OFAC sanctions program

Cyber-Related Sanctions

The cyber-related sanctions program designates persons responsible for significant malicious cyber activities, including hacking, disruption of critical infrastructure, and theft of trade secrets or funds.

Program at a glance

Program codeCYBER
Legal authorityEO 13694 (2015, as amended by EO 13757)
ScopeCyber
Designation volumeHundreds of designations, many with crypto addresses

Who and what it targets

Cybercriminals, state-sponsored hacking groups, ransomware operators, and their money-laundering networks. Many designations include crypto wallet addresses.

Relevance to AI agents

Cyber sanctions are highly relevant to crypto payment agents — designated wallets are often added to the SDN digital-assets list. Pre-transaction wallet screening is the primary control for catching cyber-sanctioned addresses.

Screening note. A counterparty program match is not always a blanket block — the program tag tells your agent how to route the hit (hard block for terrorism/embargo, review-required for sectoral, etc.). SanctionsAI returns the program code on every match.

Frequently asked questions

Do cyber sanctions include crypto wallet addresses?

Yes. Designated cyber actors frequently receive crypto, so their wallets appear on the SDN digital-assets list.

What does EO 13694 cover?

Significant malicious cyber activities harming US national security, foreign policy, or economic health, including infrastructure disruption and fund theft.

Compliance disclaimer. This page is educational and not legal advice. Program scope and current general licenses must be confirmed against the live OFAC programme page and, where relevant, by a qualified professional.

Screen a counterparty against every program

Returns the program code on every match. Free tier: 5 checks/day.

Screen a counterparty free →  See pricing