Author Archive


Jan

9

Cyber Attacks on U.S. Banks May Be Iranian Retaliation for Sanctions


Posted by at 11:53 pm on January 9, 2013
Category: Foreign CountermeasuresIran Sanctions

Bank of AmericaAccording to this article in the New York Times, the recent DDOS attacks launched against U.S. financial institutions were likely the work of the Government of Iran and in retaliation for U.S. sanctions against Iran and its financial institutions. These attacks, which started in September, have targeted, and caused temporary disruptions to, sites of “Bank of America, Citigroup, Wells Fargo, U.S. Bancorp, PNC, Capital One, Fifth Third Bank, BB&T and HSBC.” Because of the nature of DDOS attacks, these disruptions caused inconveniences to the banks and their customers who were unable to access the websites, but did not result in the theft or compromise of financial data.

The chief evidence for this is indirect: the scope and sophistication of the attacks. Apparently, the attacks infected large data centers with malware and then used those data centers to barrage U.S. institutions web sites with requests in an effort to overwhelm them and take them down. The use of the data centers resulted in attacks that, in some instances, peaked at 70 gigabits.

Although no data was compromised in this instance, the use of data centers in these attack raises yet again the issue of cloud computing and export law given that the malware that turns the data centers into attack bots could, in theory, access customer information, including export-controlled technical data, which might be stored in those data centers. The article does not identify the data centers involved, or whether they were located in the United States or abroad, but if any of these were located in the United States, where U.S companies would be permitted, at least in theory, to store controlled technical data without export licenses, the possibility that a deemed export of that data to Iran has occurred is quite real.

Traditional thinking in the murky area of export law and cloud computing has been that storage of export-controlled technical data on clouds physically located in the United States raised no export control issues. But if these clouds are increasingly targeted by non-U.S. hackers, this assumption may no longer be valid.

Permalink Comments Off on Cyber Attacks on U.S. Banks May Be Iranian Retaliation for Sanctions

Bookmark and Share


Copyright © 2013 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)

Jan

8

When a Voluntary Disclosure Isn’t a Voluntary Disclosure


Posted by at 9:14 pm on January 8, 2013
Category: OFAC

Ellman International HQThe new owners of Ellman International Inc., a New Jersey supplier of medical devices, agreed to pay the Office of Foreign Assets Control (“OFAC”) $191,700 to settle charges that the prior owners of the company exported medical devices to Iran and hired a physician in Iran without authorization from OFAC. Allegedly the medical devices were shipped to Iran through a middleman in Dubai with the knowledge and participation of senior management of the old owners. When the new owners of Ellman discovered the violations after the acquisition, they voluntarily disclosed the violations to OFAC.

Sadly, at least for the new owners, OFAC held that the voluntary disclosure wasn’t a voluntary disclosure under OFAC’s Enforcement Guidelines. In holding that the voluntary disclosure wasn’t a voluntary disclosure, OFAC had this to say:

[T]he submission was determined not to be a voluntary disclosure as defined by OFAC’s Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, App. A (“the Enforcement Guidelines”). OFAC had previously been notified of a rejected transaction between Ellman and a customer located in Iran but did not at that time learn the full scope of the activity because Ellman’s prior owners failed to properly respond to OFAC’s inquiry.

Now, of course, there is a good argument that the one rejected transaction wasn’t eligible for treatment as a voluntary disclosure because OFAC had already been informed of it by the rejecting third party. But it seems more of a stretch to say that everything else in the new management disclosure wasn’t a voluntary disclosure simply because prior management did not respond to an earlier OFAC inquiry on the rejected transaction. Let’s look at the actual language of the Enforcement Guidelines which, shocking as that  may sound, should control here:

Notification to OFAC of an apparent violation is not a voluntary self-disclosure if: a third party is required to and does notify OFAC of the apparent violation or a substantially similar apparent violation because a transaction was blocked or rejected by that third party (regardless of when OFAC receives such notice from the third party and regardless of whether the Subject Person was aware of the third party’s disclosure); the disclosure includes false or misleading information; the disclosure (when considered along with supplemental information provided by the Subject Person) is materially incomplete; the disclosure is not self-initiated (including when the disclosure results from a suggestion or order of a federal or state agency or official); or, when the Subject Person is an entity, the disclosure is made by an individual in a Subject Person entity without the authorization of the entity’s senior management.

