Cybercrime DB

OFAC Cybercrime Sanctions Designations and Legal Effect

Designation puts U.S. persons at risk for unknowing violations.

Editorial team · · 11 min read
Cover illustration for “OFAC Cybercrime Sanctions Designations and Legal Effect”
cybercrime sanctions and extraditions · October 8, 2026 · 11 min read · 2,380 words

OFAC's cyber sanctions program is not a symbolic slap on the wrist. A single designation triggers asset freezes, reporting duties, and strict-liability exposure for any U.S. person who deals with the wrong name, whether they knew it was the wrong name or not. This piece walks through how that machinery was built, what it actually does the moment it fires, and who ends up standing in the blast radius.

OFAC did not wake up one day with the power to freeze a hacker's bank account. The authority was built in layers over roughly a decade, and each layer was added on purpose. That is why the whole structure is now so hard to dismantle. The foundation is Executive Order 13694, signed April 1, 2015, and nicknamed "Cyber1." It declared a national emergency over malicious cyber activity coming from outside the United States and gave Treasury the power to freeze the assets of people responsible for it, or anyone helping them.

Executive orders can usually be undone by the next president with a signature. That is not true here, because Congress stepped in. A later sanctions law took EO 13694 and its companion EO 13757 and wrote them into statute. That means undoing them now takes an act of Congress, not a stroke of a pen. A change in administration will not blow it over.

Two root statutes, the general emergency-powers laws that every cyber-related executive order relies on, give the whole system its legal oxygen. Every cyber-related executive order rests on these two laws. The day-to-day rules that regulators and companies actually follow live in 31 CFR Part 578, the Cyber-Related Sanctions Regulations, updated through Federal Register notices as new orders and designations come in. On the people side, the Secretary of the Treasury holds the formal pen for designations, but only after consulting the Attorney General and the Secretary of State. The State Department works alongside OFAC to help identify who belongs on the list. None of this is improvised. It is a deliberately stacked system, built so that no single office and no single signature can take it apart.

The SDN List

A designation is an administrative decision by Treasury that a person or entity meets the legal criteria for sanctions, and the moment that decision is published, the designated name lands on OFAC's Specially Designated Nationals and Blocked Persons List, known universally as the SDN List. The State Department and OFAC work together to build the case before that happens, but the legal effect kicks in the instant the name appears.

OFAC does not only put the person who ran the scam on that list. It also designates the people and companies who helped. The Xinbi Guarantee action from September 9, 2026, is a clean example. Alongside the main criminal marketplace, OFAC designated two supporting entities, SafeW Technology Co., Ltd. and Anwen Technology Co., Ltd., for materially assisting, sponsoring, or providing financial, material, or technological support to the operation. Helping the bad actor is its own offense under this framework.

The SDN List also is not the full map of who is blocked. OFAC applies what is commonly called the ownership rule: any company owned by one or more blocked people, holding a controlling share, directly or indirectly, is itself blocked automatically, whether or not its name appears on the list. A sanctioned individual can set up three shell companies tomorrow, and none of them have to appear anywhere for the block to apply. Anyone doing business due diligence has to check ownership structure, not just run a name through a database.

Crypto adds another wrinkle. Since 2018, OFAC has started attaching specific wallet addresses to designations, a practice now echoed by allied regulators in the UK, the EU, and Australia, closing off some of the cross-border shuffling that used to let sanctioned money hop jurisdictions. The system also has built-in relief valves. General licenses let specific transactions proceed that would otherwise be blocked. Cyber-related General License 1C, for instance, authorizes certain dealings with a foreign intelligence service, and General License 2, issued April 23, 2026, covers transactions tied to a water utility company. Ltd. for drinking water treatment and distribution. The regime can draw a hard line and still carve out room for essential services.

Diagram: How a Designation Fires: The Immediate Legal Duties. Visualizes: Visualize the cascade of obligations that activate the instant a name appears on the SDN List.

A designation does not sit quietly waiting for someone to notice it. It activates a fixed set of legal duties for every U.S. person on the spot, whether or not that person had ever heard of the designated entity before breakfast.

