Helping to pay off ransomware hackers could draw big penalties from the feds
Full article765 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Office of Foreign Assets Control served notice to financial institutions and cyber insurance companies that they could suffer fines if they aid payments to attackers from nations like North Korea, Russia or Iran.
Anyone who helps ransomware victims pay off hackers who are under U.S. sanctions could face stiff punishment themselves, the Treasury Department said Thursday.
The advisory from Treasury’s Office of Foreign Assets Control served notice to financial institutions and cyber insurance companies — as well as cybersecurity firms that help ransomware victims identify and respond to attacks — that they could suffer fines if they aided payments to attackers from places like Russia, North Korea or Iran that are on the U.S. sanctions list.
And OFAC indicated it would be inclined to be strict about it: Those civil penalties could be levied against companies that didn’t know they were facilitating ransom payments to hackers on its sanctions list.
“OFAC may impose civil penalties for sanctions violations based on strict liability, meaning that a person subject to U.S. jurisdiction may be held civilly liable even if it did not know or have reason to know it was engaging in a transaction with a person that is prohibited under sanctions laws and regulations administered by OFAC,” the office wrote.
Notable ransomware names on the U.S. sanctions list include those that OFAC tied to developing Cryptolocker, helping funnel SamSam funds and unleashing WannaCry 2.0.
The office will review each case individually when deciding when to impose fines, but said that “self-initiated, timely, and complete report of a ransomware attack to law enforcement” would help avoid civil penalties, as would cooperating with law enforcement.
Last month, Treasury went on a bit of a cyber sanctioning binge, slapping alleged hackers in Russia over interfering in the 2020 election and scamming cryptocurrency exchanges, as well as alleged Iranian hackers targeting dissidents and journalists.
Reducing the incentives
Abetting payments to hackers poses potential national security risks, OFAC said in explaining the reason for its advisory.
“Ransomware payments made to sanctioned persons or to comprehensively sanctioned jurisdictions could be used to fund activities adverse to the national security and foreign policy objectives of the United States,” the advisory states. “Ransomware payments may also embolden cyber actors to engage in future attacks.”
It also noted the rise in ransom demands during the COVID-19 pandemic.
OFAC fines can exceed several million dollars, the office has said.
The advisory also comes one day after DHS’s Cybersecurity and Infrastructure Agency and the Multi-State Information Sharing & Analysis Center released a joint ransomware guide.
More Scoops
Treasury sanctions First VPN Service, others for abetting ransomware gangs
The designations hit 1VPNS, its alleged Ukrainian administrator and a Belarusian who allegedly sold “cryptors” to disguise ransomware and other malware.
Lawmakers ponder terrorism designations, homicide charges over hospital ransomware attacks
North Korean companies, people sanctioned for money laundering from cybercrime, IT worker schemes
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ransomware-payments-treasury-ofac-notice/