ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

Is Paying Ransom on a Ransomware Attack Legal?

Cybercriminals have found that extorting organizations through ransomware attacks is a lucrative business model. As malware used in cyberattacks becomes increasingly sophisticated, ransomware attacks are on the rise.

When an organization falls victim to a ransomware attack, it has to decide whether or not to pay the ransom. But is that legal?

In the U.S., the answer is not entirely clear-cut. In a 2020 ruling, the U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) and the Financial Crimes Enforcement Network (FinCEN) declared it illegal to pay a ransom in many cases.

What is Ransomware?

Ransomware is a type of malware that infiltrates a network and devices to block access to your data and other personal information. This information is encrypted by the cybercriminals and held hostage until a ransom is paid.

Unfortunately, ransomware is often very difficult to remove, and paying the ransom does not guarantee that the criminals will restore access to your data.

How Illegal Is Paying the Ransom in the U.S.?

First, it’s important to understand what the OFAC deems illegal when it comes to ransom payments. OFAC explains that ransomware payments made to “sanctioned persons” or “comprehensively sanctioned jurisdictions” could be used to fund terrorist activities that could negatively impact U.S. national security and foreign policy. Additionally, paying up essentially enables future attacks.

OFAC’s ruling applies to individuals and managed service providers that facilitate ransomware attack payments – from cyber insurance companies to cyber forensic firms – stating that they may be prosecuted for arranging payment.

OFAC makes it clear that civil penalties may be imposed for those who violate such sanctions.

How Severe Is the Problem?

The rate of ransomware attacks increases every year. A widespread problem, two notable attacks that had far-reaching consequences were:

  • May of 2021: Energy provider Colonial Pipeline paid a $4.4 million ransom after a ransomware attack forced them to cease operations, resulting in fuel shortages throughout the east coast.
  • June of 2020: Meat supplier JBS paid $11 million following a ransomware attack that halted meat processing and temporarily shut down its plants. This caused the price of pork and beef products to skyrocket across the U.S.

What Should I do if I’ve Been a Victim of a Ransomware attack?

Should you realize that you have fallen victim to a ransomware attack, the first thing to do is contact your IT department or third-party company immediately. They can get a handle on your situation and make a plan for how to move forward. Unfortunately, the data needed to identify the breach source disappears quickly, so you must act fast.

If you have good backups of your data, you are in a much safer state. But if you don’t, you may need to work with the FBI and OFAC to get a proper handle on the matter.

If you have cyber insurance, learn what your options are. Ultimately, knowing how this happened will leave you better prepared for future cyber threats.

Contact Information:

Name: Michael Bertini
Email: michael.bertini@iquanti.com
Job Title: Consultant

Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the following
Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.