
Trump Administration Executive Order (EO) Tracker
The decision to pay millions to a cyber criminal has never been easy, but it is now even more complex. The U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) issued an updated advisory on September 21, 2021, on the potential sanctions risks to making or facilitating ransomware payments, and cyber victims paying to restore systems and recover data may be in the crosshairs of the U.S. government as it attempts to combat the steadily growing threat of ransomware attacks.
Although it notes that “the U.S. government strongly disfavors the payment of cyber ransom or extortion demands,” the OFAC guidance stops short of prohibiting such payments. Instead, building on the initial October 2020 advisory, it hits the following:
Meanwhile, OFAC also simultaneously announced that, for the first time, it sanctioned a cryptocurrency exchange (SUEX OTC, also known as Successful Exchange) based on its ties to ransom payments. SUEX has been designated as a Specially Designated National (SDN), imposing asset freezing measures on property subject to U.S. jurisdiction and prohibiting virtually all transactions with any U.S. nexus. Its SDN designation also creates possible secondary sanctions exposure for those who provide “material support” to SUEX after its designation even if the activity has no U.S. nexus.
Companies and institutions must comply with the full range of potential sanctions, anti-money laundering, export control, and other regulatory requirements in the case of cybercrime. We expect the Government to continue to issue and expand guidance in these areas and be vigilant in enforcement and additional designations.
The U.S. government is recognizing what ransomware victims have long known: ransomware is pervasive and debilitating. The advisory first reflects on the massive uptick in the number, size, and sophistication of ransomware attacks, and the efforts by OFAC to sanction attackers behind such activity. Ransomware attacks have been carried out against private and government entities of various sizes and across sectors, including numerous organizations considered by the U.S. government to constitute critical infrastructure. The advisory states that because ransomware payments may enable criminals and adversaries with a sanctions nexus to profit and advance their illicit aims, the “U.S. government strongly discourages the payment of cyber ransom or extortion demands.” Nonetheless, the U.S. government has in other contexts acknowledged that many organizations ultimately decide to pay ransoms because, they determine, doing so is the right business decision.
The OFAC advisory is one piece of an increasing and broader effort by the U.S. government to combat the ransomware threat. In recent months, Congress has held multiple hearings on cybersecurity and ransomware. At a hearing occurring the same day OFAC’s new advisory was released, for example, FBI Director Christopher Wray described the situation as “not sustainable” and “not acceptable,” noting that the FBI had launched a new cyber strategy last year to ramp up its efforts to disrupt and defend against malicious activity, including via public-private partnerships. Secretary of the Department of Homeland Security (DHS) Alejandro Mayorkas testified that DHS (and in particular CISA, the Cybersecurity and Infrastructure Security Agency) have significantly increased their cybersecurity efforts over the past year. And earlier this month, the National Institute of Standards and Technology (NIST) also initiated a comment period on its new draft Cybersecurity Framework Profile for Ransomware Risk Management.
The legal landscape around making a ransom payment remains complicated and uncertain. The advisory warns that victim organizations, along with organizations that facilitate ransom payments, may be subject to enforcement actions if the ransom recipient turns out to be sanctioned. Without addressing the practical difficulty of identifying to whom ransomware payments are actually made when identities are concealed and cryptocurrency wallets remain near anonymous, the guidance reiterates that U.S. persons are prohibited from dealing with the sanctioned entities found on OFAC’s Specially Designated Nationals and Blocked Persons List as well as all residents of comprehensively sanctioned territories. In addition to entities on the SDN list, transactions with non-listed entities that are, directly or indirectly, 50 percent or greater owned by one or more SDNs are prohibited. Sanctions are enforced under a strict liability regime, meaning that a victim organization or an organization that facilitates a ransom payment can be held civilly liable for sanctions violations even if they did not know, nor could have reasonably known, that the recipient of the payment was sanctioned.
Not all ransomware payments carry the same sanctions risk. Following OFAC’s initial October 2020 guidance, ransomware victims generally have taken a number of measures to avoid making payments to SDNs. The updated advisory now offers expanded information on mitigating factors that may inform OFAC’s enforcement response to future ransom payments by victim organizations. It may help shape the standard of care for ransomware response generally:
The updated advisory states that, if an affected party took the mitigating steps outlined above, OFAC may go as far as resolving apparent violations with a non-public response, such as a No Action Letter or a Cautionary Letter, although the outcome will depend on the specific facts and circumstances.
The Treasury Department’s updated advisory and sanctioning of a cryptocurrency exchange add complexity to the existing process for evaluating whether to pay a ransom and suggest enhanced enforcement of potential sanctions and anti-money laundering compliance violations, particularly against financial institutions and other organizations that facilitate ransom payments. In light of this guidance – and well in advance of any possible cybersecurity incident – organizations may want to consider a number of initiatives, including:
If you have any questions on the OFAC advisory or a particular issue, please contact a Hogan Lovells team member.
Authored by Aleksandar Dukic, Gregory Lisa, Scott Loughlin, Peter Marta, Paul Otto, Jacob Wall, Beth Peters, Ajay Kuntamukkala, Stephen Propst, Anthony Capobianco, and Brian Curran.