Category: US State Department (US)

  • Just got this:

    Severing Iran’s Illicit Cash Pipeline

    PRESS STATEMENT

    THOMAS “TOMMY” PIGOTT, SPOKESPERSON

    AUGUST 7, 2026

    The United States is taking decisive action to cut the financial lifelines that sustain Iran’s ruling elite. Today, the U.S. Department of the Treasury took steps to dismantle a web of currency exchange houses and shell companies that helped Iran secretly move hundreds of millions of dollars through the international financial system. Through these networks, Tehran accessed oil revenue and evaded sanctions designed to curb its destabilizing activities, laundering funds using front companies.

    This action demonstrates the Trump Administration’s continued maximum pressure on Iran by cutting off resources the regime uses to threaten regional stability, support terrorism, and advance its military capabilities. By targeting the banks, exchange houses, and individual facilitators that operate this illicit system, the United States makes clear that those who help Iran evade sanctions will face serious consequences.

    The United States remains committed to working with partners across the region and the world to close every avenue Iran uses to fund its destabilizing activities. As the regime’s economic mismanagement and corruption become increasingly apparent to the Iranian people, actions like today’s further isolate the regime from the international financial system and reinforce that Iran’s continued support for terrorism and regional aggression will carry a steep and lasting cost.

    Today’s action is being taken pursuant to Executive Order (E.O.) 13902, which targets persons operating in Iran’s financial and petroleum sectors, and advances the President’s National Security Presidential Memorandum 2 (NSPM-2), to impose maximum pressure on Iran. This is OFAC’s eighth action in 2026 targeting Iran’s shadow banking apparatus, including Iranian banks and their rahbar front companiesexchange houses and their managersmajor financiers, and the Iranian importers and exporters who rely on these financial networks to launder and repatriate revenues. Please see the Department of the Treasury’s press releases.

    but I have not gotten anything from OFAC yet – even checked the Recent Actions page.

    But the press release page already has 2 things with today’s date:

    August 7, 2026

    Treasury Sanctions Crypto Exchanges Funding Iran’s IRGC and Enabling Illicit Finance

    August 7, 2026

    Treasury Dismantles Iranian Regime’s Global Clandestine Currency Networks

    so, stay tuned? I’ll include both Treasury releases when we get the official stuff from OFAC (since my prompt includes the relevant info with the specific designations)

  • Degrading CJNG: Announcing over $100 Million in Reward Offers and Visa Restrictions

    MEDIA NOTE

    OFFICE OF THE SPOKESPERSON

    AUGUST 5, 2026

    In a historic and decisive action in support of President Trump’s mission to eliminate narco-terrorist cartels threatening the American people, the U.S. Department of State’s Bureau of International Narcotics and Law Enforcement Affairs is announcing reward offers under the Narcotics Rewards Program (NRP) and Transnational Organized Crime Rewards Program (TOCRP) totaling up to $102 million for information leading to the arrests and/or convictions, in any country, of eight leaders and associates of Cártel de Jalisco Nueva Generación (CJNG).  These rewards are offered in coordination with the DOJ, DEA, FBI, HSI, IRS, CBP, and the National Coordination Center.

    Last year, the Trump Administration designated CJNG as a Foreign Terrorist Organization (FTO) and a Specially Designated Global Terrorist (SDGT).  CJNG is among the most violent and dangerous narco-terrorist organizations in our Hemisphere, and poisons American communities with illicit fentanyl, cocaine, heroin, and methamphetamine. 

