• Warning: If you pay ransomware, the US Dept of Treasury may fine you

    Dan Goodin at Ars Technica has a great review of the latest US Treasury Department advisory:

    Businesses, governments, and organizations that are hit by crippling ransomware attacks now have a new worry to contend with—big fines from the US Department of Treasury in the event that they pay to recover their data… payments made to specific entities or to any entity in certain countries—specifically, those with a designated “sanctions nexus”—could subject the payer to financial penalties levied by the Office of Foreign Assets Control, or OFAC.

    The prohibition applies not only to the group that is infected but also to any companies or contractors the hacked group’s security or insurance engages with, including those who provide insurance, digital forensics, and incident response, as well as all financial services that help facilitate or process ransom payments

    It’s an important new angle on an increasingly difficult subject.

    UPDATE: Brian Krebs has a more-detailed look on Krebs on Security.