On July 13, the US Treasury crossed a new line: OFAC, its sanctions enforcement office, designated a VPN provider for the first time for facilitating ransomware attacks. First VPN Service, active since 2014 and openly marketed on cybercriminal forums with a promise of "no logs, no cooperation with law enforcement," is now under sanctions, along with its administrator and a seller of "cryptors," the tools that disguise malware as harmless files to evade antivirus detection.
According to the Treasury, the provider's infrastructure served attacks against American businesses, financial institutions, hospitals and municipal governments, causing billions of dollars in losses. Blockchain analysis by TRM Labs links purchases of the service to groups such as Anubis and Qilin. Two months earlier, Operation Saffron, led by France and the Netherlands with Europol and the FBI, had seized 33 of the service's servers across 27 countries. The sanctions add the financial layer to the judicial one, and London and Brussels announced coordinated packages against Russian cyber networks the same day.
Why bring this to an executive committee? Because this evolution concretely changes the calculus of ransom payment, and it changes it against you if nothing is prepared.
Liability is strict, and the infrastructure is shared
Two mechanisms combine, and their combination is what deserves attention.
- Sanctions liability is strict. A US organization, or one exposed to the US financial system, that makes a payment touching a sanctioned entity or cryptocurrency wallet violates the sanctions regime even unknowingly. "We didn't know" is not a defence.
- OFAC now sanctions infrastructure, not just groups. A VPN, a cryptor seller, previously exchanges and mixers: these services are shared by dozens of criminal groups. The direct consequence: an incident involving an unsanctioned group can still carry a hidden nexus to a sanctioned entity somewhere in the payment or infrastructure chain.
In other words, the question "is our attacker under sanctions?" can no longer be answered reliably in the middle of the crisis, at three in the morning, under the pressure of a countdown. Which is exactly why it has to be handled beforehand.
The decision to pay is a governance decision
OFAC's advisory on ransomware payments says something remarkable: resilience measures put in place before the incident, backups, response plans, business continuity, along with prompt reporting to authorities, count as mitigating factors in enforcement. The regulator explicitly rewards preparation.
A serious decision framework, established in calm conditions, has four elements.
- A documented position of principle on payment, settled by leadership and the board, with the criteria that would justify an exception: lives at stake, total inability to restore, contractual obligation.
- A ready-to-use sanctions screening path: specialized outside counsel, a blockchain analytics provider to trace wallets, OFAC screening of intermediaries. These contracts are negotiated before the incident.
- The insurer involved from the start. Cyber insurers require sanctions screening before reimbursing any ransom; a payment made without them may never be covered.
- The reporting reflex. Alerting authorities early is not just civic duty: it is an explicit mitigating factor, and often a source of real technical help.
The real alternative to paying is recovery
Payment is an option that keeps shrinking: it may be illegal, uninsured, and it guarantees neither the return of the data nor the attacker's silence. The only solid alternative is not to need it, and that is built: immutable backups out of the attacker's reach, recovery objectives (RTO and RPO) that are realistic and tested through actual restorations, a degraded mode that keeps vital operations running.
That is the heart of business continuity planning that survives a cyberattack: when recovery capability is demonstrated, the decision not to pay stops being a heroic gamble and becomes the logical conclusion of a prepared case.
The board question
The agenda item fits in one sentence: "if ransomware hit this quarter, is our position on payment written down, legally verifiable within hours, known to our insurer, and backed by tested recovery capability?" Four yeses, and the organization gets through the crisis executing a plan. A single no, and it will improvise the heaviest decision of the year under a criminal's deadline.
Where FortaRisks comes in
FortaRisks helps turn that preparation into evidence: the Compliance module maps your continuity, backup and incident response controls across more than 30 frameworks into prioritized, documented gaps, ready to present to a board or an insurer. To place your resilience capability in minutes, our free cyber risk score is a good starting point.