The first and most basic duty is blocking. Any property or interest in property belonging to a designated person, if it sits in the United States or passes through the hands of a U.S. person, has to be frozen and reported to OFAC. There is no judgment call involved; it is a mandatory action, not a suggestion. Civil fines under IEEPA adjust annually and can run high per violation, and willful criminal violations can bring significant fines along with up to 20 years in prison, giving that duty its teeth.

People tend to picture sanctions violations as wire transfers gone wrong, but the reach is broader than money. A prohibited transaction can be something as mundane as downloading a software patch from a sanctioned vendor, or simply continuing to run software or technical services from a company that just got designated. That turns ordinary IT hygiene into a sanctions question, and it raises a security problem on top of a legal one, since software from a newly sanctioned vendor is now untrusted by definition and may sit deep inside a company's infrastructure.

Recordkeeping got heavier too. As of March 2025, the retention requirement for sanctions-related records stretched from five years to ten, which tells organizations that OFAC expects a standing compliance program, not a one-time check before a deal closes. And designations rarely travel alone anymore. The Xinbi Guarantee case paired OFAC's designation with the Department of Justice's Scam Center Strike Force, which seized infrastructure and digital asset wallets the same day the designation was published. The legal and operational hits now land together, by design.

Strict liability as the compliance trap most organizations underestimate

OFAC enforces civil violations of its cyber sanctions program under a strict liability standard. That phrase sounds dry, but it carries a sharp point: a U.S. person can be held liable for dealing with a sanctioned party without ever knowing that party was sanctioned. Not knowing is not a defense. It might shave something off the final penalty, but it does not erase the liability itself. So sanctions compliance here works a lot like a parking ticket written by a camera. The meter does not care that the driver didn't see the sign.

Screening before transacting is the obligation that demands real work here. Facilitation counts too. OFAC has made clear that helping process or arrange a ransomware payment creates liability on its own, and that exposure extends to any third party involved in moving that payment along, not just the organization that wires the funds. An insurer, a negotiator, a payment processor, anyone in the chain can be caught.

Adversaries have noticed, and some are now using AI tools and stolen identities specifically to disguise who they really are and dodge sanctions screening. That raises the degree of difficulty considerably, since the compliance burden now includes screening against counterparties actively trying to look clean.

There is a genuine limit to how far this reach extends, and it showed up in the Tornado Cash litigation. Van Loon v. Treasury ended in a 2024 court reversal, followed by OFAC's formal delisting of Tornado Cash in March 2025. The court found that immutable smart contracts cannot be treated as property subject to sanctions, and that drew a real boundary around OFAC's authority at the edge of decentralized, non-custodial systems. That boundary is narrow. It applies to code that nobody controls, not to ordinary transactions routed through people or companies, and it does nothing to loosen strict liability everywhere else.

Who Is Caught by These Obligations

Picture the compliance perimeter as a fence. For a long time, that fence mostly ran around banks and money transmitters. It now runs around a much bigger yard, one that includes technology companies, cybersecurity vendors, incident response firms, cryptocurrency platforms, and insurers.

Cyber insurers, digital forensics firms, and incident response vendors are squarely inside that fence. If one of them facilitates a ransomware payment on behalf of a client, and that payment reaches a sanctioned entity, the facilitation concept pulls the vendor into the same strict-liability exposure as the client who actually sent the money. Freight forwarders, venture funds, and digital asset companies are finding themselves on the same list of exposed parties, since sanctions enforcement has stretched past banking and trade and into technology, logistics, and crypto infrastructure.

The clearest illustration of vendor risk involves a foreign antivirus company. The Commerce Department's Final Determination barred that company, as of July 20, 2024, from entering any new agreement with U.S. persons involving its cybersecurity or antivirus products, including white-labeled versions resold under someone else's brand. So U.S. companies had to stop reselling, licensing, or integrating those products by September 29, 2024. A piece of consumer security software, quietly running on machines everywhere, turned into a corporate compliance deadline almost overnight. A vendor relationship is itself a compliance surface, not just a technical one.

Crypto businesses face their own flavor of the problem. OFAC attaches specific wallet addresses to its designations, allied regulators issue parallel crypto designations of their own, and on-chain activity can be traced back to sanctioned wallets in ways that leave exchanges and stablecoin issuers obligated to freeze assets at the protocol level. OFAC has said directly that firms engaged in online commerce are responsible for keeping unauthorized transactions with SDN-listed persons off their platforms, and that technology companies should build a risk-based compliance program where sanctions list screening is a standard feature, not an afterthought.