    The reward offers include up to $25 million (an increase from up to $5 million) for Juan Carlos Valencia González, a.k.a. “Pelón,” the new leader of CJNG following the recent death of his stepfather, CJNG founder Nemesio Rubén Oseguera Cervantes, a.k.a. “El Mencho”; up to $15 million (an increase from up to $5 million) for Audias Flores Silva, a.k.a. “Jardinero”; up to $15 million each for Gonzalo Mendoza Gaytán, a.k.a. “Sapo,” and Oseguera Cervantes’ son-in-law, Julio Alberto Castillo Rodríguez, a.k.a. “Chorro”; up to $10 million each for Ricardo Ruiz Velasco, a.k.a. “Tripa,” Julio César Montero Pinzón, a.k.a. “El Tarjetas,” and Carlos Andrés Rivera Varela, a.k.a. “La Firma”; and up to $2 million for Griselda Margarita Arredondo Pinzón.  These reward offers support our U.S. law enforcement partners in crippling the organization’s leadership. 

    Additionally, the Department is imposing visa restrictions on 65 individuals who are family members or close personal or business associates of persons linked to CJNG (who have been sanctioned under Executive Order 14059, Imposing Sanctions on Foreign Persons Involved in the Global Illicit Drug Trade).  Twenty-six of those individuals had existing visas, which have now been revoked.  Since announcing this visa restriction policy in June 2025, a total of 93 visas have been revoked from family members and associates of sanctioned drug traffickers connected to FTO-designated cartels.  Under President Trump and Secretary Rubio’s leadership, violent cartel operatives and their criminal facilitators are no longer able to enter our country and terrorize the American people.

    Today’s reward offers complement the Department of Justice’s announcement of the unsealing of charges against Mendoza Gaytán, Castillo Rodríguez, Ruiz Velasco, Montero Pinzón, and Rivera Varela.

    Today’s reward offers are authorized by the Assistant Secretary for International Narcotics and Law Enforcement Affairs under the NRPwhich supports law enforcement efforts to disrupt transnational drug trafficking globally and bring fugitives to justice, and the TOCRP, which supports law enforcement efforts to disrupt transnational organized crime globally.  The NRP, which was established in 1986, celebrates its 40th anniversary this year and, along with its sister program, the TOCRP, has brought more than 90 transnational criminals and major narcotics traffickers to justice and paid out more than $200 million for information leading to apprehensions and other qualifying outcomes.

    If you have information on Valencia González, Mendoza Gaytán, Castillo Rodríguez, or Ruiz Velasco, please contact the DEA by phone at 1-213-237-9990 (text/WhatsApp/Signal/Threema) or by email at CJNGtips@dea.gov.  If you have information on Montero Pinzón, Rivera Varela, or Arredondo Pinzón, please contact the FBI by phone at 1-800-CALL-FBI or 212-384-1778 (WhatsApp), or online at http://www.fbi.gov/cjngrewardtips.  If you have information on Flores Silva, please contact HSI by phone at 866-347-2423 or online at https://www.ice.gov/tips.  If you are located outside of the United States, please contact the nearest U.S. Embassy or Consulate.  If you are in the United States, please contact the local DEA, FBI, or HSI office in your city. 

    ALL IDENTITIES ARE KEPT STRICTLY CONFIDENTIAL.  Government officials and employees are not eligible for rewards for information furnished while in the performance of his or her official duties.

  • Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers

    MEDIA NOTE

    OFFICE OF THE SPOKESPERSON

    JULY 31, 2026

    This alert is jointly issued by the U.S. Department of State and Federal Bureau of Investigation; Japan’s Ministry of Foreign Affairs, National Cybersecurity Office, National Police Agency, Ministry of Finance, and Ministry of Economy, Trade and Industry; the Republic of Korea’s Ministry of Foreign Affairs and National Police Agency; Australia’s Department of Foreign Affairs and Trade; Global Affairs Canada and the Royal Canadian Mounted Police; France’s Ministry for Europe and Foreign Affairs; Germany’s Federal Foreign Office; Italy’s Ministry of Foreign Affairs and International Cooperation; the Netherlands’ Ministry of Foreign Affairs; New Zealand’s Ministry of Foreign Affairs and Trade; and the United Kingdom’s Foreign, Commonwealth and Development Office and Office of Financial Sanctions Implementation.

    North Korea relies upon a network of skilled Information Technology (IT) workers, deployed within and outside of North Korea, to obtain false identities and remotely earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs.

