Ransomware Payment Sanctions.
As a general matter, no federal statute categorically prohibits making ransomware payments. This includes situations in which the identity of the ransomware threat actor is unknown or the victim’s diligence efforts fail to identify the actor. However, this does not necessarily mean that all ransomware payments are legal. Of course, some types of ransomware payments are illegal, for example, those involving illegal substances, but even if a payment does not otherwise violate the law, a victim’s payment to a ransomware threat actor can still create exposure under federal sanctions laws.
While ransomware payments do not categorically violate federal law, ransomware payments can violate OFAC’s regulations in certain cases. At the moment, there are two key scenarios that can trigger sanctions-related liability:
- OFAC Sanctions: A ransomware payment generally violates OFAC regulations when made to a blocked person or comprehensively sanctioned jurisdiction, unless authorized or exempt.
- Unknown Recipient: A ransomware payment can violate OFAC regulations if the payment involves a sanctioned actor or jurisdiction, even if the actor's identity is unknown.
If OFAC imposes sanctions on the recipient of a ransomware payment, the payment itself is illegal. However, not all sanctions violations carry the same penalties. OFAC’s sanctions enforcement on civil violations generally operates under a strict-liability standard. This means that violations of OFAC’s sanctions regulations can carry severe civil liability exposure regardless of the victim’s knowledge of the sanctions.
However, this is not a one-sided standard, as sanctions violations can carry criminal liability as well. Civil sanctions violations carry the risk of substantial fines but not of incarceration. In contrast, sanctions violations that rise to criminal liability can carry potential incarceration as well as substantial fines.
While OFAC has stated that a victim’s lack of sanctions knowledge will not eliminate exposure under its civil enforcement program, the same is not necessarily true when federal law enforcement pursues criminal sanctions. Federal law enforcement must be able to prove a criminal sanctions violation beyond a reasonable doubt, and this includes showing the defendant’s mental state at the time of the transaction. Consequently, criminal sanctions liability will generally require something more than an inadvertent transaction.
How Can a Victim Screen a Ransomware Recipient Before Paying?
As a U.S. person subject to federal sanctions, you are generally barred from transacting with parties on OFAC’s Specially Designated Nationals (SDN) List. Additionally, transactions involving individuals or organizations in certain countries, such as Iran, Cuba, North Korea, and Syria, are generally barred due to U.S. comprehensive sanctions. With these restrictions in mind, victims need to ensure that any ransomware payment complies with federal law. As a result, victims must be careful to avoid paying a blocked party or transmitting funds to a country subject to comprehensive sanctions.
According to a recent Ransomware Advisory issued by the U.S. Department of the Treasury, “OFAC may impose civil penalties for sanctions violations based on strict liability, meaning that a person subject to U.S. jurisdiction may be held civilly liable even if such person did not know or have reason to know that it was engaging in a transaction that was prohibited under sanctions laws and regulations administered by OFAC.”
Victims can use their internal resources to gather information about the ransomware threat actor and the recipient. This information can then be cross-referenced against OFAC’s SDN List and potentially determine whether the payment is prohibited. When victims engage these threat actors, however, they are often at a significant disadvantage, since the identity of the threat actor is usually unknown or the threat actor uses deceptive tactics to obfuscate the actual recipient of the payment. For example, digital wallet addresses and aliases may appear on the SDN List. But while these may raise concerns, they are not necessarily conclusive in determining the recipient’s identity in connection with a ransomware attack. In fact, when confronting the ransomware attack scenario, the availability of any information that can conclusively link the threat actor to its actual identity is very limited.
Victims who engage payment facilitators to resolve ransomware attacks must be mindful of potential sanctions exposure. In its September 21, 2021 Updated Ransomware Advisory, OFAC recommended that victims conduct sanctions diligence prior to using a payment facilitator. If you intend to use a payment facilitator, we recommend to you that you seek a certification of compliance from the facilitator that addresses the specific concerns raised by OFAC. This certification would not eliminate sanctions exposure, but it would still document the victim’s diligence efforts before the payment, which may assist in resolving criminal sanctions allegations.
