EU imposes its first ever cyber sanctions, hitting six people and three organizations including GRU, for involvement in WannaCry, NotPetya, and other attacks
Place of birth: Shandong Province, China Federal Computer Week : FCW Insider: July 31 Francesco Guarascio / Reuters : EU sanctions Russian intelligence, North Korean, Chinese firms over alleged cyberattacks Phil Muncaster / infosecurity-magazine.com : EU Applies First Ever Sanctions in Response to Cyber-Attacks Tweets: Jeff Stone / @jeffstone500 : EU imposes sanctions on six individuals and three entities accused of carrying out the WannaCry, NotPetya and CloudHopper attacks. Sanctions include a travel ban and asset freeze. EU citizens also are prohibited from doing business with these targets. https://www.consilium.europa.eu/ ... Frank Bajak / @fbajak : EU imposes first-ever sanctions for cyber-attacks. Named are Russian military hackers, Chinese cyberspies, North Korean firm. Payback for WannaCry, NotPetya and attempted GRU Wi-Fi intrusion of Dutch-based chemical weapons monitor. https://apnews.com/... Natalie Thompson / @natalierthom : <thread> Today the EU took a major step in strengthening its cyber diplomacy toolbox by imposing cyber-related sanctions for the first time. A few observations/comments: [1/x] https://www.consilium.europa.eu/ ... Spain Mfa / @spainmfa : #Spain 🇪🇸 welcomes the decision of the @EUCouncil imposing for the first time sanctions against people and entities responsible for #cyberattacks against the #EU 🇪🇺 and its Member States. Crime in the digital sphere must be prosecuted. #EUCyber #SecurityUnion https://twitter.com/... SiSu WiThiN / @sisu_sanity : 1) Chinese hackers & Russian military intelligence (GRU) hackers and related organizations (plus a China/North Korea joint venture) called out and sanctioned by the EU. https://twitter.com/... @germanydiplo : Europe demonstrates its capacity to act also in the digital realm: For the first time, EU-27 sanction those responsible for cyber-attacks against Member States. #EuropeUnited #EU2020DE https://www.consilium.europa.eu/ ... https://www.consilium.europa.eu/ ... Andrew S. Weiss / @andrewsweiss : Impressive. Germany leading the charge on first-ever name-and-shame EU sanctions vs GRU cyber unit and the 4 GRU officers responsible for NotPetya and OPCW attacks https://twitter.com/... @fireeye : The US isn't alone in slapping sanctions on cyber attackers. The EU joined today with sanctions on attackers behind WannaCry, NotPetya, and Operation Cloud Hopper. See what @JohnHultquist had to say about the sanctions. via @AP http://r.socialstudio.radian6.com/ ...
Context & Ripple Effects
This closes a two-year lobbying arc: back in October 2018, the UK, Netherlands and Estonia were pushing the Council to build an EU cyber-sanctions regime ahead of a leaders' meeting ([[a:934427]]). The US had already moved unilaterally that June, sanctioning three Russian individuals and five firms over NotPetya ([[a:930513]]) — so Brussels was catching up to Washington with a legal framework of its own.
What makes the move notable is scale and breadth: six individuals and three organizations spanning Russian military intelligence, Chinese contractors tied to CloudHopper, and North Korean actors behind WannaCry, all hit at once with travel bans, asset freezes, and business prohibitions binding on EU citizens.
First-order effects
- The nine named targets are cut off from the EU financial system and Schengen travel, and any EU citizen or company doing business with them now faces penalties under the new regime.
Second-order effects
- Brussels' action converges with the US Treasury's earlier NotPetya-related designations, giving Western allies a coordinated sanctions front rather than parallel national lists — and raising due-diligence costs for firms exposed to the sanctioned entities.
Third-order effects
- The framework proves reusable: months later the EU extended it to the GRU and two officers over the 2015 Bundestag hack ([[a:1160835]]), and by 2026 it was being applied to hacking groups like Iran's Emennet Pasargad ([[a:1165373]]) — turning one-off retaliation into a standing instrument of EU cyber policy.
The trend: Cyber operations are being folded into the sanctions toolkit as a routine, repeatable response — shifting state responses to hacking from diplomatic protest to measurable economic cost.