{"id":5623,"date":"2020-10-09T13:49:26","date_gmt":"2020-10-09T20:49:26","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=5623"},"modified":"2024-08-07T12:23:11","modified_gmt":"2024-08-07T19:23:11","slug":"sanctions-risks-for-facilitating-ransomware-payments","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/","title":{"rendered":"Sanctions Risks for Facilitating Ransomware Payments"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">On October 1, 2020, the Department of the Treasury, Office of Foreign Assets Control (OFAC) issued an advisory to outline the sanctions risks associated with ransomware payments related to the malicious cyber-enabled activity<sup>1<\/sup><\/span><span style=\"font-weight: 400;\">. OFAC has made it clear that \u201cCompanies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations. This advisory describes these sanctions risks and provides information for contacting relevant U.S. government agencies, including OFAC if there is a reason to believe the cyber actor demanding ransomware payment may be sanctioned or otherwise have a sanctions nexus.\u201d\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To be clear, facilitating payments for ransomware to sanctioned entities may result in civil fines and penalties. This OFAC advisory is limited to sanctions risks related to ransomware and was not intended to address issues related to information security practitioners\u2019 cyber threat intelligence-gathering activities. <\/span><\/p>\n<h3><span style=\"font-weight: 400;\">What Does Business Need to Know?<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">The U.S. Government keeps a list of economic sanctions which are administered by OFAC. OFAC has imposed sanctions on these actors and others who materially assist, sponsor, or provide financial, material, or technological support for ransomware related activities. Ransomware payments made to sanctioned persons or sanctioned jurisdictions could be used to fund activities contrary to the United States\u2019 national security and foreign policy objectives. Ransomware payments may also encourage threat actors to engage in future attacks. In addition, paying a ransom to threat actors does not guarantee that the victim will regain access to stolen data.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">U.S. citizens and residents are generally prohibited from engaging in transactions with individuals or entities on OFAC\u2019s Specially Designated Nationals and Blocked Persons List (SDN List), other blocked persons, and those covered by comprehensive country or region embargoes (e.g., Cuba, the Crimea region of Ukraine, Iran, North Korea, and Syria).\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">Civil Penalties for Sanctions Violations Based Upon Liability<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">OFAC may impose civil penalties for sanctions violations based on liability. This means that a person subject to U.S. jurisdiction may be held civilly liable even if they did not know or have reason to know it was engaging in a transaction with a prohibited person under sanctions laws and regulations administered by OFAC. Companies involved in facilitating ransomware payments on behalf of victims should also determine whether they have regulatory obligations. In failure to meet these obligations, these companies then take on the new risk of penalties for sanctions violations.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Civil penalties for sanctions violations will have a direct impact on the flow of ransom payments. By choking off illicitly gained ransom revenue streams, OFAC\u2019s civil penalties will make ransomware a far less attractive revenue source for threat actors.<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">OFAC Has Identified Numerous Ransomware Threat Actors\u00a0<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">OFAC has identified numerous malicious cyber actors under its cyber-related sanctions program. This includes perpetrators of ransomware attacks and those who facilitate ransomware transactions. Some of these cited by the OFAC advisory and explicitly called out and sanctioned include Cryptolocker, SamSam, WannaCry, and Dridex and the threat actors behind all of these ransomware tools.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As an example, let us take a closer look at Dridex. Beginning in 2015, Evil Corp, a Russia-based cybercriminal organization, used the Dridex malware to infect computers and harvest login credentials from hundreds of banks and financial institutions in over 40 countries, causing more than $100 million in theft-related losses. In December 2019, OFAC designated Evil Corp and its leader, Maksim Yakubets, for the development and distribution of the Dridex malware.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The best way to deal with ransomware is to minimize your risk of infection. The Infoblox Cyber Intelligence Unit (CIU) has covered Dridex extensively. Here you can see our threat research from the past year includes these three important reports:\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Dridex Malspam Spoofs Messaging from Popular Accounting Software Company<sup>2<\/sup><\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Dridex Banking Trojan Hides in Fake Payroll Notifications<sup>3<\/sup><\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Dridex Banking Trojan<sup>4<\/sup><\/span><\/li>\n<\/ul>\n<h3><span style=\"font-weight: 400;\">Best Practices Help Stop Ransomware<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">An ounce of prevention is worth a pound of cure! You can reduce the risk of ransomware and ongoing attacks more quickly with these essential best practices:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Always back-up essential data.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Prioritize and apply the latest security updates and patches.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Utilize network segmentation to limit the spread of ransomware.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Train employees in email hygiene and attachments best practices.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Implement a DNS response policy zone (RPZ) enforcement to prevent data exfiltration and block DNS communications from compromised devices with malicious sites and command and control servers, including those associated with ransomware activity<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Monitor DNS requests to identify suspicious DNS activity.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Improve visibility and discovery with tools that can detect unauthorized or compromised devices and virtual machines anywhere on your network so you can automatically block their access.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Use the valuable data from DNS, DHCP, and IP address management (DDI) to gain useful insights to help you better understand ransomware attacks, related risk, and best prioritize remediation activity.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Harness threat intelligence to detect, prioritize, and anticipate evolving threats.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Support integrated security response by sharing threat data across SOAR, SIEM, and other cybersecurity ecosystem technologies.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Learn more about how we can help &#8211; more information on reducing the risk of ransomware: <\/span><a href=\"https:\/\/www.infoblox.com\/resources\/videos\/the-role-of-dns-instrumentation-and-dns-data-in-fighting-ransomware\/\"><span style=\"font-weight: 400;\">https:\/\/www.infoblox.com\/resources\/videos\/the-role-of-dns-instrumentation-and-dns-data-in-fighting-ransomware\/<\/span><\/a><span style=\"font-weight: 400;\">\u00a0\u00a0<\/span><\/p>\n<p>If you want to know more, please reach out to us directly via <a href=\"https:\/\/info.infoblox.com\/contact-form\" target=\"_blank\" rel=\"noopener\">https:\/\/info.infoblox.com\/contact-form<\/a>.<\/p>\n<p><sup>1<\/sup><a href=\"https:\/\/home.treasury.gov\/system\/files\/126\/ofac_ransomware_advisory_10012020_1.pdf\">https:\/\/home.treasury.gov\/system\/files\/126\/ofac_ransomware_advisory_10012020_1.pdf<\/a><\/p>\n<p><sup>2<\/sup><a href=\"https:\/\/insights.infoblox.com\/threat-intelligence-reports\/threat-intelligence--72\">https:\/\/insights.infoblox.com\/threat-intelligence-reports\/threat-intelligence&#8211;72<\/a><\/p>\n<p><sup>3<\/sup><a href=\"https:\/\/insights.infoblox.com\/threat-intelligence-reports\/threat-intelligence--51\">https:\/\/insights.infoblox.com\/threat-intelligence-reports\/threat-intelligence&#8211;51<\/a><\/p>\n<p><sup>4<\/sup><a href=\"https:\/\/insights.infoblox.com\/threat-intelligence-reports\/threat-intelligence--19\">https:\/\/insights.infoblox.com\/threat-intelligence-reports\/threat-intelligence&#8211;19<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On October 1, 2020, the Department of the Treasury, Office of Foreign Assets Control (OFAC) issued an advisory to outline the sanctions risks associated with ransomware payments related to the malicious cyber-enabled activity1. OFAC has made it clear that \u201cCompanies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber [&hellip;]<\/p>\n","protected":false},"author":324,"featured_media":5624,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[2],"tags":[288,335,189],"class_list":{"0":"post-5623","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security","8":"tag-ransomware","9":"tag-ofac","10":"tag-cybersecurity","11":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Sanctions Risks for Facilitating Ransomware Payments<\/title>\n<meta name=\"description\" content=\"On October 1, 2020, the Department of the Treasury, Office of Foreign Assets Control (OFAC) issued an advisory to outline the sanctions risks associated with ransomware payments related to the malicious cyber-enabled activity. OFAC has made it clear that \u201cCompanies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations. This advisory describes these sanctions risks and provides information for contacting relevant U.S. government agencies, including OFAC if there is a reason to believe the cyber actor demanding ransomware payment may be sanctioned or otherwise have a sanctions nexus.\u201d\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sanctions Risks for Facilitating Ransomware Payments\" \/>\n<meta property=\"og:description\" content=\"On October 1, 2020, the Department of the Treasury, Office of Foreign Assets Control (OFAC) issued an advisory to outline the sanctions risks associated with ransomware payments related to the malicious cyber-enabled activity. OFAC has made it clear that \u201cCompanies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations. This advisory describes these sanctions risks and provides information for contacting relevant U.S. government agencies, including OFAC if there is a reason to believe the cyber actor demanding ransomware payment may be sanctioned or otherwise have a sanctions nexus.\u201d\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2020-10-09T20:49:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-07T19:23:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\" \/>\n\t<meta property=\"og:image:width\" content=\"293\" \/>\n\t<meta property=\"og:image:height\" content=\"249\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Michael Zuckerman\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Michael Zuckerman\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/\"},\"author\":{\"name\":\"Michael Zuckerman\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/212816c17be869578ba1574b5fc7abf4\"},\"headline\":\"Sanctions Risks for Facilitating Ransomware Payments\",\"datePublished\":\"2020-10-09T20:49:26+00:00\",\"dateModified\":\"2024-08-07T19:23:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/\"},\"wordCount\":909,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\",\"keywords\":[\"Ransomware\",\"OFAC\",\"Cybersecurity\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/\",\"name\":\"Sanctions Risks for Facilitating Ransomware Payments\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\",\"datePublished\":\"2020-10-09T20:49:26+00:00\",\"dateModified\":\"2024-08-07T19:23:11+00:00\",\"description\":\"On October 1, 2020, the Department of the Treasury, Office of Foreign Assets Control (OFAC) issued an advisory to outline the sanctions risks associated with ransomware payments related to the malicious cyber-enabled activity. OFAC has made it clear that \u201cCompanies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations. This advisory describes these sanctions risks and provides information for contacting relevant U.S. government agencies, including OFAC if there is a reason to believe the cyber actor demanding ransomware payment may be sanctioned or otherwise have a sanctions nexus.