OFAC designations targeting the cybercrime supply chain

The targeting logic behind recent OFAC actions has shifted. Instead of only chasing the person who deployed the ransomware or ran the scam, OFAC is moving up and down the supply chain that makes cybercrime scalable in the first place, going after the infrastructure and services that keep the whole business running.

On July 13, 2026, OFAC designated First VPN Service, known as 1VPNS, and its administrator Dmytro Rashevskyi, for selling VPN access to ransomware groups. In the same action, OFAC designated Yegeniy Vladimirovich Silayev, who sold "cryptors," tools used to disguise ransomware as harmless software, under Executive Order 14390 of March 6, 2026. Neither of these men ran a ransomware operation directly. They sold the tools that let other people run one, and OFAC treated that role as fully designatable.

On November 19, 2025, OFAC joined Australia and the UK in sanctioning a bulletproof hosting provider that kept ransomware infrastructure online. Lining up three countries' SDN-equivalent lists on the same day closes off the old trick of just hosting operations somewhere the sanctions regime in question didn't reach.

The September 9, 2026, action against Xinbi Guarantee shows the ownership and facilitation rules working in practice. Xinbi processed the equivalent of over $24 billion in digital assets and fiat currency through an illicit Chinese-language marketplace. Alongside it, OFAC designated SafeW Technology Co., Ltd. in Singapore and Anwen Technology Co., Ltd. in Cambodia, which supplied encrypted messaging and cryptocurrency payment infrastructure respectively. Neither company ran the marketplace. Both were designated for materially supporting it, which is exactly the standard laid out earlier in this piece.

Aeza Group shows what happens after a designation lands. OFAC designated Aeza on July 1, 2025, and its leadership responded by rebranding and attempting to sever any visible link between Aeza and its new technical infrastructure. That is now a standard adversary move, infrastructure migration dressed up as a fresh start, and it means OFAC has to keep tracking successor entities rather than treating a designation as the end of the story.

Integrity Technology Group makes the final point plain. On January 3, 2025, OFAC sanctioned the company for its role in intrusions tied to a state-sponsored threat actor. Integrity disputed the factual basis of the designation, but the designation stood regardless. Running a commercial, outwardly legitimate business does not shield a company if it is providing infrastructure to a state-linked threat actor.

The pace of designations and agency coordination raises the compliance burden

The rate at which these designations land has picked up, and they rarely arrive as a solo press release anymore. Xinbi Guarantee's designation was timed to match a Department of Justice seizure of infrastructure and wallets the same day. Media Land's designation ran in parallel with matching actions from Australia and the UK. So a single event can trigger obligations across multiple legal regimes at once, not just OFAC's.

For any organization running sanctions screening, this turns compliance into a moving target that a fixed checklist cannot keep up with. A name can go from clean to blocked overnight, ownership structures shift to dodge detection, and successor entities like Aeza's rebrand show up just to confuse screening tools. Static, once-a-quarter reviews do not hold up against a list that changes this often and this unpredictably.

Security vendors publishing research on sanctioned actors or their infrastructure face a version of this same problem: that kind of threat research only holds up if it is anchored in the actual designation mechanics and ownership rules that determine who is legally exposed, not just in the technical details of the malware or the infrastructure itself. Cyberou, a threat-intelligence-powered content studio, works with security vendors on that kind of grounded analysis, tying the technical narrative to the legal architecture that gives it weight.

The broader shape of this is straightforward even if the details get complicated fast. OFAC built a legal structure that does not bend easily, applies strict liability without much patience for good intentions, and now reaches well past the banks it was originally built around. Keeping up with it means treating sanctions screening as a living process, because the list on the wall today is not the list that will be there next month.

Sources

  1. Cyber-Related Sanctions
  2. Treasury Cracks Down on Transnational Criminal Organization Behind Cyber Scam Operations Targeting Americans
  3. Cyber Sanctions - United States Department of State
  4. Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans
  5. Cyber-related Sanctions

More in cybercrime sanctions and extraditions