Council Implementing Regulation (EU) 2026/589 of 16 March 2026 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States
ID: 2e1dae44-b4c9-4c0c-bf45-298e23a0fdb9
STIX ID: report--2e1dae44-b4c9-4c0c-bf45-298e23a0fdb9
Threat Score
85/100
Uploaded: 2026-08-05
Published Date: 2026-03-16
Last Modified Date: 2026-03-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Council Implementing Regulation (EU) 2026/589 (16 March 2026) amends Annex I to Regulation (EU) 2019/796 to add two natural persons (Chen Cheng, Wu Haibo) and multiple legal entities (including Anxun Information Technology Co. Ltd., Integrity Technology Group, and Emennet Pasargad) to the EU restrictive measures list for their roles in cyber-attacks. The text alleges hacking‑for‑hire activity, facilitation of an APT (“Flax Typhoon”) that used commercial products to compromise at least 65,600 IoT devices across six Member States (2022–2023), targeting of critical infrastructure and state functions, sale of classified information, and disruptive operations including election interference and high‑profile compromises.