    North Korean IT workers impersonate nationals of other countries to obtain work and income through online platforms operated by private companies for employment, procurement, and contracting of services. These workers seek out contracts with the intent of remitting their salaries to their parent North Korean agencies. They also pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft, and theft of sensitive information. North Korean IT workers employ increasingly sophisticated methods, including the integration of AI, to obfuscate their identities and expand their activities globally.

    Our countries have repeatedly issued information to warn the international community and private sector of the threat posed by North Korean IT workers. Japan, the United States, and the Republic of Korea issued a “Joint Statement on North Korean IT Workers” in August 2025, and the Multilateral Sanctions Monitoring Team (MSMT) released its second report on North Korea’s violation and evasion of UN sanctions through cyber and IT worker activities in October 2025. The United States, Japan, Republic of Korea, United Kingdom, Australia, and Canada have all issued advisories regarding the risk North Korean IT workers pose to private companies, governments, and individual citizens. We continue to actively monitor and counter the North Korean IT worker threat.

    According to UN Security Council Resolution 2397, all UN Member States must repatriate to North Korea all North Korean nationals earning income in that Member State’s jurisdiction, subject to limited exceptions. Additionally, contracting with North Korean IT workers and paying them for services rendered may also violate the domestic laws of many countries, including Japan, the United States, and the Republic of Korea, and may result in legal consequences or financial penalties.

    The Financial Action Task Force (FATF) identifies North Korea as a high-risk jurisdiction subject to a call for action (blacklist). The FATF continuously reiterates the need to implement robust targeted financial sanctions consistent with relevant UN Security Council resolutions and calls on all jurisdictions to apply countermeasures to protect their financial systems from North Korean money laundering, terrorist financing, and proliferation financing risks. Yet, North Korea has increased connectivity with the international financial system through diversified revenue generation activities, including IT worker schemes. As spotlighted in the FATF’s Complex Proliferation Financing (PF) and Sanctions Evasion typologies report, North Korea frequently uses IT worker schemes to generate revenue that supports its weapons of mass destruction program.

    We urge all countries, companies, and other entities to deepen their understanding of North Korean IT worker schemes and implement measures to counter the tactics listed below. Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.). The following information is provided by states participating in this alert.

    Modus Operandi Used by North Korean IT Workers

    • Many North Korean IT workers register for accounts on online platforms by falsifying their nationality or identity. Typical methods used include forging identification documents and impersonating another person. North Korean IT workers use images of identification documents provided by third parties—such as proxies residing in third countries—to register accounts, while the actual work is conducted by the North Korean IT workers themselves.
    • North Korean IT workers are increasingly likely to use third-party proxies to facilitate the creation of online accounts, participate in job interviews, and even establish in-person contact to create a false sense of trust and obtain work contracts.
    • North Korean IT workers often attempt to avoid being paid by direct deposit and may request payment via money transfer services or cryptocurrency. In many cases, North Korean IT workers provide employers a third party’s bank account as the recipient for payments, request that the third party transfer the funds to a designated foreign account, and provide a part of the payment to the third party as a fee for use of their bank account.
    • North Korean IT workers often possess high-level skills in IT-related work and are seeking work in wider areas—such as the development of web pages, mobile applications, software, and blockchain applications—through online platforms and other channels. In some cases, they also get work contracts directly from companies or individuals.
    • While many North Korean IT workers reside in North Korea, China, and Russia, as well as Southeast Asian and African countries, they may conceal the fact that they are working from abroad using third-party proxies, VPNs, remote desktop software, and similar tools.
    • North Korean IT workers are known to use third-party proxies as facilitators overseas, such as in the United States, to run “laptop farms” which receive company-provided laptop computers for North Korean IT workers to remotely access, obfuscating their true location.
    • In addition to obtaining IT-related work, North Korean IT workers may obtain foreign currency by engaging in fraudulent foreign exchange trading using automated trading systems they themselves developed.