Spodek Law Group works out of offices in Manhattan, Brooklyn, Queens and Los Angeles.
Can Police Legally Block a Ransomware Payment?
The Federal Bureau of Investigation (FBI) investigates ransomware cases in the United States. Once the FBI investigates ransomware, it transmits its investigative findings to the U.S. Department of Justice (DOJ). The DOJ then uses this information to pursue federal prosecution of ransomware attacks.
Because ransomware actors operate globally, investigating and prosecuting ransomware attacks often requires extensive cooperation between law enforcement agencies both domestically and internationally. This cooperation is critical for tracing attack origin and identifying the individuals behind these cybercrimes.
Ransomware prosecutions typically involve a wide array of criminal charges. These can range from wire fraud (under 18 U.S.C. § 1343) to identification-document and means-of-identification offenses (under 18 U.S.C. § 1028) and aggravated identity theft (under 18 U.S.C. § 1028A) and conspiracy (under 18 U.S.C. § 371). One of the primary laws used in ransomware prosecutions is the U.S. Computer Fraud and Abuse Act, which contains several key provisions.
Under 18 U.S.C. § 1030(a)(5) of the CFAA, it is a criminal offense to intentionally cause damage to a protected computer. The statute reads in relevant part:
“Whoever knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer…”
Under 18 U.S.C. § 1030(a)(7) of the CFAA, it is also a criminal offense to engage in interstate threats and extortion. This section prohibits using computers to demand money or other property in exchange for not causing damage to a protected computer. Ransomware victims, such as healthcare organizations and critical infrastructure providers, often report being targeted by hackers who use encrypting malware to lock them out of their systems and then demand payment.
When you get arrested for ransomware, our defense attorneys will have to argue that you did not engage in ransomware activities. Ransomware acts can be criminal in various ways and will typically fall under these statutes and others. Here, the key will be to show that you did not violate these laws, or that you can argue against the elements for which you have been charged.
Why Is Ransomware’s Total Cost More Than the Ransom Demand?
Ransomware payments to criminal groups and hacker collectives are typically made with cryptocurrency rather than via conventional bank transfers. While ransomware demands range widely, some key factors influence the amount:
- The Characteristics of the Victim: Criminal groups may demand higher ransoms if the victim is highly dependent on the hijacked data or has the financial means to pay more.
- The Scope of the Attack: If an entire network is encrypted or high-value data is stolen, the criminal group may raise the ransom demand.
- The Type of Criminal Group: Sophisticated hacker groups often engage in more complex ransomware operations, and their ransom demands tend to be higher.
The research that was used to write this article did not contain data that would support establishing an average ransom payout. While this information will likely be useful in evaluating whether to respond to a ransomware demand or to pay the ransom, it is difficult to gather since most of this data is not publicly available.
Ransomware attacks are more than just the ransomware demand itself. From a cybersecurity perspective, ransomware is a form of malicious software that is designed to encrypt the contents of a computer and render the system inoperable, essentially holding the victim’s data hostage. This can lead to days or even weeks of business disruption, and costs for remediation such as forensic costs and cost of remediation can reach hundreds of thousands or millions of dollars.
Therefore, any attempt to estimate the cost of a ransomware attack has to take into account business disruption costs, costs to pay the ransom demand, forensic investigation costs, and ransomware cleanup costs.
Preventing ransomware attacks is the best approach to mitigate risk. Businesses can reduce ransomware risk by improving cybersecurity protocols, training employees, and using antivirus software. If a ransomware attack occurs, business owners can sometimes rely on separate, secure backup systems to restore their data without paying the ransom. However, in many cases, the backups are either outdated or the attack has compromised the backup systems as well.
Calling About Someone You Love
Most first calls to a defense firm come from a family member rather than the person under investigation. If that is you, Spodek Law Group answers its phone at any hour, and families retain the firm on a relative's behalf every week. Reach it at 888 348 8028.
Reading is good. Calling is better.
Answered within 24 hours, guaranteed. Some stories are better told out loud -
212 300 5196