Sources: The White House is split over Kaspersky sanctions, which could spur Russian cyberattacks and make enforcement hard due to the company's large clientele
but the idea has split the administration due to concerns over the size and scope of such a move. w/ @vmsalama https://www.wsj.com/... Jan Lemnitzer / @janlemnitzer : Like the EU, the US government is wondering whether Kaspersky is simply too big to sanction, exposing hundreds of millions of clients to the risk of losing their malware protection at this critical moment. To be balanced with the wisdom of having your IT security run from Moscow. https://twitter.com/... Peter Zeihan / @peterzeihan : Change your passwords...any maybe your software. https://www.reuters.com/... Joel Schectman / @joel_schectman : Another SCOOP on Russian cyber trouble from master of disaster @Bing_Chris https://twitter.com/... Chris Bing / @bing_chris : Biden admin also reportedly considering sanctions for kaspersky. But split over the issue. https://twitter.com/... Patrick Howell O'Neill / @howelloneill : Everything old is new again. From 2018: https://www.cyberscoop.com/... https://twitter.com/... @wylienewmark : It's truly galaxy-brain to say “We shouldn't sanction this entity with operational ties to the FSB, because then the entity's product might be used to conduct offensive cyber operations.” Dude, you just summed up a major reason that entity needs to be sanctioned. https://twitter.com/... Eric Geller / @ericgeller : Getting some major 2017 vibes here https://twitter.com/... Kevin Beaumont / @gossithedog : “Some U.S. officials have privately acknowledged that the alleged relationship between Kaspersky Lab and the Russian state would be similar to how U.S.-based cyber firms cooperate with U.S. intelligence agencies.” https://twitter.com/... See also Mediagazer
Context & Ripple Effects
The White House's indecision caps five years of escalating suspicion around Kaspersky: the theft of NSA cyber tools from a contractor's laptop was attributed to hackers exploiting the company's software, and a BuzzFeed investigation found an internal power struggle won by managers with ties to Russian intelligence.
The dilemma is structural, not just political — as Jan Lemnitzer notes, Kaspersky may be too big to sanction, since cutting it off would strip malware protection from hundreds of millions of clients at a moment of heightened Russian cyber threat. The eventual resolution, when it came, was narrower than a full ban: Treasury's sanctions against 12 Kaspersky executives left both the company and Eugene Kaspersky untouched.
First-order effects
- Kaspersky's large installed base faces immediate uncertainty — if sanctions land, customers lose active malware protection overnight, which is precisely why officials warn enforcement would be hard.
- The administration itself is the affected party in the short term: a split White House means no decision, leaving US exposure to a Moscow-run security vendor unresolved while Russia's invasion raises attack risk.
Second-order effects
- Competing Western antivirus vendors stand to absorb a forced-migration wave of Kaspersky customers if a ban comes, turning a sanctions debate into a market-share windfall for the rest of the security industry.
- Officials' warning that sanctions could spur Russian cyberattacks makes retaliation pricing part of the calculus — Moscow's demonstrated willingness to hit US targets via supply chains raises the expected cost of any move.
Third-order effects
- If the pattern holds, security software gets treated as an extension of state intelligence capability, and governments settle for targeted measures against individuals — the executive-level sanctions model — rather than bans that orphan millions of unprotected endpoints.
- The 'too big to sanction' problem pushes toward managed wind-downs and procurement bans over outright prohibition, fragmenting the global antivirus market along geopolitical lines.
The trend: National governments are increasingly treating commercial security vendors as potential state-intelligence instruments, forcing sanctions design that balances counterintelligence risk against leaving civilian endpoints unprotected.