Swift Quoted in Legaltech News About Impact of U.S. Treasury Department Sanctions in Ransomware Payments
August 7, 2020
Legaltech News
Partner Christopher Swift was quoted in the Legaltech News article, “Treasury Department Potentially Making Ransomware Payments More Complicated — and Costly,” which discussed how companies impacted by ransomware also need to think about U.S.Treasury Department sanctions when deciding whether to pay ransomware. The Office of Foreign Assets Control, a financial intelligence and enforcement agency within the U.S. Treasury Department, maintains a Specially Designated Nationals and Blocked Persons List of groups or individuals that U.S. persons are “generally prohibited from dealing with,” which includes the payment of cryptocurrency ransoms. While OFAC has yet to levy penalties against businesses who pay ransom to an SDN list entity, companies in the midst of a cyber crisis may still have to proceed carefully.
Swift noted that a business could very quickly see its financial exposure rise beyond a hypothetical million-dollar ransom. “Not only have you paid a million dollars to a criminal group … the penalties when the Treasury Department finds out about it and comes after you are going to be anywhere from $300,000 to $2 million on top of the ransom you just paid, plus the cost of attorneys’ fees,” he said.
But the calculus that a company faces when deciding whether to pay a cryptocurrency ransom to an actor on the SDN list also extends beyond the financial considerations involved. Like many other types of cyber incidents, Swift pointed out that there’s a reputational element that a business has to consider when being publicly seen as doing business with a criminal or potentially even a terrorist organization.
Some businesses may also find unexpected value in consulting with their information technology departments about the full extent of their backups, which Swift thinks can often extend further than a business’ leadership knows. “IT departments tend to save a lot of data. Their sort of culture and outlook is built around saving and sustaining data. They save stuff they don’t need to save,” Swift said.
Swift noted that a business could very quickly see its financial exposure rise beyond a hypothetical million-dollar ransom. “Not only have you paid a million dollars to a criminal group … the penalties when the Treasury Department finds out about it and comes after you are going to be anywhere from $300,000 to $2 million on top of the ransom you just paid, plus the cost of attorneys’ fees,” he said.
But the calculus that a company faces when deciding whether to pay a cryptocurrency ransom to an actor on the SDN list also extends beyond the financial considerations involved. Like many other types of cyber incidents, Swift pointed out that there’s a reputational element that a business has to consider when being publicly seen as doing business with a criminal or potentially even a terrorist organization.
Some businesses may also find unexpected value in consulting with their information technology departments about the full extent of their backups, which Swift thinks can often extend further than a business’ leadership knows. “IT departments tend to save a lot of data. Their sort of culture and outlook is built around saving and sustaining data. They save stuff they don’t need to save,” Swift said.
People
Related News
March 13, 2026
In the News
Chris Babcock and Chris Converse on Wave of Companies Moving to Texas
Foley & Lardner LLP partners Chrisopher Babcock and Chris Converse commented on the widening trend of companies reincorporating to Texas in the Houston Business Journal article, “Texas law changes could spark wave of corporate redomestication proposals."
March 12, 2026
In the News
Louis Lehot Explores M&A's Growing Blitzhire Phenomenon
Foley & Lardner LLP partner Louis Lehot authors article on the emergence of blitzhires in the Mergers & Acquisitions article, “Blitzhires: The New Fast-Moving M&A Deal.”
March 10, 2026
In the News
Aaron Maguregui Shares Insights on Shadow AI Risks in Health Care
Foley & Lardner LLP partner Aaron Maguregui was quoted in the Part B News article, “Do you need AI policy? Experts suggest guardrails as 'shadow AI' spreads,” discussing the emerging risks of unsanctioned 'shadow AI' use by clinicians and the need to establish robust AI governance.