Changeflow GovPing Trade & Sanctions EU Council Sanctions Three Entities and Two Ind...
Urgent Enforcement Added Final

EU Council Sanctions Three Entities and Two Individuals for Cyber-Attacks

Favicon for www.consilium.europa.eu EU Council Sanctions Press Releases
Filed March 16th, 2026
Detected March 17th, 2026
Email

Summary

The Council of the EU has imposed sanctions on three entities and two individuals for their involvement in malicious cyber-attacks targeting EU member states and partners. The measures include asset freezes and travel bans, expanding the EU's horizontal cyber sanctions regime.

What changed

The Council of the EU has adopted restrictive measures against three entities (Integrity Technology Group and Anxun Information Technology from China, and Emennet Pasargad from Iran) and two Chinese individuals for their roles in cyber-attacks. These attacks include compromising over 65,000 devices, targeting critical infrastructure, spreading disinformation during the Paris Olympic Games, and compromising a Swedish SMS service. These listings bring the total number of individuals and entities under the EU's cyber sanctions regime to 19 and 7, respectively.

Regulated entities within the EU must immediately cease all financial and economic dealings with the sanctioned parties, including making funds or economic resources available to them. Natural persons listed also face a travel ban preventing entry into EU territories. Compliance officers should review their existing due diligence processes to ensure no prohibited transactions occur with these newly listed parties. Failure to comply can result in significant penalties under EU sanctions law.

What to do next

  1. Review and update sanctions lists to include the newly designated entities and individuals.
  2. Ensure no funds, financial assets, or economic resources are made available to the sanctioned parties.
  3. Verify that travel to or transit through EU territories by the sanctioned individuals is prevented.

Penalties

Asset freeze for all listed parties; prohibition for EU citizens and companies from making funds, financial assets, or economic resources available to them; travel ban for natural persons.

Source document (simplified)

  • Council of the EU
  • Press release
  • 16 March 2026 14:10

Cyber-attacks against the EU and its member states: Council sanctions three entities and two individuals


The Council adopted today restrictive measures against three entities and two individuals responsible for cyber-attacks carried out against EU member states and EU partners.

The Council has listed Integrity Technology Group, a China-based company, that has routinely provided products used to compromise and access devices in EU members states, across Europe and worldwide. Between 2022 and 2023, through their technical and material support, more than 65,000 devices were hacked across six member states .

Similarly, Anxun Information Technology, a China-based company, has provided hacking services aimed at the critical infrastructure and critical functions of member states and third countries. The two Chinese individuals also listed today by the Council, are co-founders of the company and were responsible for and involved in cyber-attacks affecting EU member states.

Lastly, the Iranian company Emennet Pasargad has unlawfully gained access to a French subscriber database and advertised its contents for sale on the dark web. They also compromised advertising billboards to spread disinformation during the 2024 Paris Olympic Games. Additionally, the company compromised a Swedish SMS service, impacting a large number of EU citizens.

Those listed today under both regimes are subject to an asset freeze, and EU citizens and companies are forbidden from making funds, financial assets or economic resources available to them. Natural persons also face a travel ban that prohibits them from entering or transiting through EU territories.

With today’s listings the EU horizontal cyber sanctions regime now applies to 19 individuals and 7 entities.

Today’s decision confirms EU’s and its member states’ willingness to provide a strong and sustained response to persistent malicious cyber activities targeting the EU, its member states and partners. The EU and its member states will continue to cooperate with our international partners to promote an open, free, stable and secure cyberspace.

The relevant legal acts have been published in the Official Journal of the European Union.

Background

The Framework for a Joint EU Diplomatic Response to Malicious Cyber Activities (the " cyber diplomacy toolbox ") was established in June 2017. It allows the EU and its member states to use all CFSP measures, including restrictive measures if necessary, to prevent, discourage, deter and respond to malicious cyber activities targeting the integrity and security of the EU and its member states.

In May 2019, the Council established a framework of sanctions allowing the EU to impose targeted restrictive measures to deter and respond to cyber-attacks which constitute an external threat to the EU or its member states.


Visit the meeting page

Press contacts


Topics
- Foreign affairs
- Cybersecurity
- Digital infrastructure
- Sanctions

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
EU Council
Filed
March 16th, 2026
Instrument
Enforcement
Legal weight
Binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Importers and exporters Technology companies
Geographic scope
EU-wide

Taxonomy

Primary area
Sanctions
Operational domain
Compliance
Topics
Cybersecurity International Trade

Get Trade & Sanctions alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when EU Council Sanctions Press Releases publishes new changes.

Free. Unsubscribe anytime.