    Furthermore, accounts associated with North Korean IT workers often exhibit the characteristics below. If multiple characteristics apply to a job applicant, there is a possibility that a North Korean IT worker is fraudulently seeking work.

    For companies operating online platforms:

    • Frequent changes to registered information (such as account name, contact details, and bank account information for receiving salaries).
    • The account holder’s name does not match the name on the registered payment account.
    • Multiple accounts have been created using the same identification document.
    • Identification documents used for identity verification appear forged or altered using image editing software.
    • Multiple accounts are accessed from the same IP address.
    • A single account is accessed from multiple IP addresses within a short period of time.
    • The account remains logged in for an unusually long period of time.
    • The cumulative work hours or related metrics are unnaturally high.
    • An account user posts false reviews for itself, likely to improve the account’s rating.

    For those hiring or procuring services:

    • The account’s profile contains errors or uses unnatural expressions that appear to be the result of inaccurate machine translation, indicating a lack of proficiency in the language of the country they claim to be from. (However, North Koreans may use translation services or large language models to produce convincing profiles and communications in second languages.)
    • Discrepancies appear in video conference meetings, including photo ID mismatches or video feeds that appear to be manipulated or artificially generated.
    • Refuses to participate in video conference meetings.
    • Offers to work at rates lower than the general market rate.
    • Shows signs that the account is being operated by multiple people. North Korean IT workers often operate in teams, and the individual whom a hiring or procuring official interacts with may change depending on the time of day.
    • Requests payment in cryptocurrency.
  • If you read through LinkedIn or Bluesky auto-posting, you will not have noticed 2 recent changes to existing posts:

    • The post announcing the UN’s new DRC listings was updated to also include Canada’s adoption of the changes the same day
    • And the post that carried the US State Department about the FTO and SDGT designations of La Viagras and the Juarez Cartel mistakenly said it preceded changes by OFAC. In this case, on Wednesday at about 11:20 AM, OFAC did update those two designations, although the title of the Recent Actions post did not say that designations were being updated (yes, technically, an existing ILLICIT DRUGS E.O. was added to the FTO and SDGT programs making them “new” designations). And the State Department notice came out over 25 hours later, at about 12:30 PM yesterday (all times Eastern). My friend Yoshi tells me that this sort of delay, while much larger than typical post-designation PR by State, is typical. You live and you learn, I guess.

    Humblest apologies,

    Mr. Sanctions

  • Terrorist Designations of the Juárez Cartel and Los Viagras

    PRESS STATEMENT

    MARCO RUBIO, SECRETARY OF STATE

    JULY 16, 2026

    Today, the U.S. Department of State is designating the Juárez Cartel and Los Viagras as Foreign Terrorist Organizations (FTOs) and Specially Designated Global Terrorists (SDGTs). 

    The Juárez Cartel and Los Viagras are violent narco-terrorist cartels that have committed numerous attacks against Americans, Mexican security forces, and civilians, including the 2019 massacre in Sonora of nine U.S. citizens – three adults and six children – killed by hitmen from the Juárez Cartel’s dominant faction La Línea.

    The Trump Administration will continue to use all available tools to protect our nation by keeping poison off our streets and disrupting the revenue streams funding violent narco-terrorists.  Today’s action taken by the State Department further demonstrates that the Trump Administration continues to deliver on its promises to the American people to dismantle narco-terrorist cartels, make American communities safer, and secure the border.

    Terrorist designations expose and isolate entities and individuals, denying them access to the U.S. financial system and the resources they need to carry out attacks.  As a result of actions taken today, all property and interests in property of those designated today that are in the United States or that are in possession or control of a U.S. person are blocked, and U.S. persons are generally prohibited from engaging in transactions with them.  Moreover, designations can assist law enforcement actions of other U.S. agencies and governments.

    Today’s actions are taken pursuant to section 219 of the Immigration and Nationality Act and Executive Order 13224. Foreign Terrorist Organization designations go into effect upon publication in the Federal Register.  

