Europe’s Improvised Autonomy on Ransomware, Without Washington
Europe’s Improvised Autonomy on Ransomware, Without Washington
In July 2026, the EU and Britain sanctioned Russian hackers without waiting for Washington to act first, proving that the Union can already impose costs on its adversaries. The next step is turning that proven capability into a lasting, repeatable policy.
Image Credit: Euro Prospects
By Margherita Rossi, Cyber Defense Analyst, Security & Defence Unit
Edited by Luca Rastelli, AI & Defense Governance
15 September 2026
For most of the past decade, Europe’s response has rested on an unstated division of labour. Brussels and the EU member states wrote the rules: data protection, incident reporting, sectoral resilience obligations. However, the instruments that actually raised the cost of attacking Europe were assembled elsewhere, in Washington’s sanctions list and law-enforcement operations. That arrangement was never formalised, but it was consistent enough to shape how European institutions thought about their own role: as regulators of resilience, not as authors of deterrence.
That assumption no longer describes reality. Over the past year, European agencies have led major operations against ransomware infrastructure, and in July 2026 the European Union and the United Kingdom jointly sanctioned Russia’s malicious cyber ecosystem (its intelligence services and the criminal proxies they task) attributing, among other operations, a sabotage attempt on Poland’s energy grid to the FSB. This happened without waiting for, or receiving, comparable actions from Washington. Europe, in other words, is already behaving like an independent actor, able to impose costs. What is still missing is not the capability but the doctrine: a framework that treats ransomware as an object of foreign, security, and defence policy rather than as a compliance obligation. This article traces how that gap opened, what Europe’s improvised response to it currently looks like, and what would be required to convert improvisation into a durable posture.
Crime as a Service: Industrialisation Without Accountability
The strategic weight ransomware now carries cannot be separated from its industrialisation through the so-called Ransomware-as-a-Service (RaaS) environment. By splitting cyber extortion into a service economy that includes malware development, access brokerage, negotiation, and laundering all handled by separate actors, RaaS has lowered the technical bar for conducting high impact attacks while protecting the developers who profit most from direct operational exposure. Europol has noted that this fragmentation complicates attribution and undermines the deterrent logic that law enforcement traditionally relies on: responsibility for an attack is spread across several actors, none of whom carried out the whole thing, which makes it hard to know who to punish.
The deeper effect of the industrialisation of ransomware attacks is redistribution of responsibility. RaaS ecosystems separate ownership of malware from execution of the attack, which means that liability does not settle on a single identifiable actor. These strategies make ransomware the perfect instrument for criminal grey zones: a model that diffuses blame by design is, functionally, a model built for deniability, which is exactly what makes disruption through RaaS sustainable without triggering the kind of response reserved for clearly attributable state action.
This is where ransomware’s strategic function becomes clearly visible. Its persistence depends less on technical sophistication than on state tolerance: many of the most active and damaging groups of recent years, such as REvil, Conti, and LockBit, operated for extended periods from jurisdictions where cybercrime enforcement was weak or subordinated to other priorities. Notably, Conti’s 2022 declaration of allegiance to Russian state interests, followed only by fragmentation rather than its dismantlement, illustrated concretely how these ecosystems adapt and persist even after high-profile exposure.
It is worth stressing that groups operating under this kind of permissive cover increasingly resemble de facto proxies. Proxies are usually agents, groups, or entities that act on behalf of a more powerful primary actor to achieve disruption and strategic objectives while keeping the primary actor at a safe distance. In this case, ransomware groups do not act under direct instruction of a state or a primary actor. However, their activity generates disruption abroad while preserving deniability for the states that decline to act against them. The attacks themselves are calibrated to target institutional reliability and erode public trust, rather than causing irreversible damage. Among the sectors that suffer the most from these attacks are public administrations (at the national and local levels), digital financial services, healthcare, transport, and energy providers, precisely because disruption in these areas converts quickly into political pressure and governance stress. However, as mentioned, these effects are cumulative but they sit consistently below the threshold of armed conflict. For permissive states willing to tolerate ransomware activity on their territory, this translates into a strategic asset: pressure on opponents obtained without the diplomatic cost of an operation they could be linked to.
This is the backdrop against which the July 2026 sanctions should be read. The package did not target a ransomware operation as such: it named a wider state–criminal ecosystem (the intelligence services and the cybercriminals, hacktivists, and front companies they task) and attributed the attempted sabotage of Poland’s energy grid specifically to the FSB’s Centre 16. Russia operates across a spectrum running from deniable criminal proxies to directly attributable state action, and by naming actors along its full length the EU and UK attempted precisely the move the RaaS model is built to prevent: pushing responsibility up the chain, to the state.
