On 16 March 2026, the Council of the European Union imposed cyber-sanctions on three companies—two based in China and one in Iran—and two Chinese individuals. The Council linked them to hacking operations affecting EU member states, including attacks on more than 65,000 devices across six member states during 2022–2023 that it said received technical and material support from Integrity Technology Group. These are the Council’s stated reasons for listing the parties, not findings that this article independently verifies or a claim that every allegation was adjudicated in court.
Who the EU listed on 16 March 2026
The Council announced restrictive measures against three entities and two individuals under the EU’s cyber-sanctions framework. Its release attributed the following conduct to them:
| Listed party | What the Council said |
|---|---|
| Integrity Technology Group (China) | The company routinely provided products used to compromise and access devices in EU member states, elsewhere in Europe and worldwide. The Council said that more than 65,000 devices in six member states were hacked during 2022–2023 with the company’s technical and material support. |
| Anxun Information Technology (China) | The Council said the company provided hacking services targeting critical infrastructure and critical state functions in EU member states and third countries. |
| Two Chinese individuals | The Council described the individuals as Anxun co-founders and said they were responsible for or involved in attacks affecting EU member states. |
| Emennet Pasargad (Iran) | The Council said the company gained unlawful access to a French subscriber database and advertised its contents for sale on the dark web; compromised advertising billboards to spread disinformation during the 2024 Paris Olympic Games; and compromised a Swedish SMS service, affecting many EU citizens. |
The conduct in the table is the Council’s account of the legal listing reasons. The announcement does not make these allegations independent findings of fact.
What the 65,000-device figure means
The figure is specific: the Council said more than 65,000 devices across six EU member states were hacked between 2022 and 2023 through Integrity Technology Group’s technical and material support. It is not a figure for all cyberattacks in Europe, all activity by the listed companies, or the number of people affected. The Council did not identify the individual devices or provide a further breakdown in the March announcement.
#1 Best Overall
- APPLIANCE ONLY: Hardware unit sold without a service subscription — security services, firmware updates and support are NOT included and must be purchased separately to activate protection.
- PERFORMANCE: Up to 2.5 Gbps firewall inspection, 1 Gbps threat prevention and 1.2 Gbps IPSec VPN throughput driven by SonicWall's patented Reassembly-Free Deep Packet Inspection (RFDPI) engine.
- CONNECTIVITY: 8x1GbE + 2x1G SFP in a desktop form factor; zero-touch deploy and manage on-box or via cloud Network Security Manager (NSM).
- THREAT PROTECTION: SonicOS 8 delivers intrusion prevention, gateway anti-malware, application control, TLS/SSL decryption, Capture ATP multi-engine sandboxing (RTDMI) and reputation-based content & DNS filtering with an active service subscription.
- BUILT FOR SMALL BUSINESS & BRANCH: Secure SD-WAN, IPSec and SSL VPN plus Zero-Trust Network Access through Cloud Secure Edge keep distributed sites and remote workers protected.
What the cyber-sanctions do
The EU’s horizontal cyber-sanctions regime can target people or entities the Council considers responsible for, supporting, or otherwise involved in cyberattacks or attempted attacks with significant impact that constitute an external threat to the EU or its member states. The Council established this framework in May 2019; the EU cyber diplomacy toolbox dates to June 2017.
- Asset freezes: Listed people and entities have their funds and economic resources frozen.
- Travel bans: Listed individuals are subject to a ban on entering or transiting through EU territory.
- Prohibition on making resources available: EU persons and companies may not make funds or economic resources available to listed parties, directly or indirectly.
The March release stated: “Those listed today under both regimes are subject to an asset freeze, and EU citizens and companies are forbidden from making funds, financial assets or economic resources available to them.” This was an institutional statement by the Council of the EU, not a quotation attributed to a named speaker. For practical compliance, people and businesses should consult the applicable legal acts and official guidance rather than rely on a news summary.
Rank #2
- SECURE UPGRADE PLUS PROGRAM (2-Yr, Advanced Edition): SonicWall upgrade path that bundles a new TZ280 appliance with the Advanced Protection Suite (APSS). REQUIREMENTS: for customers upgrading from an existing SonicWall firewall; a qualifying prior unit may be required at registration.
- SERVICE BUNDLE – ADVANCED PROTECTION SUITE (APSS): all Essential services plus Capture ATP cloud sandboxing with patented RTDMI, advanced DNS security, cloud Network Security Manager (NSM) management, reporting & analytics, and 24/7 support — SonicWall's recommended all-in security suite.
- PERFORMANCE: Up to 2.5 Gbps firewall inspection, 1 Gbps threat prevention and 1.2 Gbps IPSec VPN throughput driven by SonicWall's patented Reassembly-Free Deep Packet Inspection (RFDPI) engine.
- CONNECTIVITY: 8x1GbE + 2x1G SFP in a desktop form factor; zero-touch deploy and manage on-box or via cloud Network Security Manager (NSM).
- BUILT FOR SMALL BUSINESS & BRANCH: Secure SD-WAN, IPSec and SSL VPN plus Zero-Trust Network Access through Cloud Secure Edge keep distributed sites and remote workers protected.
How the list changed after the March announcement
The March round is not the latest addition reflected in the Council’s published count. The Council’s policy page records an extension of the regime until 18 May 2027. On 13 July 2026, Council Decision (CFSP) 2026/1713 added eight natural persons and four entities; the act describes them as responsible for, supporting, or involved in cyberattacks with significant effect constituting an external threat to the Union or its member states.
As shown on the Council policy page last reviewed on 13 July 2026, the regime covered 27 individuals and 11 entities. That total includes additions made after the 16 March announcement, so it is not the number listed in the March round alone. The total can change as the EU adopts further measures.
Recommended Free Tools
This article concerns the EU’s horizontal cyber-sanctions framework and these specific listings. It does not describe separate EU sanctions regimes concerning Iran or China.
Quick Recap
Best Value
- SonicWall TZ370 High Availability Unit (02-SSC-6443) - Seamless Failover Protection: Designed to pair with a primary SonicWall firewall for automatic failover and continuous network uptime. Not a Standalone unit - requires an identical primary SonicWall appliance; cannot function independently.
- Protects against encrypted malware and intrusions using DPI-SSL inspection, IPS, anti-malware, and Capture ATP sandboxing with RTDMI detection.
- Secure SD-WAN intelligently steers traffic across links to reduce MPLS costs and improve cloud application performance for branch users.
- Zero-Touch deployment, SonicExpress onboarding, and centralized management via Network Security Manager simplify rollout and ongoing operations.
- Scales up to 900,000 to 1,000,000 concurrent connections depending on policy mix, supporting secure growth across users and devices.
Rank #4
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




