• Login
    • Advanced search
    • Title
    • Channel
    • Module
  • Home
  • Industry
    •  

      • Aerospace, Defense, and Government Services
      • Automotive
      • Consumer
      • Manufacturing and Industrials
      • Education
      • Energy and Natural Resources
      • Financial Institutions
    •  

      • Insurance
      • Life Sciences and Health Care
      • Private Capital
      • Real Estate
      • Sports, Media and Entertainment
      • Technology and Telecoms
      • Transport and Logistics
  • Practice
    • Corporate & Finance

      • Banking and Loan Finance
      • Business Restructuring and Insolvency
      • Capital Markets
      • Corporate Governance and Public Company Representation
      • Digital Assets and Blockchain
      • Infrastructure, Energy, Resources, and Projects
      • Leveraged and Acquisition Finance
      • Mergers and Acquisitions
      • Pensions
      • Private Equity, Venture Capital and Investment Funds
      • Real Estate
      • Real Estate Investment Trusts (REITs)
      • Tax
      • Transfer Pricing
    • Global Regulatory

      • Administrative and Public Law
      • Antitrust and Competition
      • Communications, Internet, and Media
      • Education
      • Energy Regulatory
      • Environment and Natural Resources
      • Financial Services
      • Food Law
      • Gaming Law
      • Government Contracts and Public Procurement
      • Government Relations and Public Affairs
      • Health
      • Immigration
      • International Trade and Investment
      • Medical Device and Technology Regulatory
      • New Nuclear
      • Pharmaceuticals and Biotechnology Regulatory
      • Privacy and Cybersecurity
      • Space and Satellite
      • Strategic Operations, Agreements and Regulation
      • Transportation Regulatory
    • Intellectual Property

      • Copyright
      • Designs
      • Domain Names
      • IP and Technology Transactions
      • IP Enforcement
      • Patents
      • Trade Secrets and Confidential Know-how
      • Trademarks and Brands
      • Unfair Competition
    • Litigation, Arbitration, and Employment

      • Business and Human Rights
      • Construction and Engineering
      • Corporate and Securities Litigation
      • Employment
      • International Arbitration
      • Investigations, White Collar, and Fraud
      • Products Law
      • Risks, Disputes, and Litigation
  • Comparative guides
  • Engage Premium
  • Login
  • Register
Hogan Lovells Engage 5.7.7
      • Title
      • Channel
      • Module
    • Hit ENTER to search in content
    • Advanced search
    • Login
  • Home
  • Industry
    •  

      • Aerospace, Defense, and Government Services
      • Automotive
      • Consumer
      • Manufacturing and Industrials
      • Education
      • Energy and Natural Resources
      • Financial Institutions
    •  

      • Insurance
      • Life Sciences and Health Care
      • Private Capital
      • Real Estate
      • Sports, Media and Entertainment
      • Technology and Telecoms
      • Transport and Logistics
  • Practice
    • Corporate & Finance

      • Banking and Loan Finance
      • Business Restructuring and Insolvency
      • Capital Markets
      • Corporate Governance and Public Company Representation
      • Digital Assets and Blockchain
      • Infrastructure, Energy, Resources, and Projects
      • Leveraged and Acquisition Finance
      • Mergers and Acquisitions
      • Pensions
      • Private Equity, Venture Capital and Investment Funds
      • Real Estate
      • Real Estate Investment Trusts (REITs)
      • Tax
      • Transfer Pricing
    • Global Regulatory

      • Administrative and Public Law
      • Antitrust and Competition
      • Communications, Internet, and Media
      • Education
      • Energy Regulatory
      • Environment and Natural Resources
      • Financial Services
      • Food Law
      • Gaming Law
      • Government Contracts and Public Procurement
      • Government Relations and Public Affairs
      • Health
      • Immigration
      • International Trade and Investment
      • Medical Device and Technology Regulatory
      • New Nuclear
      • Pharmaceuticals and Biotechnology Regulatory
      • Privacy and Cybersecurity
      • Space and Satellite
      • Strategic Operations, Agreements and Regulation
      • Transportation Regulatory
    • Intellectual Property

      • Copyright
      • Designs
      • Domain Names
      • IP and Technology Transactions
      • IP Enforcement
      • Patents
      • Trade Secrets and Confidential Know-how
      • Trademarks and Brands
      • Unfair Competition
    • Litigation, Arbitration, and Employment

      • Business and Human Rights
      • Construction and Engineering
      • Corporate and Securities Litigation
      • Employment
      • International Arbitration
      • Investigations, White Collar, and Fraud
      • Products Law
      • Risks, Disputes, and Litigation
  • Comparative guides
  • Engage Premium
  • Login
  • Register
  1. News
  2. FinCEN analysis of BSA filings in 2021 reveals increased number and severity of ransomware attacks

FinCEN analysis of BSA filings in 2021 reveals increased number and severity of ransomware attacks

07 November 2022
    • Share by email
    • Share on
    • Twitter
    • LinkedIn
    • Get link
    • Get QR Code
    • Download
    • Print

The Financial Crimes Enforcement Network’s most recent financial trend analysis report on ransomware-related Bank Secrecy Act filings for 2021 reveals an increased number of ransomware attacks and that a substantial number of attacks are connected to actors in Russia.

Index
  1. What is Ransomware?
    1. What happened in 2021?
    2. What is the connection to Russia?
    3. What are FinCEN’s recommendations?
    4. Next steps

What is Ransomware?

In its report, the Treasury Department’s Financial Crimes Enforcement Network (“FinCEN”) defined ransomware as a software that encrypts files and holds the data hostage until the receipt of ransom money. Ransomware attacks have shifted from a “high-volume” approach to a selective one, maximizing the opportunities for return by targeting larger businesses. Since 2019, ransomware groups have adopted new extortion tactics, such as threatening to publish the stolen data, to ensure payment of the ransom is made. 

What happened in 2021?

In 2021, there were 1,013 Bank Secrecy Act (“BSA”) filings that reported $750 million in ransomware-related activity. 2021 has surpassed all prior years in both the number of incidents and total dollar value of ransomware-related incidents reported in BSA filings. In 2021, there was a 188% increase in ransomware-related filings from 2020. Within 2021, there was a rise in incidents between the first and second half of the year. For first half of 2021, FinCEN, using BSA data, reported at least 458 ransomware-related incidents valuing roughly $398 million. In the second half of 2021, at least 793 ransomware-related incidents were reported, valuing roughly $488 million. FinCEN acknowledges that the increase could be attributed to either increased ransomware-related incidents or improved reporting and detection.

What is the connection to Russia?

Roughly 58% of the unique ransomware variants that were reported to FinCEN between July 2021 and December 2021 were identified as potentially being related to actors in Russia. FinCEN recognized the difficulties of malware attribution; however, it identified those 58% of variants as “using Russian-language code, being coded specifically not to attack targets in Russia or post-Soviet states, or as advertising primarily on Russian-language sites.” Of the top five variants reported, four were found to be connected to Russia, based on at least one of the previously listed attributes. Finally, Russia-related variants were connected to 75% of the ransomware-related incidents reported in the second half of 2021.

What are FinCEN’s recommendations?

FinCEN highlights the importance for financial institutions to be able to determine when it is required to file a suspicious activity report (SAR) when dealing with a ransomware incident. FinCEN recommends:

  • Incorporate indicators of compromise into detection systems and enable blocking or reporting of malicious activity
  • Promptly contact law enforcement for any identified ransomware-related activity, Office of Foreign Assets Control (“OFAC”) if the cyber actor is suspected to be sanctioned or have a sanctions nexus, and report suspicious activity to FinCEN
  • Review FinCEN’s report “Advisory on Ransomware and the Use of the Financial System to Facilitate Ransom Payments”

Next steps

For further information on how to incorporate FinCEN’s recommendations into your compliance system or ransomware preparedness and sanctions compliance more generally, please reach out to any of the contacts listed above.

 

 

Authored by Beth Peters, Cassady Cohick, and Andrea Fraser-Reid.

Contacts
Elizabeth Boison
Partner
Washington, D.C.
Anthony Capobianco
Partner
Washington, D.C.
Brian Curran
Partner
Washington, D.C.
Aleksandar Dukic
Partner
Washington, D.C.
Ajay Kuntamukkala
Partner
Washington, D.C.
Beth Peters
Partner
Washington, D.C.
Stephen Propst
Partner
Washington, D.C.
Kelly Ann Shaw
Partner
Washington, D.C.
Ben Kostrzewa
Registered Foreign Consultant
Hong Kong
Index
  1. What is Ransomware?
    1. What happened in 2021?
    2. What is the connection to Russia?
    3. What are FinCEN’s recommendations?
    4. Next steps
Related Materials
finance/money6

Treasury Department issues ransomware guidance in response to significant uptick in ransomware attacks

globalreg_sept2021_cyber

Ransomware sanctions and the U.S. Government's latest strategy to address cyber threats

PLEASE DO NOT USE: DUP_TMT, Hong Kong, November, Data protection and cybersecurity

To pay or not to pay: Another regulator weighs in on the decision to pay a ransom

Sanctions Navigator

Sanctions Navigator: Russia Sanctions

Keywords Ransomware, malware, BSA, Bank Secrecy Act, Anti-Money Laundering Act of 2020, FinCEN, malicious software, ransomware-as-a-service, RaaS
Languages English
Topics Economic Sanctions, Anti-money Laundering and Counter-terrorism Financing
Countries United States
Delete Comment ?

Are you sure want to delete comment ?

Get link
Embed
Share by email
Get QR Code

Scan this QR Code to share this content

  • Contact us
  • Disclaimer
  • Privacy
  • Cookies
  • Legal Notices
  • Terms of Use

 

This website is operated by Hogan Lovells International LLP, whose registered office is at Atlantic House, Holborn Viaduct, London, EC1A 2FG. For further details of Hogan Lovells International LLP and the international legal practice that comprises Hogan Lovells International LLP, Hogan Lovells US LLP and their affiliated businesses ("Hogan Lovells"), please see our Legal Notices page. © 2022 Hogan Lovells.

Attorney advertising. Prior results do not guarantee a similar outcome.

Thomson Reuters HighQ Logo
© 2023 Hogan Lovells | Privacy Policy | Terms of Service