# Ransomware Sanctions, OFAC, and the Lazarus Group: A Real Case Study Page: https://stenobird.com/podcast/the-backup-wrap-up-758069/ransomware-sanctions-ofac-and-the-lazarus-group-a-real-case-study Text version: https://stenobird.com/podcast/the-backup-wrap-up-758069/ransomware-sanctions-ofac-and-the-lazarus-group-a-real-case-study.md Podcast: [The Backup Wrap-Up](https://stenobird.com/podcast/the-backup-wrap-up-758069) Published: 2026-04-20T11:00:00+00:00 Episode link: https://www.backupwrapup.com/ransomware-sanctions-ofac-lazarus-group Audio file: https://episodes.captivate.fm/episode/eafb139c-b721-4249-8d02-da0d6aed4150.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/the-backup-wrap-up-758069/episodes/ransomware-sanctions-ofac-and-the-lazarus-group-a-real-case-study Duration seconds: 2192 ## Resource Ransomware sanctions are something most companies never think about — until they're staring down a ransom demand from a group the US government has already put on a sanctions list. In this episode, Dr. Mike Saylor walks us through a real incident involving a construction company, hundreds of millions in active contracts, and the Lazarus Group — a North Korean state-sponsored threat actor. Before that company could pay a single dollar in ransom, they had to figure out whether doing so would trigger federal penalties that dwarfed the ransom itself. We're talking fines of 10x to 100x the payment amount, and in some jurisdictions, jail time. This is one of those episodes where the story alone is worth your time. Mike was in the room for this incident, negotiating directly with the Lazarus Group over a weekend — and yes, it turns out North Korean cybercriminals have a surprisingly functional help desk. But beyond the story, there's real actionable information here about OFAC (the Office of Foreign Asset Control), how the US Treasury tracks Bitcoin wallets to identify sanctioned actors, and what you actually need to do the moment ransomware hits your organization. We also get into why paying a ransom paints a target on your back — 70% of companies that pay get hit again within six months — and why immutable backups are the only thing that truly keeps you out of this situation. Chapters: 0:00 Intro 1:31 Meet the Guests: Curtis, Prasanna, and Dr. Mike Saylor 4:10 Case Study: A Construction Company and the Lazarus Group 6:34 Are These Bad Guys Sanctioned? Introducing OFAC 8:05 Why Ransomware Funds Terrorism, Drug Trafficking, and Worse 11:00 Sanctions Penalties: Fines That Can Put You Out of Business 12:24 Colonial Pipeline and Exceptions for Critical Infrastructure 13:26 How t… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/the-backup-wrap-up-758069/episodes/ransomware-sanctions-ofac-and-the-lazarus-group-a-real-case-study/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/the-backup-wrap-up-758069/ransomware-sanctions-ofac-and-the-lazarus-group-a-real-case-study.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.