Home Europe Council of the European Union Council Decision (CFSP) 2024/1391 of 17 May 2024 amending De...
Date: 17-May-2024 Category: Not Applicable State: Union Government Country: Europe

Council Decision (CFSP) 2024/1391 of 17 May 2024 amending Decision (CFSP) 2019/797 concerning restrictive measures against cyber-attacks threatening the Union or its Member States

Issued by Council of the European Union · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

What it means

  • Council Decision (CFSP) 2024/1391 amends Decision (CFSP) 2019/797 concerning restrictive measures against cyber-attacks threatening the Union or its Member States.
  • The decision extends the validity of the restrictive measures until 18 May 2025.
  • The decision updates the reasons for including six persons and two entities in the list of those subject to restrictive measures.

Key Changes

  • Article 10 of Decision (CFSP) 2019/797 is amended to extend the application of the decision until 18 May 2025.
  • The annex to Decision (CFSP) 2019/797, which lists natural and legal persons, entities, and bodies subject to restrictive measures, is amended.
  • Entries 3 to 8 in the list of natural persons are replaced, updating the reasons for listing Alexey Valeryevich Minin, Aleksei Sergeyvich Morenets, Evgenii Mikhaylovich Serebriakov, Oleg Mikhaylovich Sotnikov, Dmitry Sergeyevich Badin and Igor Olegovich Kostyukov.
  • Entries 3 and 4 in the list of legal persons, entities, and bodies are replaced, updating the reasons for listing Main Centre for Special Technologies (GTsST) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU) and 85th Main Centre for Special Services (GTsSS) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU).

Impact Analysis

Governments and International Organizations

  • Third states may be impacted if they engage with the listed individuals or entities, potentially facing reputational or economic consequences.

Businesses and Organizations

  • Companies should conduct due diligence to ensure that their supply chains and business partners are not linked to the listed entities.

Individuals

  • The decision may impact the reputation and professional opportunities of the listed individuals.

Suggested Action Items

  • Provide training to relevant staff on the implications of the restrictive measures and their responsibilities for compliance.

Key Entities Referenced

Council of the European Union: The entity responsible for adopting the decision to amend Decision (CFSP) 2019/797. High Representative of the Union for Foreign Affairs and Security Policy: The entity that proposed the amendment to Decision (CFSP) 2019/797. Decision (CFSP) 2019/797: The original Council Decision concerning restrictive measures against cyber-attacks threatening the Union or its Member States. Alexey Valeryevich Minin: A Russian national listed for participating in an attempted cyber-attack against the Organisation for the Prohibition of Chemical Weapons (OPCW) and cyber-attacks against third states. A human intelligence support officer of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Aleksei Sergeyvich Morenets: A Russian national listed for participating in an attempted cyber-attack against the Organisation for the Prohibition of Chemical Weapons (OPCW) and cyber-attacks against third states. A cyber-operator for the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Evgenii Mikhaylovich Serebriakov: A Russian national listed for participating in an attempted cyber-attack against the Organisation for the Prohibition of Chemical Weapons (OPCW) and cyber-attacks against third states. Leading “Sandworm”, an actor and hacking group affiliated with Unit 74455 of the Russian Main Intelligence Directorate. Oleg Mikhaylovich Sotnikov: A Russian national listed for participating in an attempted cyber-attack against the Organisation for the Prohibition of Chemical Weapons (OPCW) and cyber-attacks against third states. A human intelligence support officer of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Dmitry Sergeyevich Badin: A Russian national listed for participating in a cyber-attack against the German federal parliament (Deutscher Bundestag) and cyber-attacks against third states. A military intelligence officer of the 85th Main Centre for Special Services (GTsSS) of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Igor Olegovich Kostyukov: A Russian national listed as the current Head of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU). Responsible for cyber-attacks carried out by the GTsSS. Main Centre for Special Technologies (GTsST): An entity of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU) involved in cyber-attacks with a significant effect originating from outside the Union and constituting an external threat to the Union or its Member States and in cyber-attacks with a significant effect against third States. 85th Main Centre for Special Services (GTsSS): An entity of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU/GRU) involved in cyber-attacks with a significant effect constituting an external threat to the Union or its Member States and in cyber-attacks with a significant effect against third States. Organisation for the Prohibition of Chemical Weapons (OPCW): An international organization targeted by an attempted cyber-attack by Russian military intelligence officers. German federal parliament (Deutscher Bundestag): The German parliament, which was the target of a cyber-attack in April and May 2015.
Official Source Record View Original Source →
See Full Document Text
Official Journal EN of the European Union L series 2024/1391 17.5.2024 COUNCIL DECISION (CFSP) 2024/1391 of 17 May 2024 amending Decision (CFSP) 2019/797 concerning restrictive measures against cyber-attacks threatening the Union or its Member States THE COUNCIL OF THE EUROPEAN UNION, Having regard to the Treaty on European Union, and in particular Article 29 thereof, Having regard to the proposal from the High Representative of the Union for Foreign Affairs and Security Policy, Whereas: (1) On 17 May 2019, the Council adopted Decision (CFSP) 2019/797 (1). (2) Decision (CFSP) 2019/797 applies until 18 May 2025. On the basis of a review of that Decision, the validity of the restrictive measures set out therein should be extended until that date. (3) In the light of continuing and increasing malicious behaviour in cyberspace, including behaviour directed against third States, the reasons for including six persons and two entities in the list of natural and legal persons, entities and bodies subject to restrictive measures set out in the Annex to Decision (CFSP) 2019/797 should be updated. (4) Decision (CFSP) 2019/797 should therefore be amended accordingly, HAS ADOPTED THIS DECISION: Article 1 Decision (CFSP) 2019/797 is amended as follows: (1) Article 10 is replaced by the following: ‘Article 10 This Decision shall apply until 18 May 2025 and shall be kept under constant review.’; (2) the Annex is amended in accordance with the Annex to this Decision. Article 2 This Decision shall enter into force on the day following that of its publication in the Official Journal of the European Union. Done at Brussels, 17 May 2024. For the Council The President H. LAHBIB (1) Council Decision (CFSP) 2019/797 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States (OJ L 129 I, 17.5.2019, p. 13). ELI: http://data.europa.eu/eli/dec/2024/1391/oj 1/9ANNEX The Annex to Decision (CFSP) 2019/797 (‘List of natural and legal persons, entities and bodies referred to in Articles 4 and 5’) is amended as follows: (1) in the list headed ‘A. Natural persons’, entries 3 to 8 are replaced by the following: Name Identifying information Reasons Date of listing ‘3. Alexey Valeryevich MININ Алексей Валерьевич МИНИН Alexey Minin took part in an attempted cyber-attack with a potentially 30.7.2020 significant effect against the Organisation for the Prohibition of Chemical Date of birth: 27.5.1972 Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant Place of birth: Perm Oblast, Russian SFSR (now effect against third States. Russian Federation) As a human intelligence support officer of the Main Directorate of the Passport number: 120017582 General Staff of the Armed Forces of the Russian Federation (GU/GRU), Alexey Minin was part of a team of four Russian military intelligence officers Issued by: Ministry of Foreign Affairs of the Russian who attempted to gain unauthorised access to the Wi-Fi network of the Federation OPCW in The Hague, the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, Validity: from 17.4.2017 until 17.4.2022 which, if successful, would have compromised the security of the network Location: Moscow, Russian Federation and the OPCW’s ongoing investigatory work. The Netherlands Defence Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst) Nationality: Russian disrupted the attempted cyber-attack, thereby preventing serious damage to Gender: male the OPCW. A grand jury in the Western District of Pennsylvania (United States of America) has indicted Alexey Minin, as an officer of the Russian Main Intelligence Directorate (GRU), for computer hacking, wire fraud, aggravated identity theft and money laundering. 2/9 ELI: http://data.europa.eu/eli/dec/2024/1391/oj EN OJ L, 17.5.2024Name Identifying information Reasons Date of listing 4. Aleksei Sergeyvich Алексей Сергеевич МОРЕНЕЦ Aleksei Morenets took part in an attempted cyber-attack with a potentially 30.7.2020 MORENETS significant effect against the Organisation for the Prohibition of Chemical Date of birth: 31.7.1977 Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant Place of birth: Murmanskaya Oblast, Russian SFSR effect against third States. (now Russian Federation) As a cyber-operator for the Main Directorate of the General Staff of the Passport number: 100135556 Armed Forces of the Russian Federation (GU/GRU), Aleksei Morenets was part of a team of four Russian military intelligence officers who attempted to Issued by: Ministry of Foreign Affairs of the Russian gain unauthorised access to the Wi-Fi network of the OPCW in The Hague, Federation the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, which, if successful, would Validity: from 17.4.2017 until 17.4.2022 have compromised the security of the network and the OPCW’s ongoing Location: Moscow, Russian Federation investigatory work. The Netherlands Defence Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst) disrupted the attempted Nationality: Russian cyber-attack, thereby preventing serious damage to the OPCW. Gender: male A grand jury in the Western District of Pennsylvania (United States of America) has indicted Aleksei Morenets, as assigned to Military Unit 26165, for computer hacking, wire fraud, aggravated identity theft and money laundering. ELI: http://data.europa.eu/eli/dec/2024/1391/oj 3/9 OJ L, 17.5.2024 ENName Identifying information Reasons Date of listing 5. Evgenii Mikhaylovich Евгений Михайлович СЕРЕБРЯКОВ Evgenii Serebriakov took part in an attempted cyber-attack with a potentially 30.7.2020 SEREBRIAKOV significant effect against the Organisation for the Prohibition of Chemical Date of birth: 26.7.1981 Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant Place of birth: Kursk, Russian SFSR (now Russian effect against third States. Federation) As a cyber-operator for the Main Directorate of the General Staff of the Passport number: 100135555 Armed Forces of the Russian Federation (GU/GRU), Evgenii Serebriakov was part of a team of four Russian military intelligence officers who attempted to Issued by: Ministry of Foreign Affairs of the Russian gain unauthorised access to the Wi-Fi network of the OPCW in The Hague, Federation the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, which, if successful, would Validity: from 17.4.2017 until 17.4.2022 have compromised the security of the network and the OPCW’s ongoing Location: Moscow, Russian Federation investigatory work. The Netherlands Defence Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst) disrupted the attempted Nationality: Russian cyber-attack, thereby preventing serious damage to the OPCW. Gender: male Since spring 2022, Evgenii Serebriakov is leading “Sandworm” (a.k.a. “Sandworm Team”, “BlackEnergy Group”, “Voodoo Bear”, “Quedagh”, “Olympic Destroyer” and “Telebots”), an actor and hacking group affiliated with Unit 74455 of the Russian Main Intelligence Directorate. Sandworm has carried out cyber-attacks on Ukraine, including Ukrainian government agencies, following Russia’s war of aggression against Ukraine. 4/9 ELI: http://data.europa.eu/eli/dec/2024/1391/oj EN OJ L, 17.5.2024Name Identifying information Reasons Date of listing 6. Oleg Mikhaylovich Олег Михайлович СОТНИКОВ Oleg Sotnikov took part in an attempted cyber-attack with a potentially 30.7.2020 SOTNIKOV significant effect against the Organisation for the Prohibition of Chemical Date of birth: 24.8.1972 Weapons (OPCW) in the Netherlands and in cyber-attacks with a significant Place of birth: Ulyanovsk, Russian SFSR (now effect against third States. Russian Federation) As a human intelligence support officer of the Main Directorate of the Passport number: 120018866 General Staff of the Armed Forces of the Russian Federation (GU/GRU), Oleg Sotnikov was part of a team of four Russian military intelligence officers Issued by: Ministry of Foreign Affairs of the Russian who attempted to gain unauthorised access to the Wi-Fi network of the Federation OPCW in The Hague, the Netherlands, in April 2018. The attempted cyber-attack was aimed at hacking into the Wi-Fi network of the OPCW, Validity: from 17.4.2017 until 17.4.2022 which, if successful, would have compromised the security of the network Location: Moscow, Russian Federation and the OPCW’s ongoing investigatory work. The Netherlands Defence Intelligence and Security Service (Militaire Inlichtingen- en Veiligheidsdienst) Nationality: Russian disrupted the attempted cyber-attack, thereby preventing serious damage to Gender: male the OPCW. A grand jury in the Western District of Pennsylvania has indicted Oleg Sotnikov, as an officer of the Russian Main Intelligence Directorate (GRU), for computer hacking, wire fraud, aggravated identity theft and money laundering. ELI: http://data.europa.eu/eli/dec/2024/1391/oj 5/9 OJ L, 17.5.2024 ENName Identifying information Reasons Date of listing 7. Dmitry Sergeyevich BADIN Дмитрий Сергеевич БАДИН Dmitry Badin took part in a cyber-attack with a significant effect against the 22.10.2020 German federal parliament (Deutscher Bundestag) and in cyber-attacks with Date of birth: 15.11.1990 a significant effect against third