The European Union, in a statement delivered on 20 July 2026 at the first substantive session of the UN Global Mechanism on ICTs in international security, warned of a rapidly evolving cyber threat landscape marked by state-sponsored proxy actors, AI-enabled zero-day exploits, and escalating attacks on critical infrastructure, particularly healthcare. The statement, issued by the EU Delegation to the UN in New York, outlined key messages under the agenda item on existing and potential threats, calling for enhanced international cooperation and accountability for states that tolerate or direct malicious cyber activities by non-state actors.

The EU highlighted that malicious actors continue to target government services, hospitals, financial institutions, and energy grids, and that cyber tools are now used as integrated instruments of war, including against international humanitarian organizations. The healthcare sector has become a prime target for ransomware due to sensitive patient data and operational criticality. The EU proposed discussing protection of the healthcare sector as critical infrastructure during the Dedicated Thematic Groups in December, and offered to share experiences from its 2024 EU Action Plan to Protect the Health Sector from Cyberattacks.

A key concern raised was the increasing use of non-state actors as proxies by states, which the EU described as a maturation of a proxy model that allows sponsor states to claim plausible deniability. The EU stressed that states must be held accountable for activities conducted through proxies, in line with the law of state responsibility. The statement referenced the EU's recent sanctions on individuals and entities supporting Russia's malicious cyber activities, and noted that Estonia, supported by the EU, objected to the participation of JSC Positive Technologies, a Russian firm linked to such operations.

The EU also pointed to the rapid exploitation of zero-day vulnerabilities by new AI models, and committed to continuing threat advisories through ENISA and CERT-EU. The statement called for the Dedicated Thematic Groups to facilitate exchange on cyber threats and formulate recommendations to reinforce responsible state behaviour and collective resilience. The candidate countries North Macedonia, Montenegro, Albania, Ukraine, Moldova, Bosnia and Herzegovina, Georgia, and Norway aligned with the statement.

← Atlas › News › Foreign affairs