    Normally, these State Department updates appear within a few hours of the OFAC action. So, I thought this was a State Department jumping the gun.

    well, no… Wednesday’s OFAC designations updated those two organizations with the FTO and SDGT tags, but didn’t have a PR about that part of the action… and the title of the Recent Actions piece didn’t event mention that there were designation updates.

    And the timing… State Department PR today at 12:22 PM, OFAC action 11:32 AM on Wednesday…

  • Reporting the news, regardless of my personal opinion:

    Visa Restriction Policy Targeting Far-Left Terrorist and Other Aligned Groups

    PRESS STATEMENT

    MARCO RUBIO, SECRETARY OF STATE

    JULY 16, 2026

    Far-left terrorist and aligned groups often use sophisticated, organized networks to perpetrate violence as a political tool – seeking to implement an extreme political vision through intimidation and coordinated campaigns of terror. It is a strategy that explicitly aims to undermine the political foundations of free and self-governing societies, utilizing bombings, assassinations, and other forms of terrorism to silence speech, limit political opposition, change policy outcomes, and sabotage political processes.

    Today, in support of National Security Presidential Memorandum-7 and ongoing U.S. Government efforts to disrupt networks fomenting political violence before they escalate to criminal action, the Department of State is announcing a new visa restriction policy that targets members of Far-Left Terrorist and other aligned groups who have supported or incited acts of terrorism; supported violent criminal activity; participated in economic sabotage; financed, recruited, or provided logistical support for violent or criminal actions committed by Far-Left Terrorist and other aligned groups; and/or facilitated the convergence of Far-Left Terrorist and other aligned networks for the purposes of violent action.

    This policy will safeguard the American homeland by restricting entry of foreign nationals who finance, recruit, incite, or otherwise enable terrorist, violent, and criminal Far-Left Terrorist networks – closing the visa pathways that Far-Left Terrorists and other aligned groups exploit to threaten American lives, undermine economic stability, and coordinate violent action on U.S. soil.

    These actions are being taken pursuant to Section 212(a)(3)(C) of the Immigration and Nationality Act.

  • Iran: Dismantling Shamkhani’s Illicit Shipping Empire

    PRESS STATEMENT

    THOMAS “TOMMY” PIGOTT, SPOKESPERSON

    JULY 14, 2026

    As part of the United States’ effort to increase pressure on the Iranian regime amid their unlawful attacks on commercial shipping in the Strait of Hormuz, the United States is acting to disrupt and degrade the illicit shipping and sanctions evasion network of U.S.-designated Mohammad Hossein Shamkhani, which serves as a major enabler behind Iran’s oil exports. Today, we are designating more than 50 individuals, entities, and vessels that enable Shamkhani and the Iranian regime to continue profiting while the Iranian people suffer.

    The Shamkhani network relies on a combination of Iranian and foreign nationals and firms to conduct sanctions‑evasion schemes. It also uses offshore shell companies, critical to the network’s ability, to trade sanctioned goods and recover the proceeds of those trades.

    The United States will use all the tools at our disposal to hold the regime accountable for its actions.

    Today’s action is being taken pursuant to Executive Order (E.O.) 13902, which provides authority to the Secretary of the Treasury, in consultation with the Secretary of State, to identify and impose sanctions on key sectors of Iran’s economy. For more information on today’s action, see the Department of the Treasury’s press release.

  • Initiating Rescission Process of Syria’s Designation as a State Sponsor of Terrorism

    PRESS STATEMENT

    MARCO RUBIO, SECRETARY OF STATE

    JULY 8, 2026

    Today, President Trump informed Congress of his administration’s intent to rescind Syria’s designation as a State Sponsor of Terrorism (SST), following a 45-day pre-notification period. This is yet another historic step by President Trump to give the Syrian people a chance at greatness. 

    Lifting sanctions on Syria will unlock international trade and investment, give Syria a chance to rebuild, and open up a new chapter for the Syrian people.  A stable, unified Syria at peace with itself and its neighbors benefits not only the region, but the entire world.

