OFAC Cyber-Related Sanctions

Sanctions that target malicious cyber actors, including state-sponsored hacking groups, ransomware operators, and the people who support them.

TL;DR

TL;DR: Cyber-related sanctions block the wallets, groups, and facilitators behind hacking and ransomware. Because these actors transact in crypto, screening wallet addresses is the core defense.

Why cyber actors are a sanctions target

OFAC designates malicious cyber actors and their infrastructure, including the cryptocurrency addresses used to collect ransom payments. These listings flow into the SDN List, which means a wallet can become blocked by name and address. Because the actors move funds through crypto, a payment sent to a listed wallet is a sanctions violation even if the sender never knew who was behind it.

Why it matters for agent payments

An agent paying out in crypto needs to screen the destination wallet, not just the counterparty name. The live data set tracks 947 OFAC-listed crypto wallets alongside 19,218 SDN names, so a single screening call can catch a listed address before funds are sent. Screening the wallet is what stops an automated payment from landing in a sanctioned actor's hands.

What to check

Why crypto changes the screening picture

Crypto changes what screening has to check. A name match is not enough when the sanctioned party's exposure is a wallet address, and listed addresses are not guessable. The screening data must include listed wallets alongside names, and the check must run on the destination address before any onchain transfer. For an agent that pays in stablecoins or native assets, the wallet check is the point where a cyber designation is actually caught.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →