RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Policy & law

Policy & law / From the archive · 1 October 2020 record · prepared 16 September 2026

Treasury warned that paying some ransomware gangs could break sanctions law

OFAC's advisory says facilitating a ransomware payment can violate sanctions on a strict-liability basis, even without knowledge of the recipient.

Visual for this record: Treasury warned that paying some ransomware gangs could break sanctions law
Visual published by infocrypto.fr, shown for identification of the record. Credit: infocrypto.fr · source page ↗ Rights: owner-review-pending.

What the document says

The Treasury Department's Office of Foreign Assets Control advisory, dated 1 October 2020, states that companies which facilitate ransomware payments on behalf of victims, including financial institutions, cyber insurers, and digital-forensics and incident-response firms, encourage future demands and may risk violating OFAC regulations themselves. The advisory explains that U.S. persons are generally barred from transacting with anyone on OFAC's Specially Designated Nationals list or in a comprehensively sanctioned jurisdiction, and that this applies whether or not the payer knows the recipient is sanctioned: OFAC may impose civil penalties on a strict-liability basis. It cites prior sanctions designations tied to ransomware operators, including the developers of Cryptolocker, SamSam and Dridex and the Lazarus Group behind WannaCry, as the basis for that risk. It adds that a company's timely report of an attack to law enforcement, and its cooperation during and after an incident, count as significant mitigating factors if OFAC later finds a sanctions nexus, and that license applications for a ransomware payment are reviewed case by case with a presumption of denial. Treasury's own public notice of the advisory that day directed regulated industries toward its licensing division for that review. A companion FinCEN advisory, issued the same day, addressed related anti-money-laundering obligations for financial institutions; that advisory was later rescinded, effective 8 November 2021.

Confidence and limits

This description is drawn directly from OFAC's published advisory text, explanatory guidance rather than a regulation, as the document itself notes; it does not have the force of law and does not describe any enforcement action taken under it. The companion FinCEN advisory is cited only for its existence and later rescission, both shown on the agencies' own pages; neither source describes how often a ransomware facilitator has actually been penalised.

Why it mattered

Before this advisory, many incident-response firms and insurers treated a ransomware payment mainly as an operational and financial decision. By stating that facilitating a payment could be a strict-liability sanctions violation regardless of knowledge, Treasury made sanctions screening a required step in ransomware response, visibly changing how negotiation firms and insurers structured their payment processes afterward.

Defensive takeaway

Build sanctions screening of any ransom demand's payment address and known threat-actor identifiers into your incident-response plan before an attack happens, and identify in advance which vendor, insurer or bank would perform that screening on your behalf.

  • Does our incident-response plan name who is responsible for sanctions screening before any ransom payment is considered?
  • Have we confirmed which vendor, insurer, or bank would actually perform that screening under a real deadline?
  • Would we report an attack to law enforcement promptly enough for that cooperation to count as a mitigating factor?

The advisory does not ban ransomware payments outright, and it leaves open a licensing path reviewed case by case; its practical effect was to make sanctions exposure a standing consideration in every ransomware response rather than an edge case relevant only to unusually well-resourced attackers.

Defensive takeaway

Before facilitating or approving a ransomware payment, screen the demanded wallet and any known threat-actor identifiers against sanctions lists, and involve legal counsel rather than treating payment as a purely operational decision.

This account is based directly on OFAC's own advisory text and Treasury's public notice of it; it does not draw on any enforcement action applying the advisory, since none is cited here.

Sources & reading trail

Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments ↗

OFAC's full advisory text on strict-liability sanctions risk for facilitating ransomware payments.

government-primary · Source published: 1 October 2020 · Retrieved: 16 September 2026

Ransomware Advisory (OFAC Recent Action, October 1, 2020) ↗

Treasury's own notice of the advisory's publication and the enforcement-consideration factors it describes.

government-primary · Source published: 1 October 2020 · Retrieved: 16 September 2026

Advisory on Ransomware and the Use of the Financial System to Facilitate Ransom Payments (Rescinded) ↗

FinCEN's companion advisory metadata, including its issue date and later rescission on 8 November 2021.

government-primary · Source published: 1 October 2020 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.