Ransomware Sanctions

OFAC sanctions targeting ransomware operators, facilitators, and payment processors. Paying ransom to designated entities is prohibited, and so is facilitating such payments.

TL;DR

TL;DR: OFAC has designated ransomware operators and facilitators on the SDN List, and paying ransom to a designated party is prohibited. OFAC has also cautioned that facilitating ransomware payments can itself create liability.

What OFAC has done

OFAC has used its designation authority to target ransomware actors, the exchanges and mixers they use, and the people who help move their payments. Once a party is on the SDN List, transacting with them is prohibited and their assets are blocked. OFAC has also published advisories warning that paying a ransom to a designated entity is itself a sanctions violation.

The facilitator problem

The risk extends beyond the direct payer. OFAC guidance states that parties who facilitate ransomware payments, such as intermediaries, exchanges, or service providers who enable the transfer, can face liability even if they did not originate the payment. Intent is not required, because sanctions liability is strict.

What screening changes

Before any payment, a screening check against the SDN List and OFAC-listed wallets can reveal whether the destination is designated. If it is, the payment stops rather than becoming a violation. Because ransom destinations are often wallets, screening must cover crypto addresses as well as names. sanctionsai.dev screens 947 OFAC-listed crypto wallets and 19,218 SDN names in under 100 ms, which lets an agent check a wallet before it ever sends funds.

Practical guidance

Screen the destination before paying, keep records of every check, and treat a flagged wallet as a hard stop rather than a prompt to try another route.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →