The EU Council imposed sanctions on three entities and two individuals over cyberattacks targeting EU member states and partners. The measures include asset freezes, a ban on EU persons and companies providing funds or economic resources to those listed, and travel bans for the individuals. The action expands the EU cyber sanctions regime to 19 individuals and 7 entities, underscoring a coordinated response to persistent malicious cyber activity affecting Europe.
The sanctioned parties include China-based Integrity Technology Group, which the Council said provided products used to compromise devices in EU member states and worldwide, contributing to the hacking of more than 65,000 devices across six member states between 2022 and 2023. Also listed were Anxun Information Technology and its two co-founders for providing hacking services targeting critical infrastructure and critical functions in member states and third countries. The Iranian company Emennet Pasargad was sanctioned for accessing a French subscriber database and offering it for sale on the dark web, compromising advertising billboards to spread disinformation during the 2024 Paris Olympic Games, and breaching a Swedish SMS service affecting a large number of EU citizens.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-16, the Council of the European Union sanctioned Integrity Technology Group, Anxun Information Technology, Emennet Pasargad, and i-Soon executives Wu Haibo and Chen Cheng for cyberattacks and influence operations targeting EU member states and partners. The measures included asset freezes, bans on EU persons and companies providing funds or economic resources, and travel bans for the listed individuals.
In 2025, the US Department of Justice charged 12 people tied to i-Soon over cyberattacks allegedly conducted on behalf of Chinese security services.
The references state that the EU measures followed earlier US sanctions against Emennet Pasargad for its cyber and influence operations.
Prior to the EU action, the United States sanctioned Integrity Technology Group for its role in enabling Flax Typhoon and the Raptor Train botnet's large-scale IoT compromises.
During the 2024 Paris Olympic Games, Emennet Pasargad was linked to the compromise of advertising displays used to spread anti-Israel propaganda and disinformation.
Leaked materials in 2024 indicated that Anxun Information Technology, also known as i-Soon, took assignments from China's Ministry of Public Security, reinforcing allegations that it operated as a hack-for-hire contractor.
Emennet Pasargad was also tied to the compromise of an SMS service in Sweden that was used in a campaign affecting thousands of citizens under the 'Anzu Team' alias.
Emennet Pasargad was linked to the theft of Charlie Hebdo subscriber data and the attempted sale of that information on the dark web, an incident the EU later referenced in its sanctions decision.
Between 2022 and 2023, tools supplied by China's Integrity Technology Group were used in activity linked to Flax Typhoon that compromised more than 65,000 devices across six EU member states.
The EU later cited Tehran-based Emennet Pasargad for attempted interference in the 2020 US election as part of the activity underlying its 2026 cyber sanctions action.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcescworld.com
Open sourcerisky.biz
Open sourcenews.risky.biz
Open sourcehelpnetsecurity.com
Open sourceeclypsium.com
Open sourcego.theregister.com
Open sourceconsilium.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.