
What the document says
The Treasury Department's Office of Foreign Assets Control advisory, dated 1 October 2020, states that companies which facilitate ransomware payments on behalf of victims, including financial institutions, cyber insurers, and digital-forensics and incident-response firms, encourage future demands and may risk violating OFAC regulations themselves. The advisory explains that U.S. persons are generally barred from transacting with anyone on OFAC's Specially Designated Nationals list or in a comprehensively sanctioned jurisdiction, and that this applies whether or not the payer knows the recipient is sanctioned: OFAC may impose civil penalties on a strict-liability basis. It cites prior sanctions designations tied to ransomware operators, including the developers of Cryptolocker, SamSam and Dridex and the Lazarus Group behind WannaCry, as the basis for that risk. It adds that a company's timely report of an attack to law enforcement, and its cooperation during and after an incident, count as significant mitigating factors if OFAC later finds a sanctions nexus, and that license applications for a ransomware payment are reviewed case by case with a presumption of denial. Treasury's own public notice of the advisory that day directed regulated industries toward its licensing division for that review. A companion FinCEN advisory, issued the same day, addressed related anti-money-laundering obligations for financial institutions; that advisory was later rescinded, effective 8 November 2021.
Confidence and limits
This description is drawn directly from OFAC's published advisory text, explanatory guidance rather than a regulation, as the document itself notes; it does not have the force of law and does not describe any enforcement action taken under it. The companion FinCEN advisory is cited only for its existence and later rescission, both shown on the agencies' own pages; neither source describes how often a ransomware facilitator has actually been penalised.
Why it mattered
Before this advisory, many incident-response firms and insurers treated a ransomware payment mainly as an operational and financial decision. By stating that facilitating a payment could be a strict-liability sanctions violation regardless of knowledge, Treasury made sanctions screening a required step in ransomware response, visibly changing how negotiation firms and insurers structured their payment processes afterward.
Defensive takeaway
Build sanctions screening of any ransom demand's payment address and known threat-actor identifiers into your incident-response plan before an attack happens, and identify in advance which vendor, insurer or bank would perform that screening on your behalf.
- Does our incident-response plan name who is responsible for sanctions screening before any ransom payment is considered?
- Have we confirmed which vendor, insurer, or bank would actually perform that screening under a real deadline?
- Would we report an attack to law enforcement promptly enough for that cooperation to count as a mitigating factor?
The advisory does not ban ransomware payments outright, and it leaves open a licensing path reviewed case by case; its practical effect was to make sanctions exposure a standing consideration in every ransomware response rather than an edge case relevant only to unusually well-resourced attackers.
Before facilitating or approving a ransomware payment, screen the demanded wallet and any known threat-actor identifiers against sanctions lists, and involve legal counsel rather than treating payment as a purely operational decision.
This account is based directly on OFAC's own advisory text and Treasury's public notice of it; it does not draw on any enforcement action applying the advisory, since none is cited here.
Sources & reading trail
OFAC's full advisory text on strict-liability sanctions risk for facilitating ransomware payments.
government-primary · Source published: 1 October 2020 · Retrieved: 16 September 2026
Treasury's own notice of the advisory's publication and the enforcement-consideration factors it describes.
government-primary · Source published: 1 October 2020 · Retrieved: 16 September 2026
FinCEN's companion advisory metadata, including its issue date and later rescission on 8 November 2021.
government-primary · Source published: 1 October 2020 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.