By SanctionsAI team · Updated 2026-08-09

Ransomware payment sanctions evasion risks

Paying ransomware to sanctioned entities or jurisdictions is an OFAC violation. OFAC issued an Updated Advisory on Ransomware Regarding the Use of the Financial System for Facilitating Ransomware Payments in 2021.

TL;DR: Companies paying ransomware demands can face OFAC penalties if the recipient is a designated entity or located in a comprehensively sanctioned jurisdiction. OFAC's 2021 advisory warns that ransomware payments to sanctioned actors constitute sanctions violations regardless of intent.

OFAC's ransomware advisory

In September 2021, OFAC published an updated advisory making clear that paying ransomware to sanctioned entities, including those in comprehensively embargoed jurisdictions (Cuba, Iran, North Korea, Syria, Crimea/DNR/LNR), violates sanctions. The advisory offers a safe harbor for voluntary self-disclosure.

Designated ransomware actors

OFAC has designated multiple ransomware operators and associated crypto exchange services under various programs. Notable examples include actors linked to Evil Corp, the Lazarus Group, and darknet markets like Hydra. Each designation means US persons cannot pay them, even under ransomware extortion.

Risk factorOFAC implication
Ransomware actor is SDN-listedPayment is a direct sanctions violation
Payment routed through comprehensively sanctioned jurisdictionViolation regardless of recipient identity
Payment to known ransomware affiliate in non-sanctioned jurisdictionLegal but high-risk; may facilitate future sanctions evasion
Voluntary self-disclosure of accidental payment to SDNMay qualify for mitigation under OFAC enforcement guidelines

Safe harbor: voluntary self-disclosure

OFAC's enforcement guidelines provide significantly reduced penalties for entities that voluntarily self-disclose apparent violations. The 2021 ransomware advisory explicitly encourages self-disclosure of payments to designated entities, with a presumption of mitigation for voluntary reporting.

Compliance control: Before any ransomware payment, screen the recipient wallet against OFAC SDN addresses. If the wallet is designated, do not pay. File a voluntary self-disclosure if a payment was already made.

Screen your agent's next payment

Check any wallet, name, or entity against OFAC, EU, UN sanctions lists in real time.

Free wallet checker

Frequently Asked Questions

Is paying ransomware illegal under OFAC?
Paying ransomware to OFAC-designated entities or to anyone in a comprehensively sanctioned jurisdiction is a sanctions violation. Paying non-designated actors is not illegal under sanctions law but may violate other laws.
What should I do if I already paid a designated ransomware actor?
File a voluntary self-disclosure with OFAC immediately. The enforcement guidelines offer significantly reduced penalties for voluntary disclosure with cooperative remediation.
Does the OFAC advisory apply to crypto payments?
Yes. OFAC's sanctions apply to all transactions by US persons regardless of payment method. Crypto ransomware payments to designated wallets are violations.
Can I screen a ransomware wallet before paying?
Yes. Screen the recipient wallet address against OFAC SDN crypto addresses. agentmail provides free wallet screening at /tools/wallet-checker.

← Back to evasion · SanctionsAI