. This decision allows the EU for the first time to sanction persons or entities that:
- are responsible for cyber-attacks or attempted cyber-attacks
- provide financial, technical or material support for such attacks
- are involved in other ways
Last review: 13 July 2026