The Biden administration this week announced new security guidance to target those who facilitate ransomware payments, laying out an action plan that focuses on disrupting criminal networks and virtual currency exchanges. It follows on the heels of a surge in ransomware payments, which more than doubled from 2019 to 2020 to some $400 million globally.
It’s no secret that it’s been a big year for ransomware, with an increasing number of remote employees more susceptible to cyberattacks while working on their own networks amid the pandemic. The White House signaled in July a sharpened focus on the problem, and on Tuesday the U.S. Department of the Treasury said it will target those who facilitate ransomware payments.
The department called on private sector entities that may be targets — including banks and financial institutions (FI) — to prevent and mitigate cyberattacks by practicing good “cyber hygiene.”
The Treasury Department’s Office of Foreign Assets Control (OFAC) also released an updated advisory on the risk of sanctions for facilitating ransomware payments — mostly cryptocurrency — which is easy to send and difficult to trace. OFAC recently sanctioned cryptocurrency exchange SUEX OTC, claiming that “over 40% of SUEX’s known transaction history was associated with illicit actors.”
OFAC strongly discouraged payment of ransomware demands and urged those who fall victim to cooperate with the appropriate authorities.
Takeaways for banks and FIs
Bank Automation News sought expert input on what the U.S. Treasury’s multi-angle ransomware crackdown means for banks and FIs, much of which boiled down to a single word: diligence.
“Organizations need to take OFAC sanctions risk into account in any ransomware incident, specifically in determining whether and under what circumstances they pay, process, facilitate, or in the case of insurance, indemnify a ransomware payment,” reads a report on this matter from the Association of Certified Anti-Money Laundering Specialists, a global professional organization whose more than 82,000 members work in the compliance industry.
The government action could indeed help curb ransomware attacks, but only if other governments take similar steps, Kenneth Mendelson, senior managing director at security, compliance and investigatory services consultancy Guidepost Solutions, told BAN.
“Adding compliance risk to the risk from ransomware itself may seem onerous, but OFAC’s mitigating factors provide a qualified ‘out’ by encouraging companies to cooperate with law enforcement and to evaluate the sanctions risk before making a ransomware payment,” Mendelson said.
Alex Pezold, CEO of Tulsa, Okla.-based TokenEx, a cloud-based data security company, agreed, and praised the action by the U.S. Treasury.
“Cybercriminals are constantly evolving ways to compromise and exploit consumer data, forcing the clear need for these sanctions,” Pezold said. “The decentralized nature of cryptocurrencies can make them harder to trace, which only serves to encourage bad actors.”
Banks and FIs should have a detailed strategy in place for ransomware and other cyberattacks, Pezold told BAN. “Every organization must address these concerns and prioritize and develop a plan for which data to protect,” he said. “Another consideration must be to build resiliency into the company’s systems so that rebooting is possible, if something were to happen.”
But, whether the U.S. Treasury’s crackdown will slow cybercriminals in an ever-growing wave of ransomware attacks remains to be seen.
“Sanctions like these are positive, but at this stage they will not deter attackers, who can still easily use different exchanges or payment methods,” said Danny Lopez, CEO of cybersecurity firm Glasswall, a provider of file sanitation solutions — including to the U.S. intelligence community. Traditional approaches to IT security are inadequate, he said, suggesting an alternative for banks, FIs and other potential targets.
“‘Zero-trust security’ sees the world differently, and is the approach that needs to be adopted,” he told BAN. “It means that no one is trusted by default, regardless of whether they are inside or outside a network.”
“In a world where data can be held amongst multiple cloud providers, it is crucial to strengthen all processes relating to access verification,” Lopez said. “Without a zero-trust approach, organizations run the risk of attackers having free reign across a network once they are inside.”






