The United Kingdom and the European Union recently announced their first joint cyber sanctions package targeting what officials describe as Russia’s “persistent and increasingly reckless” cyber and hybrid operations across Europe. On July 13, 2026, the UK sanctioned 24 individuals and entities linked to destructive cyber activity, election interference, and anti-Ukraine disinformation, including cybercriminal proxy networks tied to Russian intelligence services. The measures include sanctions against GRU senior leadership figures Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko for allegedly directing GRU cyber and hybrid threat operations, as well as action taken against IMPULS, a company accused of helping recruit hackers and cyber specialists from Russian universities and academies. The UK also imposed sanctions on individuals associated with Lumma Stealer malware that has allegedly enabled cybercriminals to collect sensitive information from compromised devices at scale and has been used by Russia to support global cyber espionage operations. There were also measures that target individuals associated with Rybar LLC, a Russian state-resourced media company accused of spreading false narratives about Ukraine and interfering in European elections, including in Moldova and Armenia.
The UK Government reported that the coordinated package reflects a broader effort by the UK, the EU, and allied governments to attribute and disrupt Russian cyber activity, including a joint attribution of the attempted attack on Poland’s energy grid to Russia’s FSB Centre 16. According to UK officials, the failed attack could have left 500,000 citizens without electricity in winter and was considered an example of Russian efforts to sow chaos across Europe.
The Council of the European Union separately announced the designation of nine Russian individuals and four entities that are part of Russia’s cyber ecosystem that enabled and facilitated cyber-attacks against the EU, its member states, and international partners. The Council acknowledged that this marks the first time that the EU and UK simultaneously adopted sanctions under their respective cyber sanctions’ regimes, which demonstrates their shared commitment to combatting Russian malicious cyber activities through coordinated action. The EU’s sanctions include restrictive measures against Bullet Proof Hosting service provider Media Land LLC, its owner Alexander Volosovik, its sister company ML.Cloud, the pro-Russia hacktivist group Z-Pentest, its leader Yuliya Vladimirovna Pankratova. The Council also targeted individuals linked to LummaC2, Trickbot, and Conti malware programs.
UK Government Press Release | Council of the EU Press Release