Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Incident Response

Ransomware Response Compliance: The OFAC Sanctions Screen and FinCEN SAR Your IR Team Needs Before the Wire Goes Out

OFAC can fine your organization for paying a sanctioned ransomware group even if you didn't know they were on the SDN list. With Evil Corp, Conti, and dozens of other groups designated, the sanctions analysis happens in the first hours of an incident — not after the payment.

By Rebecca Leung · June 22, 2026 ·
Table of Contents

TL;DR

  • OFAC strict liability means you can be fined for paying a sanctioned ransomware group even without knowing they were on the SDN list — attribution screening before payment is not optional
  • Evil Corp (designated 2019, expanded October 2024), Conti-linked entities, and dozens of other groups are on the SDN list; variant fingerprinting and wallet screening are your tools
  • Financial institutions must file a FinCEN SAR within 30 days of detecting ransomware, using key term “CYBER-FIN-2021-A004,” documenting IOCs including the ransomware variant and any wallet addresses
  • Notification runs on four simultaneous clocks: FFIEC 36-hour, SEC 4-day materiality, state breach laws, and FinCEN SAR — your IR plan needs all four explicitly documented

Most ransomware incident response playbooks are written by IR firms. The technical coverage is excellent: detection, containment, isolation, eradication, recovery. What IR firms don’t specialize in — what most ransomware playbooks get wrong — is the compliance stack that runs in parallel from the moment you confirm an infection. The OFAC screen. The FinCEN SAR. The FFIEC 36-hour clock. The SEC materiality decision. These obligations don’t wait for technical recovery. They start immediately, and they have teeth.

For a financial institution hit with ransomware in 2026, getting the technical response right and ignoring the compliance response isn’t a partial win. It’s a second incident.

The Strict Liability Problem

OFAC’s September 2021 updated advisory states plainly: civil penalties for sanctions violations apply on a strict liability basis. A person subject to U.S. jurisdiction may be held civilly liable even if they did not know or have reason to know that a transaction was prohibited under sanctions law.

Applied to ransomware: if you pay Evil Corp — the Russia-based cybercrime syndicate behind BitPaymer and WastedLocker ransomware variants — you may have violated OFAC sanctions regardless of whether you knew you were paying Evil Corp. The group’s original designees were sanctioned in 2019. Additional members were designated in October 2024. Ransomware variants with known Evil Corp fingerprints have been used against U.S. financial institutions throughout the period between those designations.

This is not a theoretical risk. OFAC has designated multiple ransomware groups, including Evil Corp, Conti-associated entities, and REvil-linked operators. The FBI maintains attribution databases that correlate ransomware variants to designated threat actors. The moment you receive a ransomware demand, you have a compliance obligation to run that attribution analysis before authorizing any payment — not after.

Strict liability doesn’t mean penalties are unavoidable if you accidentally pay a sanctioned actor. OFAC has a robust mitigation framework for violations that are non-egregious and involve good-faith compliance efforts. But mitigation is meaningfully different from no liability, and the mitigation factors are front-loaded — they require actions you take before you pay, not after.

The OFAC Screen: What It Actually Involves

Before any ransomware payment decision, legal and compliance need to complete three screening steps:

Threat actor attribution: Has the FBI or CISA attributed this specific ransomware variant to a designated group? This requires contacting law enforcement early — for financial institutions, the relevant contact is typically the FBI Cyber Division field office for your region. FBI attribution analysis is both an operational asset (they may have decryption keys for known variants) and a compliance asset (their attribution finding supports your OFAC analysis).

Blockchain wallet screening: Cryptocurrency addresses associated with the ransom demand should be screened against known SDN-linked wallets using blockchain analytics tools such as Chainalysis or Elliptic. A match to a known SDN wallet is a hard stop on payment. No match reduces OFAC exposure but doesn’t eliminate it — threat actors use layered infrastructure specifically to obscure wallet attribution.