Nope. Nothing there at all about failing to respond to an OFAC inquiry as forever barring any future disclosure from being given credit as a voluntary disclosure.

Of course, the moral here is not just that OFAC often doesn’t pay attention to its own regulations. The more important moral, because it’s something that you can do something about, is that acquiring parties need to conduct adequate due diligence and discover export violations before the deal closes, i.e., before it’s too late. Perhaps the new owners did conduct such due diligence, in which case it is likely that there is a hold-back on the purchase price that will be used to pay this fine. But if they didn’t, that was an expensive mistake.

Permalink Comments Off on When a Voluntary Disclosure Isn’t a Voluntary Disclosure

Bookmark and Share


Copyright © 2013 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)

Jan

4

Washington Post Jumps On The “ITAR-Certified” Bandwagon


Posted by at 3:23 pm on January 4, 2013
Category: DDTCPart 122

Washington PostBuried among all the articles on the recent events on the Hill, the Washington Post snuck in an article on the White House’s export control reform initiative and on export controls in general. Unfortunately, but not surprisingly, the reporter gets tangled up in the complexities of the current export control regime and muffs a few things.

The worst of these errors was the simplest one to avoid. As regular readers of this blog know, we have spilled several million gallons of digital ink (or should I say illuminated millions of computer screen pixels?) decrying and ridiculing the concept that the required registration under the International Traffic in Arms Regulations (“ITAR”) for manufacturers of defense articles represents some kind of “certification” of the manufacturer.   Instead, registration signifies nothing more than that the manufacturer filled out a  brief form disclosing certain corporate information and paid the required fee. It is not, by any stretch, an “ITAR certification.”

But now this “certification” canard has wriggled its way into the august pages of Washington’s paper of record:

Building the boards in the United States costs Kincaid “100 to 400 percent” more, he says, but he did not hesitate to fill out the paperwork five years ago and pay the fee, which is now more than $2,000, to become an ITAR-certified manufacturer because he appreciated the made-in-the-United-States sentiment and thought that it might “bring some of the work back.”

Sigh.

And then there’s this:

So a defense contractor sending equipment for U.S. military use on a battle­field abroad must obtain its authorization to “export” its product to a foreign country.

No. If the manufacturer sells the equipment to the U.S. military and they take it abroad, the manufacturer doesn’t need a license.

And this:

As Abrams sees it, the trouble for businesses like Kincaid’s isn’t compliance with export controls but the uneven application of the controls. For instance, her organization has seen identical bid requests “with one stamped ITAR and one not stamped ITAR,” she says. So if one company complies and the other does not, then the noncompliant manufacturer seizes a significant competitive advantage, assuming no one comes calling from the departments of State, Commerce or Treasury — three agencies with different computer systems, missions and cultures, but all with responsibilities in export controls.

Again, no. Neither Commerce nor Treasury would have any responsibilities or jurisdiction over the unauthorized export of ITAR-controlled items.

I spent some time speaking with the reporter on this story and, apparently, did not do a good enough job communicating to him some export control basics, so I take part of the blame for these last two errors. But, I made a big deal with him about “certification” versus “registration,” so there was no excuse for that mistake.

Permalink Comments (8)

Bookmark and Share


Copyright © 2013 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)

Dec

21

How the OFAC Stole Christmas


Posted by at 4:00 pm on December 21, 2012
Category: General

Santa Flanked by F-16

A spokesman for the Treasury Department’s Office of Foreign Assets Control (“OFAC”) told Export Law Blog this morning that discussions between OFAC and the North Pole over Santa Claus’s Christmas Eve itinerary had broken down and were not expected to be resumed before Santa’s scheduled departure on December 24 at 10 pm EST.

The dispute arose from a dilemma that the U.S. sanctions against Cuba posed for Santa’s planned delivery of toys to children in Cuba. If Santa delivers toys for U.S. children first, there will be toys destined for Cuba in the sleigh in violation of 31 C.F.R. § 515.207(b). That rule prohibits Santa’s sleigh from entering the United States with “goods in which Cuba or a Cuban national has an interest.” On the other hand, if Santa delivers the toys to Cuban children first, then 31 C.F.R. § 515.207(a) prohibits the sleigh from entering the United States and “unloading freight for a period of 180 days from the date the vessel departed from a port or place in Cuba.”

A press release from the North Pole announced that the OFAC rules left Santa no choice but to bypass the children of the United States this Christmas. A spokesman from OFAC warned that if Santa attempted to overfly the United States, his sleigh would be forced to land and his cargo seized. He continued:

We know that the outcome is harsh, but we cannot allow the Cuban regime to continue to be propped up by Santa’s annual delivery of valuable Christmas toys to Cuban children.

Congressional leaders did not return our calls.


This post is an annual tradition and appeared previously in 2007, 2008, 2009, 2010 and 2011 in slightly altered form. Export Law Blog would like to take the opportunity of this post to extend its best holiday wishes to all of its readers. Posting will be light between now and the end of the holidays.

Permalink Comments (3)

Bookmark and Share


Copyright © 2012 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)

Dec

20

Credit Bureaus and Merchants Point Fingers at Each Other over SDN Issues


Posted by at 10:35 pm on December 20, 2012
Category: OFAC

Finger PointingAn article that appeared yesterday on Yahoo News details the war between merchants, consumers and credit bureaus when credit bureaus supply information to merchants indicating that the merchant’s customer is on the Office of Foreign Assets Control’s List of Specially Designated Nationals and Blocked Persons, more commonly known as the SDN list. We’ve discussed the issue before but there are a number of names on the SDN list that are common names that are likely shared by a large number of people and the bad guy. The credit bureaus have been sending reports to their customers that indicate hits based on the name alone, without respect to other information in the SDN listing such as date of birth,  leading to consumers being denied credit or services.

Not surprisingly, when denied consumers howl, the credit bureaus say it is the merchant’s obligation to determine if the customer is one the SDN list, and the merchants and customers are saying it’s the credit bureau’s obligation to do further investigation before simply sending the name match as part of its report. Moreover, some credit bureaus are claiming that the OFAC information isn’t part of the credit report, but a separate product, and is therefore not subject to the Fair Credit Reporting Act.

In one case, Cortez v. Transunion, 617 F. 3d 688 (3d Cir. 2010), the Third Circuit sent such an argument packing, holding that the FCRA does apply to the OFAC information and that Transunion breached its duty under the act by failing to maintain adequate procedures to guarantee the accuracy of the reports it supplies to merchants and lenders. The Court also held that Transunion violated its obligations under the FCRA to provide, upon request, a notice to the consumer of the OFAC information and the opportunity to contest it. Since the consumer has no right, at least according to OFAC, to have OFAC clarify that he or she is on the SDN list, it becomes doubly important that consumers at least have the right to contest the appearance of the misleading OFAC information on their credit reports.

I can’t post something on this new story without commenting on this passage early on the story:

Lenders are supposed to check the list each time they receive a new application for credit and face steep penalties of up to $10 million if they don’t. The rule went into effect in 2003 as part of the USA Patriot Act’s broader efforts to kneecap terrorists’ ability to finance a life in the U.S.

To state that the obligation to check the SDN list was first imposed in 2003 by the PATRIOT Act is, of course, utter hogwash. Everyone has been required to check the SDN list for long before that or face penalties if they engaged in transactions with persons or entities on the list. The article is presumably referring to section 326 of the PATRIOT Act, which required Treasury to adopt rules for financial institutions compelling them to adopt a procedure to determine customer identity and to check that identity against the SDN list and similar government lists. Section 326, which applies only to financial institutions, thus, requires those institutions to establish procedures to fulfill their existing obligations to check these lists, an obligation that has been in place for financial institutions and all U.S. persons since at least 1994.

Permalink Comments (1)

Bookmark and Share


Copyright © 2012 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)