OFAC Designates Virtual Currency Exchange as Malicious Cyber Actor
Time 3 Minute Read

On September 21, 2021, the U.S. Department of the Treasury’s Office of Foreign Assets Control (“OFAC”) issued an Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (the “Updated Advisory”) on the sanctions risks associated with facilitating ransomware payments.

The Updated Advisory explains that OFAC has designated malicious cyber actors under its cyber-related sanctions programs. Cyberattack victims, financial institutions, insurance firms and other companies assisting with ransomware payments are responsible for ensuring that they do not engage in unauthorized transactions prohibited by OFAC sanctions. As a result, companies subject to U.S. jurisdiction and engaging in transactions involving ransomware payments should consider the risk that such activities may violate sanctions prohibitions and expose them to civil liability. Through the Updated Advisory, OFAC continues to demonstrate increased enforcement attention on digital currencies.

Additionally, on September 21, 2021, OFAC, with assistance from the FBI, designated SUEX OTC, S.R.O., (“SUEX”) as a malicious cyber actor, the first such sanctions designation against a virtual currency exchange. According to the Treasury Department’s press release, over 40% of SUEX’s known transactions are associated with illicit actors, and SUEX is being sanctioned for providing material support to the threat posed by criminal ransomware actors. Under OFAC’s sanctions, all of SUEX’s property and interests in property that are subject to U.S. jurisdiction are blocked, and U.S. persons generally are prohibited from engaging in transactions with SUEX. Further, entities that SUEX owns 50% or more of also are blocked. According to the Treasury Department, financial institutions and other persons that engage in certain transactions or activities with SUEX, as well as other sanctioned entities and individuals, may also expose themselves to sanctions or be subject to an enforcement action.

In the last year, OFAC has brought various enforcement actions against digital currency services providers, cautioning persons subject to U.S. jurisdiction of the sanctions risks associated with the provision of digital currency services. This emphasis on digital currencies continues in response to the increased demand for ransomware payments during the COVID-19 pandemic, with actions focused on disrupting virtual currency exchanges that facilitate financial transactions for ransomware actors.

In connection with the Updated Advisory, OFAC has added digital currency addresses to OFAC’s Specially Designated Nationals and Blocked Persons List (“SDN List”) to notify companies of specific digital currency identifiers associated with blocked persons.

OFAC applies a strict liability standard when imposing civil penalties for sanctions violations. Thus, OFAC may hold a U.S. person civilly liable despite such person not knowing or having reason to know that a transaction involved an SDN, other blocked person or embargoed country.  Companies assisting with ransomware payments are encouraged to develop and maintain tailored, risk-based sanctions compliance procedures and controls to mitigate the risk of violating U.S. sanctions regulations. In the event of an apparent violation of U.S. sanctions regulations, significant mitigating factors that OFAC considers to determine its enforcement response include: (1) the adequacy of a sanctions compliance program, (2) the steps taken to reduce the risk of extortion by a sanctioned actor, (3) self-initiated, timely and complete reporting of ransomware attacks, and (4) ongoing cooperation with law enforcement. With respect to cooperation with law enforcement, OFAC will consider whether the company provided all relevant information, including technical details, ransom payment demand, and ransom payment instructions, to the appropriate U.S. government agencies as soon as possible.

To mitigate sanctions risks, companies subject to U.S. jurisdiction that assist with ransomware payments should be aware of U.S. sanctions regulations that may expose them to civil liabilities.

You May Also Be Interested In

Time 11 Minute Read

US Department of the Treasury’s Office of Foreign Assets Control (OFAC), the US Department of Commerce’s (Commerce) Bureau of Industry and Security (BIS) and the US Department of Justice (DOJ), collectively issued guidance regarding the obligations of non-US based companies and persons to comply with US sanctions (Tri-Seal Compliance Note: Obligations of foreign-based persons to comply with US sanctions and export control laws) (Compliance Note).

Time 8 Minute Read

What Happened: 

As reported in a Hunton Client Alert, the US Department of Justice (DOJ), the US Department of Commerce’s Bureau of Industry and Security (BIS), and the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) recently issued guidance regarding the voluntary self-disclosure by US businesses of violations of US sanctions and export control laws to these agencies (Tri-Seal Compliance Note: Voluntary Self-Disclosure of Potential Violations) (Compliance Note).

Time 9 Minute Read

What Happened:

On February 28, 2022, the US Department of Treasury’s Office of Foreign Assets Control (“OFAC”) issued further sanctions on Russia’s Central Bank, National Wealth Fund, and Ministry of Finance, and announced regulations to implement Executive Order 14024 under the Russia Harmful Foreign Activities Sanctions Program. On February 24, 2022, the Department of Commerce’s Bureau of Industry and Security (“BIS”) issued an immediate final rule implementing sanctions under the Export Administration Regulations (“EAR”).1

Time 4 Minute Read

On September 21, 2021 and October 15, 2021, the US Treasury Department’s Office of Foreign Assets Control (OFAC) issued reminders of the sanctions risks for facilitating ransom payments to designated malicious cyber actors.  As discussed in our prior blogpost on OFAC's October 1, 2020 advisory, OFAC has made clear that it is increasingly willing to bring enforcement actions against entities, including cyber insurers, that facilitate payments to sanctioned threat actors on behalf of corporate victims.

This guidance should serve as a reminder to policyholders that ransomware and other cyber incidents trigger stringent regulatory and reporting requirements and that policyholders should consider engaging experienced advisors to develop a cohesive response strategy when cyber incidents occur.  OFAC’s guidance also should remind policyholders to carefully scrutinize cyber insurance coverages (and others) to ensure they provide the broadest possible coverage for cyber risks while still following OFAC guidance.

The Hunton Blockchain Blog features opinions and legal analysis as we follow the development and use of distributed ledger technology known as the blockchain.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page