Loading…
Loading…
The US Cyber-Related Sanctions program was established by Executive Order 13694 (1 April 2015), which declared a national emergency with respect to the threat of significant malicious cyber-enabled activities originating from, or directed by, persons abroad. The EO authorised OFAC to block the property of any foreign person determined to have engaged in or materially assisted, sponsored, or provided support for:
infrastructure, financial systems, or computer networks;
government networks.
Executive Order 13757 (28 December 2016) expanded EO 13694 to include tampering with, altering, or causing a misappropriation of information for the purpose of interfering with or undermining election processes or institutions — codifying the basis for the 2016 election-interference sanctions designations (including Russian GRU and FSB units).
The original regulations (31 CFR Part 578) were published in abbreviated form on 31 December 2015 — a placeholder framework without full interpretive text. The 2022 final rule replaces that placeholder with complete regulatory text across nine subparts, adding:
activity," "critical infrastructure," and related terms for US-person compliance.
assistance, official government business, and NGO activities, mirroring the standard OFAC licence architecture used in other program reissuances.
blocked persons, evasion provisions, and the scope of "materially assisted."
ceiling (up to USD 1.4 million per violation or twice the transaction value as adjusted by the inflation adjustment rules).
The reissuance also triggered an administrative renumbering of Specially Designated Nationals (SDN) entries under the CYBER program, with OFAC publishing updated unique identifier numbers (UIDs) for affected designees.
At the time of this reissuance, the CYBER program's SDN list included individuals and entities linked to:
Intelligence Directorate units 26165 and 74455 (Fancy Bear / Sandworm), responsible for the DNC hack and NotPetya.
cyber nexus.
designated under the IRAN program's cyber overlay.
via DOJ indictment rather than OFAC designation), but the regulatory perimeter covers equivalent actors.
SDN-screening procedures to CYBER-designated entities; the 2022 definitions clarify which services constitute "material support" for sanctioned threat actors.
in or near jurisdictions hosting designated cyber actors face compliance friction; the new general licences (particularly for defensive cybersecurity research and vulnerability disclosure) reduce uncertainty for the security-research community.
sanctioned threat actor holds ≥50% ownership interest — relevant for state-linked technology firms in sanctioned jurisdictions.
designations; subsequent actions targeting ransomware groups (e.g., Evil Corp, Conti affiliates) and cryptocurrency mixers used by cyber actors (Blender.io, Tornado Cash) draw on the definitional framework codified here.
operators based in jurisdictions without extradition treaties, using financial nexus as the jurisdictional hook.
review regulations (Commerce/BIS) or the cyber incident reporting rules (CISA/DHS) to create a broader cyber-threat response architecture.