OFAC Ransomware Screening
Applying sanctions screening to ransomware payments, where OFAC has designated ransomware operators and their wallet addresses.
TL;DR
TL;DR: Paying a ransomware operator can itself be a sanctions violation when that operator or its wallet is designated, so ransomware payments must be screened before they are made.
Why ransomware payments are sanctioned
OFAC has designated ransomware operators and the wallet addresses they use to collect payments. Paying a designated ransomware wallet, even to recover encrypted data, is a prohibited transaction because the recipient is on the SDN List or its wallet is blocked. Under strict liability, intent is not required: the victim who pays a designated wallet has still violated sanctions. OFAC guidance also encourages victims to report ransomware incidents to law enforcement, and paying a listed wallet compounds the harm rather than resolving it.
The screening obligation
The control is the same as any other payment: check the recipient before sending. For crypto ransomware, the recipient is a wallet address, so wallet screening is the critical check. A victim who screens and finds the wallet is listed should not pay, and should instead seek alternative recovery paths and report the matter.
Screening for agents and responders
sanctionsai.dev tracks 947 OFAC-listed crypto wallets among its checks. A wallet submitted before payment returns ALLOW or BLOCK in under 100 ms, so an automated responder or agent does not pay a designated ransomware wallet. The dispute_open tool can then document the finding for the record. For automated response tools, the wallet screen is the difference between a compliant pause and an accidental violation.