Data Privacy & Tech

#32026D1079EU Extends Cyber Sanctions Listings Until May 2027

🇪🇺European Union··Other·Medium Impact·View source ↗

AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.

🇬🇧 English

This decision keeps EU cyber sanctions in place for the people and entity already listed under the EU regime for major cyber-attacks. The asset-freeze and travel-ban measures for listed persons and entities are extended until 18 May 2027, while the wider sanctions framework remains in force until 18 May 2028. The decision also updates the reasons for listing four individuals and one Chinese company linked to APT10, Operation Cloud Hopper, Wizard Spider, Conti, Trickbot, Ryuk and Black Basta activity. Businesses, banks, compliance teams and cybersecurity vendors should treat these listings as current and make sure sanctions screening, customer checks and transaction controls reflect the updated entries.

AI-generated summary. May contain errors. Refer to official sources for legal decisions.

Key Changes

  • Extends cyber-related restrictive measures for listed persons and entities until 18 May 2027
  • Confirms that the broader EU cyber sanctions decision remains applicable until 18 May 2028
  • Updates listing reasons for four individuals and one company linked to major cyberattack groups and campaigns

Obligations

What this law requires

critical

Apply the restrictive measures set out in Articles 4 and 5 of Decision (CFSP) 2019/797 to all natural and legal persons, entities and bodies listed in the Annex until 18 May 2027.

EU Member StatesEU sanctions authoritiesEU operators subject to EU restrictive measures
Measures apply until 18 May 2027
prohibition
high

Treat Gao Qiang as a currently listed natural person under the EU cyber sanctions regime, based on updated reasons linking him to APT10, Operation Cloud Hopper and Huaying Haitai.

EU sanctions screening teamsfinancial institutionsregulated businesses
Listing measures extended until 18 May 2027
operational
high

Treat Zhang Shilong as a currently listed natural person under the EU cyber sanctions regime, based on updated reasons linking him to APT10, Operation Cloud Hopper, malware development and Huaying Haitai.

EU sanctions screening teamsfinancial institutionsregulated businesses
Listing measures extended until 18 May 2027
operational
high

Treat Mikhail Mikhailovich Tsarev as a currently listed natural person under the EU cyber sanctions regime, based on updated reasons linking him to Wizard Spider and deployment of Conti and Trickbot malware.

EU sanctions screening teamsfinancial institutionsregulated businesses
Listing measures extended until 18 May 2027
operational
high

Treat Maksim Sergeevich Galochkin as a currently listed natural person under the EU cyber sanctions regime, based on updated reasons linking him to Wizard Spider and development, testing and deployment of Trickbot and Conti malware.

EU sanctions screening teamsfinancial institutionsregulated businesses
Listing measures extended until 18 May 2027
operational

Affected Parties

Banks and financial institutions handling sanctions screeningCompanies doing business with international counterparties+2 more…

Tags

EU sanctions,cybersecurity,restrictive measures…
EU Extends Cyber Sanctions Listings Until May 2027 | Legiseye