US Treasury sanctions three Russian individuals and five firms, saying they helped Russia conduct cyberattacks, including NotPetya, against US and its allies
Even as Trump was working hard … Alfred Ng / CNET : US announces more sanctions over Russian hacking Lorenzo Franceschi-Bicchierai / Motherboard : Founder of Cybersecurity Company Says His Firm Was Sanctioned Because He was Born in Russia Kieren McCarthy / The Register : US tech companies sucked into Russian sanctions row Derek B. Johnson / Federal Computer Week : Treasury hits infosec vendors with Russia-related sanctions Lawrence Abrams / BleepingComputer.com : USA Sanctions Russian Entities Over Alleged Ties to Russian FSB Patrick Howell O'Neill / Cyberscoop : U.S. sanctions Russian companies linked to FSB Hanna Bogorowski / The Daily Caller : Treasury Department Hits Russia With Hacking Sanctions U.S. Department of the Treasury : Treasury Sanctions Russian Federal Security Service Enablers Joe Uchill / Axios : U.S. Treasury slaps sanctions on Russian firms for cyberattacks Mallory Locklear / Engadget : US extends sanctions against Russians over cyberattacks Tweets: Eric Geller / @ericgeller : .@USTreasury slaps sanctions on three Russian companies, two subsidiaries of one of those companies, and three leaders of another of the companies for supporting the FSB's “cyber and underwater capabilities”: http://home.treasury.gov/... http://twitter.com/... Julia Ioffe / @juliaioffe : While Trump was inviting Russia back into the G7, his administration sanctioned 5 Russian companies and 3 Russian individuals for their work with the FSB to undermine American cyber security, including targeting of underwater cables. http://home.treasury.gov/... Patrick Howell O'Neill / @howelloneill : Two companies sanctioned by the US government today for allegedly being linked to Russian hacking responded: @erpscan says they are not subisidaries of the Russian firm Digital Security, @_embedi_ says they don't work for the Russian government but... https://www.cyberscoop.com/... pic.twitter.com/lzCVb0Uq5C
Context & Ripple Effects
This is the moment US sanctions policy turns from individual hackers to the commercial security industry itself: among the five firms named are infosec vendors like Digital Security and Embedi that sell research and penetration-testing services to Western clients, and one founder says he was sanctioned simply for being born in Russia. Treasury frames them as suppliers to the FSB's offensive program, including NotPetya.
The move sets a template the government keeps reusing: six months later it hits nine GRU members over election interference (Treasury sanctions more Russian hackers), then FSB-linked ransomware operators in 2023, twelve Kaspersky executives in 2024 (sanctions against 12 Kaspersky executives), and a Beijing firm tied to Flax Typhoon in 2025.
First-order effects
- The three individuals and five firms are cut off from the US financial system, and their Western customers — the very enterprises these vendors audit and test for — must unwind contracts immediately or risk secondary exposure.
- Legitimate Russian-founded security researchers outside the state apparatus get swept into the same net, as the sanctioned founder's complaint illustrates, chilling an entire diaspora's ability to do business with US clients.
Second-order effects
- Western platform owners start scrubbing Russian firms from trusted channels — the pattern Microsoft followed years later when it removed Positive Technologies from its early-access vulnerability program (Microsoft cuts off Positive Technologies) — so sanctioned vendors lose not just money but access to the bug and threat-intelligence ecosystem.
- Russia's response is to pull its security industry inward, deepening the split between Western and Russian threat-intelligence markets and pushing FSB-aligned work toward the only buyers left.
Third-order effects
- If the pattern holds through the Kaspersky, Conti/Ryuk, and Flax Typhoon actions, sanctions become Washington's standing tool for decoupling state-linked cyber actors from the global market — with 'security company' no longer a shield but often the target itself.
- The global infosec industry structurally bifurcates along geopolitical lines: dual-use research firms everywhere now price in the risk that their government relationships make them sanctionable, fragmenting a market built on shared vulnerability knowledge.
The trend: Economic sanctions are becoming the primary US instrument for severing state-linked hacking ecosystems — including nominally commercial security firms — from the Western market.