\u201d\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\",\"width\":293,\"height\":249},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/sanctions-risks-for-facilitating-ransomware-payments\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Sanctions Risks for Facilitating Ransomware Payments\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/212816c17be869578ba1574b5fc7abf4\",\"name\":\"Michael Zuckerman\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_324_1628613720-96x96.jpg\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_324_1628613720-96x96.jpg\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_324_1628613720-96x96.jpg\",\"caption\":\"Michael Zuckerman\"},\"description\":\"Michael Zuckerman is a seasoned B2B product marketing and marketing strategy consultant with experience in the cybersecurity marketplace. Zuckerman\u2019s domain experience in cybersecurity over the past 10 years includes DNS security, threat intelligence, threat intelligence platforms (TIP), container security, mobile device security, moving target defense, network threat analysis (AI), sandbox, deception technology, cloud access security brokers (CASB), SASE, AI based SIEM, secure collaborative governance, and related technology sets to include data loss prevention (DLP), user and entity behavior analytics (UEBA), and encryption.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/michael-zuckerman\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Sanctions Risks for Facilitating Ransomware Payments","description":"On October 1, 2020, the Department of the Treasury, Office of Foreign Assets Control (OFAC) issued an advisory to outline the sanctions risks associated with ransomware payments related to the malicious cyber-enabled activity. OFAC has made it clear that \u201cCompanies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations. This advisory describes these sanctions risks and provides information for contacting relevant U.S. government agencies, including OFAC if there is a reason to believe the cyber actor demanding ransomware payment may be sanctioned or otherwise have a sanctions nexus.\u201d","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/","og_locale":"en_US","og_type":"article","og_title":"Sanctions Risks for Facilitating Ransomware Payments","og_description":"On October 1, 2020, the Department of the Treasury, Office of Foreign Assets Control (OFAC) issued an advisory to outline the sanctions risks associated with ransomware payments related to the malicious cyber-enabled activity. OFAC has made it clear that \u201cCompanies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations. This advisory describes these sanctions risks and provides information for contacting relevant U.S. government agencies, including OFAC if there is a reason to believe the cyber actor demanding ransomware payment may be sanctioned or otherwise have a sanctions nexus.\u201d","og_url":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/","og_site_name":"Infoblox Blog","article_published_time":"2020-10-09T20:49:26+00:00","article_modified_time":"2024-08-07T19:23:11+00:00","og_image":[{"width":293,"height":249,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","type":"image\/png"}],"author":"Michael Zuckerman","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Michael Zuckerman","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/"},"author":{"name":"Michael Zuckerman","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/212816c17be869578ba1574b5fc7abf4"},"headline":"Sanctions Risks for Facilitating Ransomware Payments","datePublished":"2020-10-09T20:49:26+00:00","dateModified":"2024-08-07T19:23:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/"},"wordCount":909,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","keywords":["Ransomware","OFAC","Cybersecurity"],"articleSection":["Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/","url":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/","name":"Sanctions Risks for Facilitating Ransomware Payments","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","datePublished":"2020-10-09T20:49:26+00:00","dateModified":"2024-08-07T19:23:11+00:00","description":"On October 1, 2020, the Department of the Treasury, Office of Foreign Assets Control (OFAC) issued an advisory to outline the sanctions risks associated with ransomware payments related to the malicious cyber-enabled activity. OFAC has made it clear that \u201cCompanies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations. This advisory describes these sanctions risks and provides information for contacting relevant U.S. government agencies, including OFAC if there is a reason to believe the cyber actor demanding ransomware payment may be sanctioned or otherwise have a sanctions nexus.\u201d","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","width":293,"height":249},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/security\/sanctions-risks-for-facilitating-ransomware-payments\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.infoblox.com\/blog\/category\/security\/"},{"@type":"ListItem","position":3,"name":"Sanctions Risks for Facilitating Ransomware Payments"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/212816c17be869578ba1574b5fc7abf4","name":"Michael Zuckerman","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_324_1628613720-96x96.jpg","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_324_1628613720-96x96.jpg","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_324_1628613720-96x96.jpg","caption":"Michael Zuckerman"},"description":"Michael Zuckerman is a seasoned B2B product marketing and marketing strategy consultant with experience in the cybersecurity marketplace. Zuckerman\u2019s domain experience in cybersecurity over the past 10 years includes DNS security, threat intelligence, threat intelligence platforms (TIP), container security, mobile device security, moving target defense, network threat analysis (AI), sandbox, deception technology, cloud access security brokers (CASB), SASE, AI based SIEM, secure collaborative governance, and related technology sets to include data loss prevention (DLP), user and entity behavior analytics (UEBA), and encryption.","url":"https:\/\/www.infoblox.com\/blog\/author\/michael-zuckerman\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/5623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/324"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=5623"}],"version-history":[{"count":5,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/5623\/revisions"}],"predecessor-version":[{"id":9009,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/5623\/revisions\/9009"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/5624"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=5623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=5623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=5623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}