logo

Council Implementing Regulation (EU) 2026/589 of 16 March 2026 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States

ID: 2e1dae44-b4c9-4c0c-bf45-298e23a0fdb9

STIX ID: report--2e1dae44-b4c9-4c0c-bf45-298e23a0fdb9

Threat Score

85/100

Uploaded: 2026-08-05

Published Date: 2026-03-16

Last Modified Date: 2026-03-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Council Implementing Regulation (EU) 2026/589 (16 March 2026) amends Annex I to Regulation (EU) 2019/796 to add two natural persons (Chen Cheng, Wu Haibo) and multiple legal entities (including Anxun Information Technology Co. Ltd., Integrity Technology Group, and Emennet Pasargad) to the EU restrictive measures list for their roles in cyber-attacks. The text alleges hacking‑for‑hire activity, facilitation of an APT (“Flax Typhoon”) that used commercial products to compromise at least 65,600 IoT devices across six Member States (2022–2023), targeting of critical infrastructure and state functions, sale of classified information, and disruptive operations including election interference and high‑profile compromises.