Variant fingerprinting: Different ransomware variants have identifiable technical characteristics — file naming conventions, encryption methods, ransom note formats, C2 infrastructure patterns. These characteristics, compared against known threat actor profiles in FBI and CISA databases, allow for probabilistic attribution even when wallet screening is inconclusive.

If attribution is uncertain after these steps, OFAC provides a mechanism for voluntary disclosure before payment — contacting OFAC, disclosing the situation, and requesting guidance. Using that mechanism is itself a significant mitigating factor in any subsequent enforcement action.

Document everything. The screening steps you ran, what each step returned, the attribution conclusion, who made the decision, and when. If the screening ultimately supports a conclusion that the recipient is not a sanctioned actor, that documented analysis is your good-faith defense.

FinCEN SAR Filing: What Banks Must Do

For financial institutions, a ransomware attack triggers Bank Secrecy Act SAR filing obligations that are separate from — and in addition to — OFAC considerations.

FinCEN’s guidance requires a SAR when a financial institution knows, suspects, or has reason to suspect that a cyber-event was intended to conduct, facilitate, or affect a transaction — and the suspicious activity involves $5,000 or more in funds. In a ransomware incident, this threshold is almost universally met.

When to file: A SAR must be filed within 30 days of initial detection. The 30-day clock runs from when you had reason to suspect the suspicious activity — which in a ransomware incident is typically the moment you confirm the attack. Continuing activity SARs are required if the incident spans multiple reporting periods.

What the SAR must include: FinCEN’s advisory FIN-2021-A004 on ransomware instructs institutions to include the key term “CYBER-FIN-2021-A004” in the SAR. Beyond the key term, the SAR should document:

  • The ransomware variant (if identified)
  • Indicators of compromise: IP addresses, email addresses, file hashes, domains used in the attack
  • Cryptocurrency wallet addresses associated with the demand
  • Any relevant characteristics of the demand itself (amount, payment instructions, threat actor communications)

When voluntary SAR filing applies: FinCEN also encourages — but does not require — voluntary SAR filing for significant cyber-events that don’t otherwise trigger mandatory filing. If the attack didn’t directly affect transaction systems but involved significant data exfiltration that could facilitate future financial fraud, voluntary filing is appropriate.

The Four-Clock Notification Problem

A ransomware attack on a financial institution doesn’t trigger one notification obligation. It triggers several, running on different clocks, going to different recipients. Managing all of them simultaneously — while the technical team is in incident response mode — requires a pre-documented notification schedule. Here’s the stack:

ObligationTriggerTimeframeRecipient
FFIEC Computer Security Incident Rule”Notification incident” causing harm or likely harm to operations or customers36 hoursPrimary federal regulator (OCC, Fed, FDIC)
SEC 8-K Cyber DisclosureMaterial cybersecurity incident at a public company4 business days of materiality determinationSEC + public disclosure
State breach notification lawsPersonal information of state residents compromised24 hours to 90 days (varies by state)State AG + affected individuals
FinCEN SARSuspicious cyber-related transaction activity ≥ $5,00030 days from detectionFinCEN
OFAC voluntary disclosurePotential or actual payment to sanctioned actorAs soon as possibleOFAC

The FFIEC 36-hour clock starts when you determine you’ve had a “notification incident.” The definition is broader than many compliance teams realize: it’s any incident that results in actual harm — or is reasonably likely to result in harm — to your operations, customers, counterparties, or the provision of services. If ransomware has encrypted your transaction processing systems, that clock is running from the moment you confirm the attack.

The SEC 4-day clock starts when you determine the incident is “material.” Materiality in the cyber context means what a reasonable investor would consider significant: major operational disruption, significant data exposure affecting customer relationships, or costs that would materially affect financial results. Banks and their affiliated public entities need to make that materiality determination explicitly and document it — not default to non-disclosure because the recovery is ongoing.

