Memo: ahead of meeting next week, the UK, Netherlands, Estonia, and other countries push for the EU to introduce sanctions for those who carry out cyberattacks
Bloomberg : Tweets: @nat_droz Tweets: Natalia Drozdiak / @nat_droz : After recent alleged attempts by Russia & China to attack Western agencies' computer systems - the U.K., the Netherlands, Estonia, and other EU govs are pushing for a new sanctions regime targeting individuals & orgs behind cyber attacks http://www.bloomberg.com/... via @nchrysoloras
Context & Ripple Effects
This 2018 memo is the origin point of what became the EU's cyber-sanctions machinery: the UK, Netherlands, and Estonia — all targets or near-targets of alleged Russian operations — wanted the bloc to stop treating attribution as a press release and start attaching costs. The push paid off two years later when the EU imposed its first-ever cyber sanctions, hitting six people and three organizations including the GRU over WannaCry and NotPetya.
Since then the tool has only widened: the EU has moved from sanctioning individuals to designating entire hacking groups and companies, including Iran's Emennet Pasargad and two Chinese firms in 2026 sanctions on hacking groups, while parallel work tightened export controls on dual-use technologies like hacking software. The 2018 proposal is the template every later designation runs on.
First-order effects
- If adopted at next week's meeting, individuals and organizations behind attacks attributed to Russia and China face EU-wide asset freezes and travel bans — turning attribution dossiers into enforceable designations.
Second-order effects
- A standing sanctions regime gives the EU a coercive layer alongside its defensive track — the network-protection rules for banking, energy, telecom, and transport agreed in 2022 and the Joint Cyber Unit for incident response — so member states can pair hardening with punishment.
Third-order effects
- The pattern points toward sanctions becoming the EU's default response to state-linked cyber operations, expanding from named individuals to whole units and the companies that host them — as seen in the Evil Corp case, where the UK NCA tied ransomware attacks on NATO allies to Kremlin orders.
The trend: The EU is institutionalizing cyber retaliation, converting post-incident attribution into a repeatable sanctions pipeline that now reaches individuals, groups, and companies alike.