Paying ransomware to sanctioned entities or jurisdictions is an OFAC violation. OFAC issued an Updated Advisory on Ransomware Regarding the Use of the Financial System for Facilitating Ransomware Payments in 2021.
TL;DR: Companies paying ransomware demands can face OFAC penalties if the recipient is a designated entity or located in a comprehensively sanctioned jurisdiction. OFAC's 2021 advisory warns that ransomware payments to sanctioned actors constitute sanctions violations regardless of intent.
In September 2021, OFAC published an updated advisory making clear that paying ransomware to sanctioned entities, including those in comprehensively embargoed jurisdictions (Cuba, Iran, North Korea, Syria, Crimea/DNR/LNR), violates sanctions. The advisory offers a safe harbor for voluntary self-disclosure.
OFAC has designated multiple ransomware operators and associated crypto exchange services under various programs. Notable examples include actors linked to Evil Corp, the Lazarus Group, and darknet markets like Hydra. Each designation means US persons cannot pay them, even under ransomware extortion.
| Risk factor | OFAC implication |
|---|---|
| Ransomware actor is SDN-listed | Payment is a direct sanctions violation |
| Payment routed through comprehensively sanctioned jurisdiction | Violation regardless of recipient identity |
| Payment to known ransomware affiliate in non-sanctioned jurisdiction | Legal but high-risk; may facilitate future sanctions evasion |
| Voluntary self-disclosure of accidental payment to SDN | May qualify for mitigation under OFAC enforcement guidelines |
OFAC's enforcement guidelines provide significantly reduced penalties for entities that voluntarily self-disclose apparent violations. The 2021 ransomware advisory explicitly encourages self-disclosure of payments to designated entities, with a presumption of mitigation for voluntary reporting.
Check any wallet, name, or entity against OFAC, EU, UN sanctions lists in real time.
Free wallet checker