EU imposes first ever cyber attack sanctions

The EU has imposed the first ever sanctions against cyber-attacks. The accused of carrying out the WannaCry, NotPetya and Cloud Hopper attacks…
Cyber

Share this article:

The EU has imposed the first ever sanctions against cyber-attacks. These include six individuals and three entities accused of carrying out the WannaCry, NotPetya and Cloud Hopper attacks. The sanctions imposed include a travel ban and asset freeze.

John Hultquist, Senior Director of Analysis, Mandiant Threat Intelligence comments:

“The European Union imposed sanctions against multiple people and organizations for their role in a number of cyberattacks and cyber espionage incidents. The sanctions are tied to the NotPetya and Ukraine blackout attacks carried out by the GRU as well as an act of cyber espionage that was attempted against the OPCW by that same organization. WannaCry was another global destructive event similar to the NotPetya incident that posed as ransomware, though it was carried out by North Korean actors. Cloud Hopper was a long term complex cyber espionage operation that targeted managed service providers to gain access to third parties that was carried out by Chinese contractors working on behalf of the Ministry of State Security.

NotPetya and WannaCry were two of the most devastating cyberattacks in history, causing billions of dollars in damage and disrupting many vital systems, such as those belonging to the UK’s NHS. At least one victim of NotPetya has claimed 1.3 billion dollars in damage. The NotPetya attack was carried out by the GRU actors known as Sandworm who had previously conducted two attacks on Ukraine’s grid. Those same actors attempted a destructive attack on the Pyeongchang Olympics though no government statement has accused the Russian government for their role in that incident.

The Cloud Hopper campaign was a complex intelligence collection operation that was meant to gather intelligence rather than disrupt systems. APT10 gained access to Managed Service Providers as a means to then target their customers – organizations who used those providers to host their IT. China and others continue this type of activity, moving upstream to telecommunications and IT providers where they can gain access to multiple organizations and individuals simultaneously.

The GRU was also behind an attempt to hack the OPCW’s WI-FI network by physically visiting their facilities in the Hague. That operation was disrupted but the unit had been involved in similar operations in Switzerland, Brazil, and Malaysia which targeted the Olympics and other investigations involving Russia. The consistent use of physical human intelligence teams to supplement its intrusion efforts makes the GRU a particularly effective adversary. Sanctions may be particularly effective for disrupting this activity as they may hinder the free movement of this unit.”

 

Share this article on Twitter or LinkedIn.

See more news here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Scroll to Top