October 01, 2021 By Anthony D. Mirenda
Categories: Privacy , Congress , Data Security
Ransomware payments continue to be a focus of the U.S. Treasury Department’s Office of Foreign Assets Control (“OFAC”). As previously reported by Foley Hoag, on October 1, 2020, OFAC released an advisory regarding potential sanctions risks related to facilitating ransomware payments. Almost a year later, on September 21, 2021, OFAC updated its advisory to provide additional guidance regarding what OFAC considers to be mitigating factors if facilitating a ransomware payment results in an apparent violation of U.S. sanctions. In addition, OFAC, for the first time, added a foreign cryptocurrency exchange (SUEX OTC, S.R.O.) and a number of crypto addresses to its Specially Designated Nationals and Blocked Persons List.
OFAC’s 2021 advisory strengthened the stern warning it gave last year: victims of ransomware attacks (and those who assist them) risk violating U.S. sanctions by facilitating ransomware payments if such payments go to sanctioned entities. The updated advisory then builds upon OFAC’s prior warning by emphasizing three themes: (1) act prudently to protect yourself from attack; (2) immediately disclose and report an attack to law enforcement; and (3) cooperate with law enforcement and provide details on the attack as quickly as possible. OFAC may impose penalties for sanctions violations based on strict liability, and OFAC maintains, as a matter of policy, that license applications to make ransomware payments face a presumption of denial. Thus, OFAC is using its enforcement authority to encourage good practices before an attack, and to encourage swift reporting and cooperation after, as the best means to avoid or mitigate such penalties. We have highlighted some of the key updates below:
The U.S. Congress is also now getting more involved. Various bills have been introduced in the House and the Senate, including a bipartisan Senate measure that would require many organizations – including not only critical infrastructure operators, but also non-profits, businesses with more than 50 employees, and state and local government entities – to report ransomware attacks to federal authorities. Much may change about these bills as they make their way through the legislative process, but as the risks continue to expand, it is clear that this issue is not going away any time soon.
Foley Hoag has comprehensive resources to help you protect against ransomware attacks, deal with an attack if you become a victim, and navigate potential sanctions risks: