Ravi Nayyar’s Post

View profile for Ravi Nayyar

Critical Software and Critical Infrastructure Law | PhD Scholar

'... a crypto wallet that was not associated to any entity sanctioned by OFAC ... '[Ransomware authorship] cannot establish a link that the author of the software had an interest [in the attack and thus benefitted from the ransom] ... '... OFAC had been informed of the Ransomware Attack and had not initiated any enforcement proceedings neither against the insured nor against the intermediary tasked with making the ransomware payment ... 'The cantonal court thus ruled that it was highly unlikely that the Insurance would be subject to [US sanctions] penalties ... [Insurer then appealed unsuccessfully.] '... failed to establish that an entity sanctioned under US sanctions regulations (Evil Corp) was involved in the Ransomware Attack and was the beneficiary of the ransom payment ... failed to demonstrate that it was exposed to the risk of being sanctioned under US sanctions regulations. As a result, the Insurance could not rely on the Sanctions Clause ... '... difficulties of attribution of cyberattacks which is a major policy challenge that goes way beyond contractual disputes ... 'The issue is whether it can consider that any cyberattack that would have been committed using said ransomware could solely be attributable to the author of the ransomware'. Wait, does this approach mean that ransomware sanctions may not actually be the ideal tool for stopping _victims_ from paying? They could still work to isolate crims within their ecosystems, of course. Maybe sanctions clauses should say 'if the ransomware code is sufficiently similar to the code dished out by a sanctioned person or group more generally at the time of the attack, we won't pay'? cc: Luke, Adam https://lnkd.in/guCvfN_f

4A_206/2023 | Cyberinsurance Coverage for Ransomware Payments vs US Sanctions Regulations - Swiss Contract Law

4A_206/2023 | Cyberinsurance Coverage for Ransomware Payments vs US Sanctions Regulations - Swiss Contract Law

https://swisscontract.law

To view or add a comment, sign in

Explore topics