Western governments have increasingly used economic sanctions as a tool to disrupt state-sponsored cyber threat actors, targeting not only the hackers themselves but also the infrastructure and enablers that support their operations. Reports from the Royal United Services Institute (RUSI) highlight that sanctions are most effective when they focus on entities such as cryptocurrency mixers, hosting providers, technology suppliers, and private-sector contractors, as these groups are more vulnerable due to their reliance on the legitimate global economy. The United States has demonstrated the greatest impact with its long-standing framework, often combining sanctions with criminal indictments, diplomatic pressure, and intelligence sharing to amplify operational and reputational pressure on adversaries.
While the European Union and the United Kingdom have established newer sanction regimes, their impact has been more limited, with relatively few individuals and entities sanctioned to date. Experts emphasize that sanctions alone are insufficient to stop cyberattacks but can make operations slower, riskier, and more expensive for threat actors when integrated into broader cross-domain strategies. Recommendations for improving the effectiveness of cyber sanctions include clearer strategic intent, greater transparency, and a continued focus on disrupting the support networks that enable state-backed cyber operations.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.