Unpacking the Biden administration’s (crypto-friendly) blitz on ransomware

Quick Take
- The Biden administration’s rollout of its strategy against ransomware managed to get all of the relevant government agencies on the same page.
- It also went out of its way not to upset the crypto industry, which has reacted vocally to recent threats of a crackdown.
We'd love your feedback.
Crypto media outlets are remarkably fond of blowing the whistle on perceived government crackdowns.
The recent wave of action by the US government against the global ransomware ecosystem is not exactly one of those. And that was by design.
The concerted, government-wide effort, culminated in the second-ever sanctions imposed on a crypto exchange — just a month and a half after the first — and a number of indictments.
Those actions, alongside a flurry of regulatory guidance over the course of October, were the fruits of a number of announcements from President Biden himself following spring’s massive ransomware attacks.
But while this could be called a crackdown, the administration has deftly choreographed its "all-of-government" approach to ransomware with an eye to keeping the crypto industry on its side.
All-of-government
“There’s a belief, to be frank, that we’re at odds,” Deputy Secretary of the Treasury Wally Adeyemo told an audience of the crypto industry at a Chainalysis event on November 4. “But this is not how we see things. We cannot stress this enough.”
Adeyemo’s comments followed a busy October for the Treasury. Just days later, Adeyemo would once again appear before the world, this time next to Attorney General Merrick Garland, Deputy Attorney General Lisa Monaco, and FBI Director Chris Wray, each of whom took part in a strike against several ransomware operators and an exchange, Chatex, that they found had been laundering payouts.
There is no guarantee that this push will ultimately play out in the interests of the crypto industry. However, the Biden administration’s ransomware initiative has thus far proved to be a more effective use of bureaucracy than, for example, the Steve Mnuchin-led Treasury’s rushed proposal last year to introduce new reporting rules targeting so-called unhosted wallets.
That proposal was contentious enough within the Treasury on its own that the agency’s Financial Crimes Enforcement Network (FinCEN) did not put it up on its own site, leaving it to the Treasury itself to post.
In this case, the first step in the campaign was to escalate ransomware to the level of other national security threats, including terrorism. This meant that the National Security Council was the origin point. A direct point of contact with the White House, the NSC unites a number of cabinet-level figures, including the Secretaries of Defense, Energy and the Treasury as well as the Attorney General.
Within that constellation of agencies, the State Department set up a hotline for public intel into ransomware. The actual analysis that identified Suex, the Russia-based over-the-counter desk that Treasury sanctioned in September, likely entailed low-level interactions between the CIA and the Treasury’s Office of Foreign Asset Control, with assistance from outside contractors.
This illustrates another common pattern with these inter-agency interactions: They don’t always start top-down, depending instead on analysts exchanging information that links on the chain filter out before they get to the top.
Treasury's toolkit
Taking point on the ransomware push has been the Department of Treasury, helmed by Secretary Janet Yellen. However, Yellen’s public appearances have been more focused on campaigning for global minimum corporate taxes. Her deputy, Wally Adeyemo, has largely been the public face of the ransomware campaign.
The Treasury is divided into four sub-offices (see the diagram below). At the center of October’s announcements was the Office of Terrorism and Financial Intelligence, which includes both the Office of Foreign Assets Control (OFAC) and, though it isn’t named in the schematic, FinCEN.
Brian Nelson and Elizabeth Rosenberg are the Biden administration’s nominees to serve as undersecretary and assistant secretary for the Office of Terrorism and Financial Intelligence, respectively. Despite appearing in congressional hearings in June, however, their nominations have been stalled. While they are active in the office, they maintain low public profiles, certainly relative to Adeyemo.
The department’s subdivisions are “very much separate," according to Robert Baldwin, head of policy at the Association for Digital Assets Markets. Baldwin was at the Treasury until this spring, primarily serving as an advisor to Deputy Secretary Justin Muzinich. In that role, he helped coordinate the Mnuchin-era President’s Working Group stablecoin report. "It's the role of the secretary and secretary senior staff to go in and blend the threat finance with the domestic finance and innovation side of things," said Baldwin.
With respect to crypto
Starting in September, the Administration ramped up its engagement with the crypto industry on the subject of ransomware via a series of announcements that various wings of the executive branch crafted, timed and deployed so as to reassure licit players that they were not the target.
First, OFAC pushed out the Suex designation on September 22 — and took the unusual step of inviting press from the cryptocurrency industry into a briefing to prepare them for the announcement. On October 1, the office pushed out an advisory to cybersecurity firms that warned that facilitating ransomware payouts might end up violating sanctions.
On October 15, OFAC followed up with simple crypto industry-targeted guidance on how to avoid future designations. “It’s our hope that the guidance we issue, and the open lines of communication we have with industry players, will help the virtual asset industry hold itself to the highest standards,” a representative for OFAC told The Block.
The next day, October 16, FinCEN released its data, which charted a massive increase in ransomware reporting in 2021 — though the office’s framing downplayed the fact that it was a more notable increase in reporting, rather than suspicious activity tied to ransomware. The data and the messaging around it aimed to validate the previous month’s level of alarm.
And then on October 19, Adeyemo appeared before the Senate Banking Committee, testifying on sanctions policy and requesting more funds to hire technical experts.
“I thought it was pretty elegantly done if you step back and think about the intent there,” Ari Redbord told The Block. Formerly a senior advisor for the deputy secretary and the under secretary for the office of terrorism and financial intelligence, he moved to blockchain analytics firm TRM labs last year.
Redbord described the Treasury’s messaging as “We can go after the illicit actors without upending the licit crypto ecosystem.”
Mission accomplished?
But then, with the November 8 Chatex designation, the Treasury conspicuously highlighted the span of its “all-of-government” work, highlighting a host of other agencies.
“It’s good to be able to talk about the interagency efforts that we’ve launched to combat ransomware,” Adeyemo said at a press briefing, during which he shared a stage with the leaders of the Department of Justice and the FBI.
Attorney General Merrick Garland, Deputy Attorney General Lisa Monaco, and FBI Director Chris Wray touted indictments, arrests and Bitcoin seizures against two leaders of criminal ransomware gangs. The Department of State announced a rewards program for information leading to similar arrests. All parties present were careful to highlight the international cooperation that had led to the moment.
That final announcement was a carefully orchestrated display. The Justice Department had been holding its indictments under seal for six weeks prior. Chatex itself was a known affiliate of Suex even at the time of the latter’s designation. Both were founded by Egor Petukhovski, who announced his departure from Chatex immediately after Suex’s designation, though the Treasury has not added Petukhovski to its specially designated nationals list yet.
The announcements bundled up into that one-day event had largely been on deck, waiting for the coordination necessary to combine them into one attention-grabbing news event.
Cynically, it's a way to flaunt a win and distribute the positive PR from that success across the Biden administration. A press blitz, in other words. But the administration’s overall strategy against ransomware seems to have yielded results. No attacks of the scale of the Colonial Pipeline attack have hit U.S. infrastructure in recent months.
Moreover, the Treasury’s pacing and approach seems to be keeping at least the domestic cryptocurrency industry on board, which is a rare achievement given that cracking down on ransomware fundamentally depends on getting the industry to advance its know-your-customer initiatives.
That compliance could change if the administration gets more aggressive. But for the time being, its key operators seem keen to telegraph moves well in advance, both to allow for internal communications and to avoid spooking the industry.
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

