London names 24 targets in a new cyber-sanctions round, sharpening the line between criminal proxy and state customer
Britain's Foreign Office has blacklisted 24 individuals and entities tied to destructive cyber and hybrid operations, including criminal proxy networks. The move is short on operational detail and long on signalling.

Britain's Foreign Office added 24 individuals and entities to its sanctions list on 13 July 2026, citing their role in "destructive cyber and hybrid operations" and the use of criminal proxy networks to launder state-directed attacks through commercial infrastructure. The designations, published via a Telegram summary by the Open Source Intel channel at 09:04 UTC, are the latest in a string of UK cyber-sanctions packages that have grown steadily more pointed since Russia's full-scale invasion of Ukraine.
The pattern is no longer novel. What matters is what London is now willing to say out loud: that the line between cybercriminal-for-hire and state customer has effectively dissolved in several theatres, and that the British government intends to treat the front company as a sanctioned target in its own right.
A wider net, fewer details
The Foreign Office has not, in the public summary circulated on 13 July, released the full operational dossier behind each of the 24 listings. That is consistent with British practice: designations name entities, sometimes alias networks, and freeze UK-held assets while travel bans bite in theory. The accompanying language, however, is sharper than earlier rounds, leaning on the phrase "destructive cyber and hybrid operations" rather than the softer "malicious cyber activity" that characterised 2023 and 2024 packages.
The shift is not cosmetic. "Hybrid" in UK and NATO usage covers the spectrum from influence operations through sabotage of undersea cables to paid criminal groups renting ransomware infrastructure to state services. By naming that envelope explicitly, London signals it will treat a ransomware affiliate as a sanctioned target if the trail leads back to a hostile intelligence customer.
That is a substantial legal claim to make on a Treasury notice. It also raises the bar for any future prosecution, since defendants can be expected to argue the criminal acts were never theirs. The Foreign Office will need to back the listing with public attribution documents in at least some of the 24 cases, or the package risks reading as a press release rather than a deterrent.
The proxy question nobody wants to answer
The designator of choice, "cybercriminals operating in proxy networks", is doing the analytical heavy lifting. The phrase mirrors language that has crept into EU Council conclusions since 2024 and into the US Treasury's Office of Foreign Assets Control advisories on ransomware payment risk. It concedes a fact that cyber defenders have documented for years: the same crews that hit hospitals, logistics firms and local councils on a Tuesday are sometimes back at work on behalf of an intelligence service on a Wednesday.
The question this leaves open is which state. London is unlikely to name a customer in a package designed to be deniable by the very actors it targets. The wider public record, however, points in one direction. The bulk of criminal-proxy cyber capacity with the operational sophistication to run destructive operations against NATO members sits in jurisdictions where Russian, Iranian and North Korean services have historically recruited. Naming the proxy without naming the principal is a deliberate halfway house: it lets the Treasury move, and it lets the customer plausibly deny.
That halfway house has been the British default since at least the December 2023 package that hit the Trickbot and Conti-linked infrastructure. The 24-name round extends the doctrine without breaking it.
What sanctions actually do here
UK cyber sanctions have a narrow technical footprint. They freeze UK-held assets, bar UK persons from making funds or services available to designated individuals, and trigger travel bans in jurisdictions that cooperate with London. For a 24-year-old ransomware operator in a non-extradition jurisdiction, the practical effect is closer to reputational than custodial.
The point is leverage rather than arrest. Designations feed into Five Eyes intelligence sharing, into EU restrictive measures where member states choose to mirror them, and into the due-diligence obligations of banks, crypto exchanges and legal firms. A listed name becomes more expensive to launder through, which over time narrows the rent the operator can extract.
The structural reading is plain. Cyber-sanctions are not a substitute for cyber-defence, and they do not displace the slow work of attribution, indictment and arrest. They are the financial architecture that makes the rest of the system more expensive to game.
The credibility test ahead
The harder question is what the package costs London diplomatically. Designating criminal proxies without naming the customer preserves a fiction that several governments find useful; pressing harder on attribution will not. If a future round of 24 names is followed by a criminal indictment under the National Crime Agency's Operation Destabilise template, the model used against the Russian-linked money-laundering networks in 2024 and 2025, the doctrine starts to look like a serious instrument. If it is followed by another package of names, the doctrine begins to look like an annual press event.
Two indicators are worth watching over the next quarter. First, whether any EU member state formally mirrors the 13 July list through its own restrictive-measures framework, which would multiply the financial impact across the single market. Second, whether any of the 24 designations are eventually paired with a public indictment in a UK or allied court, which would convert the sanctions from a freezing order into evidence.
The Foreign Office has shown it can move fast on the paperwork. The test is whether it can move at the same pace on the court record.
Desk note: Monexus reported the 13 July designations on the same day as the Open Source Intel summary, foregrounding the proxy-network framing that the Foreign Office chose to use rather than the unattributed "state actor" language that dominated 2024 packages. We will update if the Foreign Office publishes the full operational annex behind the 24 listings.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://t.me/osintlive