Interestingly many, if not most cybercrime organizations are on the OFAC list. So many companies who have paid when hit by ransomware have violated US law.
I am unaware of any prosecutions in this area.
https://ofac.treasury.gov/sanctions-programs-and-country-inf...