Ukraine and its neighbours, explained

Advertisement

Home › World › Ransom payments and pipeline waivers in May 2021

World

Ransom payments and pipeline waivers in May 2021

Summary

A look back at two U.S. decisions reported around 22 May 2021 that touched on Russia: an insurer's ransom and a sanctions waiver.

What did two developments reported just before 22 May 2021 reveal about how Washington handled Russia-linked issues? One concerned a ransomware payment, the other a pipeline.

On 21 May 2021, CNA Financial, the seventh-largest commercial insurer in the United States, disclosed that it had been hit by a ransomware attack in March 2021. The company paid $40 million to a group named Phoenix two weeks after company data was stolen and officials were locked out of its network. The attackers used malware called Phoenix Locker, a variant of ransomware known as Hades. Cybersecurity experts said Hades was created by a Russian cybercrime syndicate known as Evil Corp.

That link carried legal weight. In December 2019, the Treasury Department announced sanctions on 17 individuals and six entities tied to Evil Corp. The designation made it illegal for a U.S. company to knowingly pay a ransom to Evil Corp.

On 19 May 2021, the Biden administration lifted sanctions on the Nord Stream 2 pipeline project between Russia and Germany. The U.S. State Department said it had concluded that a waiver served the U.S. national interest, even though Joe Biden personally opposed the project.

Together, the two reports showed sanctions policy in practice: one set of measures tied to Russian criminal networks, and one waived for a Russia–Germany energy project.

Related analysis