EU’s first cyber sanctions

The EU singled out perpetrators that cyber attacked British hospitals, Ukranian infrastructure, and the Pyeongchang Olympics….
Eu cyber attacks

Share this article:

The EU singled out perpetrators that attacked British hospitals, Ukranian infrastructure, and the Pyeongchang Olympics.

The European Union, for the first time in its history, has levied sanctions in response to cyber attacks, naming six individuals and three groups associated with some of the biggest hits in recent years.

EU officials imposed restrictions on North Korean, Chinese and Russian attackers associated with the WannaCry, Operation Cloudhopper, and NotPetya attacks, including a travel ban and an asset freeze, according to a statement Thursday. 

“Sanctions are one of the options available in the EU’s cyber diplomacy toolbox to prevent, deter and respond to malicious cyber activities directed against the EU or its member states, and today is the first time the EU has used this tool. The legal framework for targeted restrictive measures against cyber-attacks was adopted in May 2019 and recently renewed.”

The 2017 WannaCry ransomware attacks, attributed to North Korean actors, struck institutions, including many hospitals and city governments. The attackers used a Windows exploit that was originally discovered by the NSA and revealed to Microsoft shortly after.

The 2017 NotPetya attacks were carried out by individuals associated with the Russian military, specifically the intelligence service, GRU. The attackers first targeted Ukraine, hitting banks, media outlets and utilities. These were highly destructive attacks not just knocking the affected computers offline but overwriting key files. The attack quickly spread to other computers around the world.

John Hultquist, senior director of analysis at Mandiant Threat Intelligence, said “NotPetya and WannaCry were two of the most devastating cyberattacks in history, causing billions of dollars in damage and disrupting many vital systems, such as those belonging to the UK’s NHS [National Health Service]. At least one victim of NotPetya has claimed 1.3 billion dollars in damage… Those same actors attempted a destructive attack on the Pyeongchang Olympics though no government statement has accused the Russian government for their role in that incident.”

The sanctions document from the EU lists “Olympics Destroyer,” an alias for the group that attacked the Pyeongchang Olympics, sometimes called “Sandworm,” associated with the NotPetya attacks.

Hultquist described the Cloud Hopper campaign as a less destructive, more traditional intelligence-collection operation, widely attributed to Chinese actors. The group, also called APT10, “gained access to Managed Service Providers as a means to then target their customers – organizations who used those providers to host their IT. China and others continue this type of activity, moving upstream to telecommunications and IT providers where they can gain access to multiple organizations and individuals simultaneously,” he said.

 

Share this article on LinkedIn.

See more news here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Ai Solution of the year - securitybuyer.com

Have your say: vote for AI Solution of the Year

Voting is open for AI Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited to select their winner
Access control of the year - securitybuyer.com

Have you voted for Access Control Solution of the Year?

Voting is open for Access Control Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited
PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
Scroll to Top