WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Treasury Department Warns of Potential Penalties for Ransomware Victims Who Pay
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Treasury Department Warns of Potential Penalties for Ransomware Victims Who Pay

Author: Charles Egli

Created: Tuesday, October 6, 2020 - 17:29

Categories: Cybersecurity

Late last week, the U.S. Treasury Department published an advisory warning that ransomware victims who pay hackers that are under U.S. sanctions could be punished. The advisory, which came from the Treasury’s Office of Foreign Assets Control (OFAC), also warned financial institutions, cyber insurance companies, and cybersecurity firms that help ransomware victims identify and respond to attacks that they could suffer fines if they aided payments to attackers from places like Russia, North Korea, or Iran that are on the U.S. sanctions list. Additionally, OFAC noted penalties could be levied against companies that didn’t know they were facilitating ransom payments to hackers on its sanctions list. The office said it would review each case individually when deciding when to impose fines, but said that “self-initiated, timely, and complete report of a ransomware attack to law enforcement” would help avoid civil penalties, as would cooperating with law enforcement. Abetting payments to hackers poses potential national security risks, OFAC said in explaining the reason for its advisory. “Ransomware payments made to sanctioned persons or to comprehensively sanctioned jurisdictions could be used to fund activities adverse to the national security and foreign policy objectives of the United States,” the advisory states. “Ransomware payments may also embolden cyber actors to engage in future attacks.” Read more in an article at CyberScoop.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar