Companies may be punished for paying ransoms to sanctioned hackers - U.S. Treasury

Reuters

Published Oct 01, 2020 02:06PM ET

By Raphael Satter

WASHINGTON (Reuters) - Facilitating ransomware payments to sanctioned hackers may be illegal, the U.S. Treasury said on Thursday, signaling a crackdown on the fast-growing market for consultants who help organizations pay off cybercriminals.

In a pair of advisories, the Treasury's Office of Foreign Assets Control and its Financial Crimes Enforcement Network warned that facilitators could be prosecuted even if they or the victims did not know that the hackers demanding the ransom were subject to U.S. sanctions.

Ransomware works by encrypting computers, holding a company's data hostage until a payment is made. Organizations have often ponied up ransoms to liberate their data.

"It is a game changer," said Alon Gal, chief technology officer of Hudson (NYSE:HUD) Rock, which works to head off ransomware attacks before they happen.

Before, companies could decide whether or not to pay cybercriminals off, he said. Now that those decisions are being brought under government oversight "we are going to see a much tougher handling of these incidents."

The Enforcement Network's advisory also warned that cybersecurity firms may need to register as money services businesses if they help make ransomware payments. That would impose a new reporting requirement on a previously little-regulated corner of the cybersecurity industry.