US regulatory framework imposing strict liability for any ransom payment benefiting a sanctioned actor, applicable to cyber insurers and their intermediaries.
The Office of Foreign Assets Control is the US Treasury authority responsible for administering economic sanctions. Its Advisory of 21 September 2021 explicitly extended the sanctions framework to the facilitation chain of ransom payments, targeting financial institutions, cyber insurance companies and incident response firms that participate in executing such a transaction. The governing principle is strict liability: any US entity or entity operating from the United States that makes or facilitates a payment to an actor on the Specially Designated Nationals list (SDN list) or linked to an embargoed country incurs civil and criminal liability, regardless of fraudulent intent. This regime creates a specific operational risk for cyber insurers, who may find themselves required to block a payment mid-negotiation if the attribution of the attacking group reveals a potential sanctions nexus. OFAC has also begun listing on its SDN list cryptocurrency exchange platforms that facilitate ransom laundering, such as SUEX OTC in 2021, thereby expanding the compliance perimeter well beyond direct payment. For the insured, the existence of this sanctions risk is an additional argument against paying a ransom, independent of the commercial decision.
A cyber insurer authorizes its insured to engage a negotiator to deal with a ransomware group operating under the DarkSide name. Mid-process, open-source intelligence suggests some group members have links to OFAC-listed entities. The insurer suspends payment authorization and retains specialist legal counsel to conduct an OFAC compliance analysis before discussions resume.
OFAC, sanctions cyber, strict liability ransomware, advisory OFAC 2021, SDN list ransomware