OFAC imposes sanctions on crypto exchange on ransomware payments, warns companies of potential sanctions – Tech

[ad_1]

United States: OFAC imposes sanctions on crypto exchange on ransomware payments, warns companies of risk of sanctions

22 October 2021

Arnold & Porter

To print this article, simply register or connect to Mondaq.com.

On September 21, 2021, the U.S. Department of the Treasury announced that it would enforce sanctions laws against cryptocurrency exchanges that facilitate ransomware payments, as part of the department’s broader effort to combat the rising tide of ransomware. Ransomware attacks have grown rapidly in scale, sophistication, and frequency: in 2020, ransomware payments reached over $ 400 million and were made almost exclusively in cryptocurrency. The recent Colonial Pipeline ransomware attack, which resulted in a substantial disruption of fuel supplies in the United States, underscores the emerging nature of threats from cybersecurity attacks. Virtual currency exchanges are critical nodes in the cryptocurrency ecosystem, and recent Treasury actions focus on these exchanges as a way to fight ransomware attacks.

For the first time, the Treasury’s Office of Foreign Assets Control (OFAC) imposed sanctions on a virtual bureau de change, SUEX OTC, SRO (SUEX), for facilitating ransomware payments. According to the Treasury, SUEX facilitated transactions involving illicit products from at least eight ransomware variants, and more than 40% of SUEX’s known transaction history is associated with illicit actors. OFAC has designated SUEX in accordance with Decree 13694, which authorizes sanctions against “persons engaging in significant malicious activities related to cybersecurity”. As a result, all property and interests of SUEX subject to US jurisdiction are blocked and US persons are prohibited from engaging in transactions with SUEX. Additionally, financial institutions and individuals engaged in certain transactions or activities with SUEX may be subject to sanctions or coercive action, even if they are not directly involved in ransomware payments.

Along with SUEX’s announcement, OFAC released an updated notice on potential sanction risks to facilitate ransomware payments. The updated advisory highlights U.S. government policy strongly discouraging payment for ransomware or extortion requests, as well as the importance of robust cybersecurity practices and reporting and cooperation with relevant U.S. government agencies in the event ransomware attack. The notice also states that individuals in the United States may be penalized for making payments to a sanctioned actor, even if they did not know or had no reason to know that they were engaging in a transaction with a sanctioned actor. For your information, OFAC maintains a list of specially designated nationals and stranded people, other stranded people, and countries or regions with which U.S. nationals are generally prohibited from doing business (for example, Cuba, the Crimean region in Ukraine, Iran, North Korea and Syria). The notice essentially states that if a US person makes a ransomware payment, the proceeds of which will go to a sanctioned actor (including, now, SUEX), that payment may constitute commercial activity with a sanctioned party in violation of the rules of the law. ‘OFAC.

In addition, the updated notice provides more information on how financial institutions and other businesses can implement a strong sanctions compliance program, a factor that OFAC can take into account in determining the appropriate response. in terms of application. In particular, companies can reduce the risk of extortion by a sanctioned actor by adopting or improving cybersecurity practices, such as those in the September 2020 Ransomware Guide from the Cybersecurity and Infrastructure Security Agency (CISA). Businesses can also reduce their risk of extortion by “maintaining offline backups of data, developing incident response plans, instituting cybersecurity training, regularly updating anti-virus and anti-malware software, and using authentication protocols “.

The updated advisory provides more details on how to properly report a ransomware attack, another potentially important mitigating factor in OFAC’s enforcement decisions. A ransom demand after such an attack must be self-disclosed to law enforcement or relevant U.S. government agencies, such as the CISA or the Treasury Office for Cyber ​​Security and Critical Infrastructure Protection (OCCIP). Disclosure should be made as soon as possible after discovery of an attack. Businesses should cooperate with the government by providing all relevant information such as technical details, ransom payment requests, and ransom payment instructions. OFAC is more likely to resolve apparent violations involving ransomware attacks with a non-public response, such as a no-action letter or letter of warning, if the company has taken the mitigating action. described in the notice, and in particular whether the company promptly reported the breach to law enforcement and provided continued cooperation.

Businesses face a complex calculation when determining whether to pay ransoms. There is a pervasive risk that cybercriminals will simply accept payment and fail to restore the targeted data. Additionally, paying a ransom does not prevent a cybercriminal from hitting the same victim twice and, in fact, may encourage repeated breaches. SUEX’s Treasury sanction and updated OFAC guidelines remind businesses of the real risks that come with ransom payments. Businesses, of course, will consider the realities that a ransomware attack followed by non-payment can cause immediate financial, reputational, and societal damage. While there is no one-size-fits-all solution to this thorny problem, businesses can put themselves in a more tenable position by implementing robust cybersecurity programs to prevent ransomware in the first place and investing in sanctions compliance procedures to mitigate the risks if they decide to pay the wrong actors. to free their business data.

The content of this article is intended to provide a general guide on the subject. Specialist advice should be sought regarding your particular situation.

POPULAR POSTS ON: US Technology

Sources

1/ https://Google.com/

2/ https://www.mondaq.com/unitedstates/fin-tech/1123926/ofac-imposes-sanctions-on-crypto-exchange-over-ransomware-payments-warns-businesses-on-sanction-risks

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts