Home Europe Council of the European Union Council Implementing Regulation (EU) 2025/173 of 27 January ...
Date: 27-Jan-2025 Category: Not Applicable State: Union Government Country: Europe

Council Implementing Regulation (EU) 2025/173 of 27 January 2025 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States

Issued by Council of the European Union · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

What it means

  • Council Implementing Regulation (EU) 2025/173 implements Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States. It adds three individuals to the list of natural persons subject to restrictive measures as outlined in Annex I to Regulation (EU) 2019/796.

Key Changes

  • Three natural persons are added to the list in Annex I of Regulation (EU) 2019/796.
  • The listed individuals are Nikolay Alexandro-vich Korchagin (born 16.9.1997), Vitaly Shevchenko (born 1.9.1997), and Yuriy Fedorovich Denisov (born 17.6.1980).
  • All three individuals are Russian nationals and officers of military unit 29155 of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).
  • They are listed for being involved in and responsible for cyber-attacks with a significant effect by conducting intelligence activities directed against Estonia and gaining unauthorized access to computer systems.
  • The cyber-attacks targeted computer systems to collect data regarding Estonia's cybersecurity policy, cyber capabilities, sensitive personal data, and other sensitive data, with the aim of threatening Estonia's security. The attacks concerned the storage of classified information and targeted allies and partners of Estonia.
  • The date of listing for all three individuals is 27 January 2025.

Impact Analysis

Impact on Businesses

  • Companies should report any suspected violations of the sanctions regime to the relevant authorities.

Impact on Financial Institutions

  • Financial institutions should update their compliance programs to reflect the changes introduced by this regulation.

Impact on Government Agencies

  • Government agencies should work with businesses and other stakeholders to improve cybersecurity awareness and preparedness.

Suggested Action Items

  • Report any suspected violations of the sanctions regime to the relevant authorities.

Key Entities Referenced

Council of the European Union: The institution of the EU that adopted Regulation (EU) 2025/173. Regulation (EU) 2019/796: Council Regulation (EU) 2019/796 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States. This regulation is the basis for the implementing regulation. Nikolay Alexandro-vich Korchagin: A Russian national, born on 16.9.1997, and an officer of military unit 29155 of the GRU, listed for involvement in cyber-attacks against Estonia. Vitaly Shevchenko: A Russian national, born on 1.9.1997, and an officer of military unit 29155 of the GRU, listed for involvement in cyber-attacks against Estonia. Yuriy Fedorovich Denisov: A Russian national, born on 17.6.1980, and an officer of military unit 29155 of the GRU, listed for involvement in cyber-attacks against Estonia. Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU): The Russian military intelligence agency to which the listed individuals are affiliated. Estonia: A Member State of the European Union that was the target of the cyber-attacks.
Official Source Record View Original Source →
See Full Document Text
Official Journal EN of the European Union L series 2025/173 27.1.2025 COUNCIL IMPLEMENTING REGULATION (EU) 2025/173 of 27 January 2025 implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States THE COUNCIL OF THE EUROPEAN UNION, Having regard to the Treaty on the Functioning of the European Union, Having regard to Council Regulation (EU) 2019/796 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States (1), and in particular Article 13(1) thereof, Having regard to the proposal from the High Representative of the Union for Foreign Affairs and Security Policy, Whereas: (1) On 17 May 2019, the Council adopted Regulation (EU) 2019/796. (2) Targeted restrictive measures against cyber-attacks with a significant effect which constitute an external threat to the Union or its Member States are one of the measures included in the Union’s framework for a joint diplomatic response to malicious cyber activities, namely the Cyber Diplomacy Toolbox, and are a vital instrument to prevent, deter, discourage and respond to such activities. (3) Malicious cyber activities against critical infrastructure or essential services, including through the use of ransomware and wipers, the targeting of supply chains and cyber-espionage, including intellectual property theft activities, are increasing in number, frequency and sophistication. With their disruptive and destructive effects, those activities pose a systemic threat to the Union’s security, economy and democracy and to society at large. (4) In 2020, cyber-attacks with a significant effect were carried out against Estonia. Cyber-attacks targeting the computer systems of multiple institutions were conducted with the aim of using the data to threaten the security of Estonia. Those cyber-attacks concerned the storage of classified information. (5) As part of the sustained, tailored and coordinated Union action against persistent cyber threat actors, three natural persons should be included in the list of natural and legal persons, entities and bodies subject to restrictive measures set out in Annex I to Regulation (EU) 2019/796. Those persons are responsible for, or involved in, cyber-attacks with a significant effect which constitute an external threat to the Union or its Member States. (6) Annex I to Regulation (EU) 2019/796 should therefore be amended accordingly, HAS ADOPTED THIS REGULATION: Article 1 Annex I to Regulation (EU) 2019/796 is amended in accordance with the Annex to this Regulation. Article 2 This Regulation shall enter into force on the date of its publication in the Official Journal of the European Union. This Regulation shall be binding in its entirety and directly applicable in all Member States. Done at Brussels, 27 January 2025. For the Council The President K. KALLAS (1) OJ L 129 I, 17.5.2019, p. 1, ELI: http://data.europa.eu/eli/reg/2019/796/oj. ELI: http://data.europa.eu/eli/reg_impl/2025/173/oj 1/3ANNEX In Annex I to Regulation (EU) 2019/796, the following entries are added under the heading ‘A. Natural persons’: Name Identifying information Reasons Date of listing ‘15. Nikolay Alexandro- Николай Александрович Корчагин Nikolay Korchagin is involved in and responsible for cyber-attacks with a significant 27.1.2025 vich KORCHAGIN effect by conducting intelligence activities directed against Estonia and gaining access to Date of birth: 16.9.1997 a computer system illegally. Nationality: Russian Nikolay Korchagin is an officer of military unit 29155 of the Main Directorate of the Gender: male General Staff of the Armed Forces of the Russian Federation (GRU). In that role, he is involved in and responsible for cyber-attacks against computer systems with the aim of Associated entity: Main Directorate of the General collecting data from the data systems of multiple institutions, which independently or in Staff of the Armed Forces of the Russian Federation combination, give an overview of the cyber security policy of Estonia, the cyber capabilities of the state, sensitive personal data and other sensitive data, with the aim of using the data to threaten the security of Estonia. The attacks therefore concern the storage of classified information. The attacks concerned allies and partners of Estonia. Therefore, Nikolay Korchagin is involved in and responsible for cyber-attacks with a significant effect which constitute an external threat to a Member State. 16. Vitaly SHEVCHEN- Виталий Шевченко Vitaly Shevchenko is involved in and responsible for cyber-attacks with a significant 27.1.2025 KO effect by conducting intelligence activities directed against Estonia and gaining access to Date of birth: 1.9.1997 a computer system illegally. Nationality: Russian Vitaly Shevchenko is an officer of military unit 29155 of the Main Directorate of the Gender: male General Staff of the Armed Forces of the Russian Federation (GRU). In that role, he is involved in and responsible for cyber-attacks against computer systems with the aim of Associated entity: Main Directorate of the General collecting data from the data systems of multiple institutions, which independently or in Staff of the Armed Forces of the Russian Federation combination, give an overview of the cyber security policy of Estonia, the cyber capabilities of the state, sensitive personal data and other sensitive data, with the aim of using the data to threaten the security of Estonia. The attacks therefore concern the storage of classified information. The attacks concerned allies and partners of Estonia. Therefore, Vitaly Shevchenko is involved in and responsible for cyber-attacks with a significant effect which constitute an external threat to a Member State. 2/3 ELI: http://data.europa.eu/eli/reg_impl/2025/173/oj EN OJ L, 27.1.2025Name Identifying information Reasons Date of listing 17. Yuriy Fedorovich Юрий Федорович Денисов Yuriy Denisov is involved in and responsible for cyber-attacks with a significant effect by 27.1.2025’ DENISOV conducting intelligence activities directed against Estonia and gaining access to Date of birth: 17.6.1980 a computer system illegally. Nationality: Russian Yuriy Denisov is an officer of military unit 29155 of the Main Directorate of the Gender: male General Staff of the Armed Forces of the Russian Federation (GRU). In that role, he is involved in and responsible for cyber-attacks against computer systems with the aim of Associated entity: Main Directorate of the General collecting data from the data systems of multiple institutions, which independently or in Staff of the Armed Forces of the Russian Federation combination, give an overview of the cyber security policy of Estonia, the cyber capabilities of the state, sensitive personal data and other sensitive data, with the aim of using the data to threaten the security of Estonia. The attacks therefore concern the storage of classified information. The attacks concerned allies and partners of Estonia. Therefore, Yuriy Denisov is involved in and responsible for cyber-attacks with a significant effect which constitute an external threat to a Member State. ELI: http://data.europa.eu/eli/reg_impl/2025/173/oj 3/3 OJ L, 27.1.2025 EN

Continue your research