For state breach notification, the 50-state patchwork means your timeline depends on where your customers are located. A ransomware attack that involves exfiltration of customer personal information triggers the fastest state deadlines — some states require notification within 24–72 hours. Map your customer geography and pre-build the notification sequence before you need it.

The Voluntary Disclosure Multiplier

OFAC’s mitigation framework for ransomware payment violations is built around cooperation and good faith. The most significant thing your organization can do to reduce enforcement risk — more significant than the OFAC screen itself — is to voluntarily self-disclose to law enforcement promptly and cooperate fully throughout the investigation.

What OFAC counts as voluntary disclosure: self-reporting to the FBI, CISA, Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP), or OFAC directly — before regulators independently discover the incident. The disclosure must include technical details about the attack, the ransomware demand, and payment instructions as soon as they’re available.

What constitutes significant mitigation under the 2021 advisory:

  • Strong pre-incident cybersecurity practices (MFA, patching, backups, network segmentation)
  • Prompt law enforcement notification before any payment decision
  • Full cooperation with FBI and CISA throughout the incident
  • Blockchain wallet screening prior to payment
  • Complete and accurate disclosure of incident facts to OFAC if requested

What OFAC considers aggravating: prior sanctions violations, large economic harm, deliberate concealment, or failure to cooperate with investigations.

The practical implication: your legal team should be contacting the FBI Cyber Division field office within hours of confirming ransomware — not primarily for technical assistance, although that’s valuable, but because that notification is the beginning of the cooperation record that OFAC will look at if you inadvertently end up in a sanctions exposure situation.

What Your IR Plan Needs to Add

Most ransomware playbooks are structured around the technical response lifecycle. The compliance obligations don’t appear in the run-book, or appear as a footnote after recovery. That sequencing is backwards.

Here’s what needs to be explicitly in your IR plan:

Legal/compliance notification trigger: At the moment you confirm ransomware, legal and compliance are notified. Not after the technical team assesses scope — at confirmation. The 36-hour clock, the materiality assessment, and the OFAC screen all require legal involvement from hour one.

OFAC screening protocol: A defined sequence — threat actor attribution, wallet screening, variant fingerprinting — that must be completed and documented before any payment decision. If the sequence doesn’t clear, the path to payment goes through OFAC pre-clearance and voluntary disclosure.

Law enforcement notification: Contact the FBI Cyber Division field office. Do it early. Document when you called and what was communicated. This is the first step in your cooperation record and may produce operational value (decryption keys, takedown coordination) in addition to compliance value.

FinCEN SAR decision tree: Who makes the SAR filing decision, based on what criteria, within what timeframe. The 30-day clock is not generous — an institution that doesn’t file a SAR within 30 days because nobody owned the decision has a separate compliance problem on top of the ransomware incident.

Regulator notification schedule: A documented schedule for FFIEC 36-hour notification (who calls, which regulator, what information), SEC materiality assessment (who makes the call, what triggers materiality, who signs off on 8-K), and state breach notification (which states are implicated, what the per-state timeline is, who drafts the notices).

Ransom payment decision gate: If a payment is under consideration, it requires documented completion of the OFAC screen, voluntary disclosure filed with law enforcement, legal sign-off, and board or senior executive approval based on pre-established criteria. No ad hoc payment decisions under the pressure of a live incident.

So What?

In 2025, IC3 received 3,611 complaints related to ransomware, with reported losses exceeding $32 million. Direct ransomware attacks on the financial services sector increased 30% year-over-year, from 156 to 202 incidents. FinCEN’s December 2025 Financial Trend Analysis on ransomware found 1,476 reported incidents in 2024 with total payments of approximately $734 million.

The financial institutions that handled ransomware incidents well in 2024 and 2025 — the ones that avoided OFAC exposure, filed their SARs on time, and notified regulators within their windows — had the compliance obligations pre-built into their IR plan. Legal was in the room from hour one. The notification schedule was already drafted. The OFAC screening protocol was already defined.