Coercion Without a Guarantor
What has changed in the European response to this dynamic? Over the past two years, European law-enforcement agencies have taken the lead in some of the largest disruption operations conducted against cybercriminal groups, degrading the criminal ecosystem’s technical backbone.
The most recent example is the joint sanctions package issued by the EU and the United Kingdom on 13 July 2026. This operation, the first of its kind, attributed a sustained campaign of infrastructure sabotage and intrusion to Centre 16 of Russia’s FSB, the Federal Security Service of the Russian Federation. The package named the FSB unit as responsible for an attempt to sabotage Poland’s energy sector in December 2025, possibly causing major disruptions to hundreds of thousands of people during the coldest months of the year. The EU sanctioned nine individuals and four different entities, while the UK designated twenty-four names on the same day. Several member states also summoned Russian diplomatic representatives in protest. Kaja Kallas, the High Representative of the European Union for Foreign Affairs and Security Policy, delivered a statement on behalf of the Union linking the disruption campaign to other targets across Member States.
What stands out about this episode is the actors involved: the coordination for this sanctions package was European and British, with no equivalent American designation issued alongside it and no mention of Washington in Kallas’ statement. Moreover, the coverage of the package mentioned NATO welcoming the action but noted no accompanying statement from Washington. This silence itself carries important information. The EU-UK action was announced on a day when US sanctions were concentrated elsewhere, on Iran, following the rising of the tensions in the Strait of Hormuz. This, combined with the Trump administration’s rhetorical disengagement from NATO and increasingly hostile posture toward European allies, suggests that the EU-UK action of July 2026 should be read as an early instance of a pattern: Europe acting on its own because it can no longer assume someone else will.
Two clarifications are needed here. First, the dynamic outlined falls into the “coercion by coalition” category, not “coercion by institution.” The July sanctions package was a bilateral EU-UK arrangement built ad hoc for the occasion and not the outcome of a standing mechanism designed to repeat itself. Second, the European Union leaned on a partner that sits outside of Brussels’ institutional reach. The UK’s departure from the EU means some of the most capable coercive tools currently are not directly at Brussels’ disposal. This last point raises a genuine question about the practical meaning of European autonomy, given that its most recent coercive expression required a non-member state to intervene.
The Limits of the EU’s Regulatory Response
The question about European autonomy also points to a gap within the EU institutions. The disruption operations and coordinated action mentioned above sit almost entirely outside the Union’s formal ransomware framework: the Union’s regulatory architecture (NIS2, DORA, Cyber Resilience Act) expanded considerably over the past decade, and these instruments have helped considerably in standardising incident reporting, raising baseline resilience requirements, improving cross-border collaboration and information-sharing, and more. But this framework’s logic is mostly defensive. Nowhere in NIS2, DORA, or the CRA is there a mechanism that automatically triggers the attribution of an attacker or a sanctions response when a covered entity is hit. Each ransomware attack on a hospital, for instance, is absorbed as a compliance failure to be reported and remediated, not a hostile attack to be answered. In brief, the regulatory framework is built to reduce the probability and impact of attacks landing, not to implement deterrence systems and raise the cost paid by attackers. Sanctions and diplomatic signalling remain ad hoc instruments of the foreign policy action of the Union.
One consequence is that the EU’s most visible action against ransomware and the EU’s description of the problem are starting to diverge. Member states continue to experience uneven implementation of existing directives, which has produced a transposition gap: as of mid-2026, only around 20 of 27 states had transposed NIS2 into national law. Meanwhile, the coercive half of Europe’s response, demonstrated in July, is developing largely outside this framework, through coalition diplomacy that has no guarantee of repetition.
Conclusion
The EU-UK bilateral coalition worked, but coalition is not a doctrine, and that gap is the real subject of this article. It is no longer possible to describe ransomware as a low-level criminal activity managed through compliance obligations. On the contrary, it is a persistent instrument of grey-zone pressure, sustained by permissive jurisdictions and industrialised through RaaS ecosystems, and Europe’s recent activity shows that it already understands this. The July 2026 sanctions package demonstrates that European and British institutions can attribute, sanction, and coordinate a public response to state-linked cyber operations without depending on Washington to move first. What Europe has not yet done is turn that capability into a formal policy. That could mean a standing EU-UK cyber coordination mechanism, or a formal trigger linking major ransomware attacks on critical infrastructure to the EU’s existing cyber sanctions regime, so that attribution and response are not improvised anew each time.
Addressing and, consequently, closing that gap does not require militarising the response to ransomware or displacing law enforcement. It requires embedding the capabilities utilised in the bilateral collaboration with the UK into the same strategic frameworks that already govern the EU’s foreign and security policy.
Disclaimer: While Euro Prospects encourages open and free discourse, the opinions expressed in this article are those of the author(s) and do not necessarily reflect the official policy or views of Euro Prospects or its editorial board.

