The European Union, in a statement delivered on 20 July 2026 at the first substantive session of the UN Global Mechanism on ICTs in international security, warned of the growing use of non-state actors as proxies by states to conduct malicious cyber activities, specifically calling out Russia for employing an ecosystem of government agencies, private companies, hacktivists, and criminals to target the EU and its partners. The statement, issued by the EEAS on 21 July 2026, highlighted the healthcare sector as a prime target for ransomware attacks and proposed discussing its protection under the Dedicated Thematic Groups in December. The EU also noted that new AI models are being used to exploit zero-day vulnerabilities almost instantly upon discovery.

The EU's intervention comes amid a broader push to enhance international cybersecurity norms. The bloc has been actively imposing sanctions on entities supporting Russian cyber operations, as demonstrated by the recent sanctions package announced last week alongside the United Kingdom. The EU also supported Estonia's objection to the stakeholder JSC Positive Technologies, which the EU says supports Russian operations. The statement emphasized the need for states to take responsibility for proxy activities, in line with the law of state responsibility, and called for raising awareness of cyber threats through advisories by the EU Cybersecurity Agency (ENISA) and CERT-EU. The EU reiterated its commitment to promoting an open, free, stable, and secure cyberspace and to supporting states in understanding and responding to cyber threats through the Global Mechanism's thematic groups.

← Atlas › News › Defence