The ones that struggled — where SAR filings were late, regulator notifications were delayed, and the OFAC screen happened after someone had already approved the payment decision — were operating compliance in real-time, under the same pressure as the technical recovery. That’s too late.

Your IR plan is a compliance document, not just an operations document. The next time you’re reviewing it, ask your legal and compliance team whether they could execute every step in this article from the first hour of a ransomware incident — without looking anything up. If the answer is no, that’s what the next revision is for.


Related reading: Ransomware Incident Response Playbook: The 24-Hour Checklist for Financial Institutions | FFIEC 36-Hour Computer Security Incident Notification Rule | Incident Triage Techniques: Severity Classification, Materiality, and the SEC 4-Day Clock

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Can OFAC fine you for a ransomware payment you didn't know was going to a sanctioned group?
Yes. OFAC imposes civil penalties for sanctions violations on a strict liability basis — meaning you can be held liable even if you didn't know or have reason to know you were paying a sanctioned entity. This is why OFAC compliance analysis needs to happen before any ransomware payment decision, not after. The September 2021 OFAC advisory is explicit about this: the unknowing nature of a violation reduces penalties but does not eliminate liability.
Which ransomware groups are currently on the OFAC SDN list?
As of 2026, OFAC's Specially Designated Nationals list includes Evil Corp and its affiliates (originally designated 2019; additional members added October 2024), entities associated with Conti ransomware operations, REvil/Sodinokibi-linked entities, and dozens of other cyber-related designees. The FBI and CISA maintain attribution databases that can help identify whether a known variant maps to a sanctioned threat actor. Threat actor attribution is the first step in the OFAC screening analysis.
When is a financial institution required to file a SAR after a ransomware attack?
FinCEN requires financial institutions to file a SAR when they know, suspect, or have reason to suspect that a cyber-event was intended to conduct, facilitate, or affect a transaction — and the activity involves $5,000 or more. In a ransomware incident, this threshold is almost always met. SARs must be filed within 30 days of initial detection, must use the key term 'CYBER-FIN-2021-A004,' and should document indicators of compromise (IOCs) including IP addresses, file hashes, ransomware variant, and cryptocurrency wallet addresses.
What notification obligations does a ransomware attack trigger for banks?
A ransomware attack against a bank or banking organization triggers multiple simultaneous notification obligations: FFIEC 36-hour computer security incident notification to the primary federal regulator (for notification incidents); SEC 8-K disclosure within 4 business days if the incident is material; state breach notification laws for affected residents (24 hours to 90 days depending on state); FinCEN SAR filing within 30 days; and voluntary disclosure to OFAC and law enforcement if there's a potential sanctions nexus. CIRCIA reporting may also apply. These run on different clocks and go to different recipients — a documented notification schedule is essential.
What is OFAC's 'voluntary self-disclosure' factor in ransomware enforcement?
Under OFAC's 2021 updated advisory, voluntarily self-disclosing a ransomware attack to law enforcement — including the FBI, CISA, or Treasury's OCCIP — and cooperating with investigations is one of the most significant mitigating factors OFAC considers in any enforcement action. This self-disclosure must be timely (before OFAC independently discovers the violation) and must include technical details, demand information, and payment instructions. Institutions that prompt law enforcement early and cooperate fully are substantially less likely to face significant civil penalties even if they inadvertently paid a sanctioned actor.
Can you pay a ransomware demand if you screen the wallet and find no OFAC matches?
Wallet screening reduces risk but doesn't eliminate it. Known SDN-associated wallets can often be identified through blockchain analytics tools, but threat actors use layered cryptocurrency infrastructure to obscure attribution. A negative wallet screen reduces your OFAC exposure and counts as a good-faith due diligence step, but it's not a guarantee. The full OFAC analysis includes threat actor attribution (FBI/CISA attribution databases, variant characteristics) in addition to wallet screening — and consulting with OFAC directly before paying is available when attribution is uncertain.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.