The European Union has expanded its sanctions regime against cyber-attacks, adding eight natural persons and four entities to the list of those subject to restrictive measures under Council Decision (CFSP) 2019/797. The update, formalised by the Council on 13 July 2026 through Decision (CFSP) 2026/1713, targets individuals and organisations deemed responsible for cyber-attacks threatening the EU or its member states. The new designations were announced in a statement by the High Representative on 29 July 2026, which also noted that eight non-EU countries—Albania, Bosnia and Herzegovina, Iceland, Moldova, Montenegro, North Macedonia, Norway, and Ukraine—have aligned their national policies with the decision.
The statement, issued on behalf of the EU, welcomes the alignment of these countries, which are either EU candidates or closely associated partners. The measure builds on the EU's existing cyber-sanctions framework established in 2019, which allows the bloc to impose asset freezes and travel bans on individuals and entities involved in cyber-attacks. The Council's decision of 13 July 2026 marks the latest expansion of that list, though the specific names of the sanctioned individuals and entities were not disclosed in the statement. The EU has increasingly used its cyber-sanctions toolbox in response to rising cyber threats, including ransomware attacks, espionage, and disruption of critical infrastructure. This latest round underscores the bloc's commitment to deterring malicious cyber activity and coordinating with like-minded partners to enforce consequences. The alignment by eight non-EU countries signals broad international support for the EU's approach to cyber deterrence, though the practical impact of the sanctions depends on enforcement and the ability to freeze assets held within the EU and aligning states.