Policy Briefing — OFAC issues advisory on ransomware payments and sanctions risk
The U.S. Treasury’s OFAC published an advisory on 1 October 2020 warning that facilitating ransomware payments to sanctioned actors could trigger civil penalties and urging stronger prevention and reporting practices.
On 1 October 2020 the Office of Foreign Assets Control released an advisory cautioning financial institutions, cyber insurers, incident responders, and forensics firms that paying or routing ransomware proceeds to sanctioned entities may violate U.S. law. OFAC encouraged organizations to implement robust cybersecurity, promptly report incidents to law enforcement, and consider sanctions risks before engaging facilitators.
Risk and legal teams should integrate sanctions screening into ransomware playbooks, coordinate with counsel on payment decisions, and reinforce technical controls that reduce the likelihood of needing to negotiate with threat actors.
Continue in the Policy pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Semiconductor Industrial Strategy Policy Guide — Zeph Tech
Coordinate CHIPS and Science Act, EU Chips Act, and Defense Production Act programmes with capital planning, compliance, and supplier readiness.
-
Digital Markets Compliance Guide — Zeph Tech
Implement EU Digital Markets Act, EU Digital Services Act, UK Digital Markets, Competition and Consumers Act, and U.S. Sherman Act requirements with cross-functional operating…
-
Export Controls and Sanctions Policy Guide — Zeph Tech
Integrate U.S. Export Control Reform Act, International Emergency Economic Powers Act, and EU Dual-Use Regulation requirements into trade compliance, engineering, and supplier…




