Ransomware Payments and OFAC: The Sanctions Trap in Every IR Plan
By the Legal Cyber Academy editorial team ·
The Sanctions Problem Sits Inside Your Incident Response Plan
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) maintains a list of Specially Designated Nationals and Blocked Persons — the SDN List — as well as country-based sanctions programs. As of September 17, 2026, making or facilitating a payment to any entity on that list, or to a party located in a comprehensively sanctioned jurisdiction, is prohibited regardless of whether you knew you were dealing with a designated party. That strict-liability structure is not hypothetical. OFAC issued an advisory in October 2020 — formally titled "Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments" — that made the exposure explicit for ransomware victims and the incident response firms, cyber insurers, and financial institutions that help them pay.
The October 2020 advisory has not been rescinded. It remains the operative statement of OFAC's posture as of September 17, 2026.
Why "We Didn't Know" Is Not Enough
Sanctions violations under the International Emergency Economic Powers Act (IEEPA) and the Trading with the Enemy Act (TWEA) can be civil or criminal. On the civil side, OFAC can impose penalties on a strict-liability basis — meaning you do not have to have known the threat actor was sanctioned. Knowledge affects penalty severity, not liability.
For ransomware specifically, the threat actor groups most commonly associated with large-scale extortion — including groups OFAC has designated, such as Evil Corp (formally sanctioned in December 2019) — often obscure their identity behind branded ransomware-as-a-service offerings. A victim organization may negotiate and pay believing they are dealing with one affiliate group when they are actually dealing with a designated entity's infrastructure.
Practically, this means:
- The name on the ransom note is not the name you need to check.
- The cryptocurrency wallet address receiving payment may be attributable to a sanctioned party through blockchain tracing, even if that is not apparent at payment time.
- The fact that you hired a reputable incident response firm does not transfer or eliminate your liability — though it is a relevant mitigating factor in OFAC's penalty calculus.
What OFAC Actually Looks For in Mitigation
OFAC's Economic Sanctions Enforcement Guidelines, codified at 31 C.F.R. Part 501, Appendix A, list factors that increase or decrease penalty amounts. In a ransomware context, the factors that provide the most protection are:
Voluntary self-disclosure. Reporting the potential violation to OFAC before it learns of the payment through other channels is treated as a significant mitigating factor. This is separate from any obligation you may have under state breach notification law or under the FBI's guidance encouraging reporting to law enforcement.
Sanctions screening before payment. Running the wallet address and any known threat actor identifiers against OFAC's SDN List and seeking a threat intelligence assessment of attribution. A screening step that turns up nothing does not eliminate liability, but it supports a claim that you took reasonable precautions.
Cooperation with law enforcement. OFAC's 2020 advisory specifically noted that engaging with the FBI, CISA, or the Secret Service before paying is both encouraged and relevant to how OFAC evaluates any resulting enforcement action.
No prior sanctions history. A first-time violation by an organization with a compliance program in place is treated very differently from a repeat or willful violation.
Where Cyber Insurance Sits in This Structure
Many cyber insurance policies cover ransomware payments as part of extortion coverage. But an insurer that processes or arranges a payment to a sanctioned party has its own sanctions exposure, which is why insurers increasingly require that the insured engage OFAC-experienced counsel and conduct pre-payment screening before the insurer will authorize coverage for the payment.
Some insurers have added policy exclusions — or conditions precedent to coverage — that require the insured to obtain legal sign-off on the sanctions analysis before any payment is made. If you skip that step and pay without clearance, you may find the extortion coverage denied on the grounds that you failed to satisfy a policy condition, independent of whatever the sanctions regulators do.
This is an area where the cyber insurance policy language and the sanctions compliance question need to be reviewed together, not sequentially.
The Reporting Obligations That Run Concurrently
A ransomware incident that reaches the payment stage almost certainly triggers multiple concurrent reporting obligations — none of which pause while you work through the sanctions question:
- CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022): CISA's implementing rules, as they develop, establish mandatory incident and ransom payment reporting timelines for covered entities. As of September 17, 2026, covered entities should confirm their specific obligations under whatever final or interim rules are in effect.
- FBI and Secret Service: The agencies have established reporting channels for ransomware, and engagement is strongly encouraged in OFAC's own guidance.
- State breach notification: If personal data is implicated, notification clocks in many states start at discovery of the incident, not at the conclusion of your investigation.
- SEC Regulation S-P or Form 8-K: Depending on whether you are a registered investment adviser, broker-dealer, or public company, securities regulators may have their own disclosure timelines running simultaneously.
Those obligations do not extend your window to decide whether to pay. They compress it.
Building the Sanctions Step Into IR Playbooks
The organizations that navigate this most cleanly are those that add the sanctions analysis as a named, mandatory step in their incident response playbook — not an afterthought when payment is already being arranged. That step should include:
- Retaining OFAC-experienced outside counsel at incident onset, not after a payment decision has been made
- Coordinating with the insurer's panel counsel before authorizing any payment
- Documenting every screening step, including who ran what check, against which version of the SDN List, and what the results were
- Making a contemporaneous record of the law enforcement notification and any response received
The documentation is not bureaucratic box-checking. It is the evidence you will need if OFAC comes asking later.
The Treasury Voluntary Disclosure Process
If a payment has already been made and there is reason to believe the recipient may have been a sanctioned party, OFAC's voluntary self-disclosure process under 31 C.F.R. Part 501 allows organizations to come forward. Voluntary disclosure, combined with full cooperation, is treated as a significant mitigating factor and can result in substantially reduced penalties or a no-action outcome. The process requires a detailed written submission describing the circumstances, the compliance program in place at the time, and corrective steps taken.
This is not a path you want to navigate without specialized counsel, but it is a path — and it is meaningfully better than waiting for OFAC to discover the payment on its own.
Go deeper — courses on this
RansomwareDecrypting the Threat: How to Protect Your Organization from Ransomware Risk
Technical and legal experts explain how ransomware works and what today's threat environment looks like…
Daniel B. Garrie · 1h 3m
FreeRansomwareBest Practices to Limit an Organization's Ransomware Risk from a Legal Perspective
This seminar covers the ransomware threat landscape alongside both technical and legal risk-management…
Daniel B. Garrie
InsuranceUnderstanding Cyber Insurance Policy: Assessing the Risk (Part 2 of 2)
Part 2 of a two-part seminar on cyber insurance, where panelists examine practical challenges…
Daniel B. Garrie
Keep reading
- NFT Royalty Disputes: Who Owns the Revenue Stream?On-chain royalty enforcement collapsed when major marketplaces bypassed creator fees in 2022–2023. Here is where the legal exposure sits tod…
- Legal Hold: What Triggers the Duty to Preserve, and What Actually Satisfies ItWhen the duty to preserve attaches, how far a legal hold must reach, and what FRCP 37(e) requires before a court can sanction a party for lo…
- eDiscovery and AI-Generated Evidence: What Litigators Must KnowAI-generated documents, emails, and chat logs are entering litigation at speed. Here is how to collect, authenticate, and challenge them bef…
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.