UK and EU Impose First Joint Sanctions on Russian Cyber Actors
The UK and EU have taken a landmark step in cybersecurity diplomacy, jointly imposing sanctions on Russian individuals and entities for the first time in response to state-sponsored cyberattacks and disinformation campaigns. The coordinated action, announced by the UK's Foreign, Commonwealth and Development Office (FCDO) and the European Council, targets actors linked to Russia's military intelligence service (GRU), including the notorious Unit 29155, which Western intelligence agencies have tied to operations like the WhisperGate wiper attacks against Ukraine and persistent influence operations across Europe.
The sanctions package includes asset freezes and travel bans on six individuals and the designation of several entities, including the 18th Center for Information Security (Military Unit 26165), tracked in open-source reporting as APT28 or Fancy Bear. According to the FCDO, these actors have been responsible for a sustained campaign of cyber espionage, hack-and-leak operations, and the deployment of wiper malware targeting critical infrastructure in Ukraine and NATO member states. The EU simultaneously sanctioned GRU officers and front companies accused of running disinformation networks designed to manipulate European elections and amplify pro-Kremlin narratives through fabricated personas and spoofed media properties.
This joint designation signals a meaningful shift in the transatlantic response to Russian cyber aggression. Previously, the UK and EU have acted separately on cyber sanctions, but the unified action demonstrates growing alignment in attributing and punishing state-sponsored intrusions. Researchers at Mandiant and CrowdStrike have long documented the overlap between GRU cyber operations and information warfare campaigns, noting that technical infrastructure—such as compromised mail servers, burner domains, and residential proxy networks—is often shared between espionage units and influence-operations teams. In several indictments, the US Department of Justice has linked the same Unit 26165 operators to spear-phishing campaigns against Democratic Party targets and the NotPetya outbreak, which caused more than $10 billion in global damages in 2017.
For organizations operating in the targeted sectors—defense, energy, government, and media—the action underscores the need for enhanced threat intelligence and operational hygiene. Defenders should audit outbound DNS configurations using a DNS leak test to identify unintended resolver exposures, and run a privacy checkup to surface metadata leaks that could fuel social engineering against staff. Security teams should also verify the integrity of executive and supplier email accounts with a email breach checker, since GRU-linked spear-phishing has historically exploited credential reuse and unpatched edge devices. The sanctions also designate Russian media entities accused of laundering disinformation, raising the stakes for supply-chain trust in the broader information ecosystem.