States. Place of birth: Kursk, Russian SFSR (now Russian As a military intelligence officer of the 85th Main Centre for Special Services Federation) (GTsSS) of the Main Directorate of the General Staff of the Armed Forces of Nationality: Russian the Russian Federation (GU/GRU), Dmitry Badin was part of a team of Russian military intelligence officers who conducted a cyber-attack against Gender: male the German federal parliament in April and May 2015. That cyber-attack targeted the parliament’s information system and affected its operation for several days. A significant amount of data was stolen and the email accounts of several MPs, as well as of former Chancellor Angela Merkel, were affected. A grand jury in the Western District of Pennsylvania (United States of America) has indicted Dmitry Badin, as assigned to Military Unit 26165, for computer hacking, wire fraud, aggravated identity theft and money laundering. 6/9 ELI: http://data.europa.eu/eli/dec/2024/1391/oj EN OJ L, 17.5.2024Name Identifying information Reasons Date of listing 8. Igor Olegovich Игорь Олегович КОСТЮКОВ Igor Kostyukov is the current Head of the Main Directorate of the General 22.10.2020’; KOSTYUKOV Staff of the Armed Forces of the Russian Federation (GU/GRU), where he Date of birth: 21.2.1961 previously served as First Deputy Head. One of the units under his Nationality: Russian command is the 85th Main Centre for Special Services (GTsSS) (a.k.a. “Military Unit 26165”, “APT28”, “Fancy Bear”, “Sofacy Group”, “Pawn Storm” Gender: male and “Strontium”). In this capacity, Igor Kostyukov is responsible for cyber-attacks carried out by the GTsSS, including those with a significant effect constituting an external threat to the Union or its Member States. In particular, military intelligence officers of the GTsSS took part in the cyber-attack against the German federal parliament (Deutscher Bundestag) in April and May 2015 and the attempted cyber-attack aimed at hacking into the Wi-Fi network of the Organisation for the Prohibition of Chemical Weapons (OPCW) in the Netherlands in April 2018. The cyber-attack against the German federal parliament targeted the parliament’s information system and affected its operation for several days. A significant amount of data was stolen and email accounts of several MPs, as well as of former Chancellor Angela Merkel, were affected. ELI: http://data.europa.eu/eli/dec/2024/1391/oj 7/9 OJ L, 17.5.2024 EN(2) in the list headed ‘B. Legal persons, entities and bodies’, entries 3 and 4 are replaced by the following: Name Identifying information Reasons Date of listing ‘3. Main Centre for Special Address: 22 Kirova Street, Moscow, Russian The Main Centre for Special Technologies (GTsST) of the Main Directorate of 30.7.2020 Technologies (GTsST) of the Federation the General Staff of the Armed Forces of the Russian Federation (GU/GRU), Main Directorate of the also known by its field post number 74455, is involved in cyber-attacks with General Staff of the Armed a significant effect originating from outside the Union and constituting an Forces of the Russian external threat to the Union or its Member States and in cyber-attacks with Federation (GU/GRU) a significant effect against third States, including the cyber-attacks publicly known as “NotPetya” or “EternalPetya” in June 2017 and the cyber-attacks directed at a Ukrainian power grid in the winter of 2015 and 2016. “NotPetya” or “EternalPetya” rendered data inaccessible in a number of companies in the Union, wider Europe and worldwide, by targeting computers with ransomware and blocking access to data, resulting amongst others in significant economic loss. The cyber-attack on a Ukrainian power grid resulted in parts of it being switched off during winter. The actor publicly known as “Sandworm” (a.k.a. “Sandworm Team”, “BlackEnergy Group”, “Voodoo Bear”, “Quedagh”, “Olympic Destroyer” and “Telebots”), which is also behind the attack on the Ukrainian power grid, carried out “NotPetya” or “EternalPetya”. Sandworm has carried out cyber-attacks against Ukraine, including Ukrainian government agencies and Ukrainian critical infrastructure, following Russia’s war of aggression against Ukraine. Those cyber-attacks include spear-phishing campaigns, malware and ransomware attacks. The Main Centre for Special Technologies of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation has an active role in the cyber-activities undertaken by Sandworm and can be linked to Sandworm. 8/9 ELI: http://data.europa.eu/eli/dec/2024/1391/oj EN OJ L, 17.5.2024Name Identifying information Reasons Date of listing 4. 85th Main Centre for Special Address: Komsomol’skiy Prospekt, 20, Moscow, The 85th Main Centre for Special Services (GTsSS) of the Main Directorate of 22.10.2020’. Services (GTsSS) of the Main 119146, Russian Federation the General Staff of the Armed Forces of the Russian Federation (GU/GRU) Directorate of the General (a.k.a. “Military Unit 26165”, “APT28”, “Fancy Bear”, “Sofacy Group”, “Pawn Staff of the Armed Forces of Storm” and “Strontium”) is involved in cyber-attacks with a significant effect the Russian Federation constituting an external threat to the Union or its Member States and in (GU/GRU) cyber-attacks with a significant effect against third States. In particular, military intelligence officers of the GTsSS took part in the cyber-attack against the German federal parliament (Deutscher Bundestag) in April and May 2015 and the attempted cyber-attack aimed at hacking into the Wi-Fi network of the Organisation for the Prohibition of Chemical Weapons (OPCW) in the Netherlands in April 2018. The cyber-attack against the German federal parliament targeted the parliament’s information system and affected its operation for several days. A significant amount of data was stolen and email accounts of several MPs, as well as of former Chancellor Angela Merkel, were affected. Following Russia’s war of aggression against Ukraine, cyber-attacks by the GTsSS (spear-phishing and malware-based attacks) were carried out against Ukraine. ELI: http://data.europa.eu/eli/dec/2024/1391/oj 9/9 OJ L, 17.5.2024 EN

Continue your research