    The rescission follows President Trump’s June 30, 2025, Executive Order directing sanctions relief for Syria, the positive changes and counterterrorism actions taken by the Syrian government under President Ahmed al-Sharaa, and formal assurances provided by President al-Sharaa that Syria will not support acts of international terrorism in the future. 

    Today marks a significant milestone in the revived U.S.-Syria bilateral relationship and in Syria’s history as a nation.  We commend the government of Syria for charting a new course and look forward to enhancing our partnership with Syria and its people. 

  • Secretary Rubio Terminates Legal Status of Cuban Communist Foreign Influence Operative

    PRESS STATEMENT

    THOMAS “TOMMY” PIGOTT, SPOKESPERSON

    JULY 1, 2026

    This week, three Cuban nationals were apprehended by federal agents following Secretary Rubio’s termination of their legal status. Carlos Antonio Lloga Dominguez – who spent more than a decade working as a foreign subversive for the Communist Cuban regime’s premier influence and intelligence front group in the United States – and his wife and son are now in federal custody pending removal from our country. Lloga Dominguez spent more than a decade employed by the Cuban Institute of Friendship with the People (ICAP). He has continued to maintain ties to the transnational communist subversion network throughout his time residing in our nation.

    ICAP, which Secretary Rubio designated for sanctions under Executive Order 14404 earlier this month, is the central node in a sprawling Cuban intelligence and influence operation, claiming to span more than 2,000 organizations across more than 150 countries. The organization has a long and intimate relationship with Cuban intelligence agents; in fact, ICAP’s current president, Fernando González Llort, is a convicted Cuban spy who served 15 years in U.S. prison for his role in the infamous Wasp Network — a massive illegal Cuban spy ring uncovered in Florida in the late 1990s. Working in close coordination with the Cuban communist regime, ICAP maintains an outsized footprint across the United States, trafficking in vile anti-American propaganda, cultivating pro-Havana regime activists and politicians, and lobbying federal, state and local politicians on behalf of the Cuban dictatorship. The organization facilitates close working relationships between Havana and radical U.S. groups, using America’s far left milieu as a vehicle to export Cuba’s Communist revolution to the United States.

    Under the Trump Administration, America will never become home for Cuban Communist regime thugs who peddle propaganda, run foreign influence operations, or seek to wage revolution against American civilization. As a reminder, pursuant to Executive Order 14404, all ICAP property and interests in property are blocked and any transactions with ICAP are prohibited absent an express authorization by the Departments of Treasury or State. And any foreign aliens involved in ICAP’s anti-American subversion operations should expect to soon find themselves on an ICE deportation flight.

  • United States Targets ISIS Financial Networks Across Three Continents

    PRESS STATEMENT

    THOMAS “TOMMY” PIGOTT, SPOKESPERSON

    JUNE 22, 2026

    Under the leadership of President Trump, the United States is dismantling ISIS’s ability to finance terrorism around the world.  We are cutting off the financial lifelines from around the world that enable ISIS to fund attacks, support its regional affiliates, and threaten civilians, including religious minorities.

    Today’s designations target three individuals and six entities operating across Europe, the Middle East, and West Africa who have enabled ISIS to move money across borders – exposing a network that spans from France and Syria to Türkiye and Nigeria.

    These actions reflect the United States’ unrelenting pressure on ISIS, which continues to decentralize its operations and rely on financial intermediaries to connect its global network. Among those designated is a France-based facilitator who provided information concerning the use of explosives to ISIS supporters, a Syria-based operator who used cryptocurrency to transfer funds on behalf of ISIS associates in multiple countries including the United States, and a Nigeria-based facilitator whose money exchange businesses served as conduits for ISIS financing.

    The United States also reaffirms its strong partnership with Nigeria, which joined the United States in the May 16, 2026, operation that resulted in the killing of Abu-Bilal al-Minuki, the number two official in ISIS.

    We will continue to use every diplomatic and legal tool available to hold ISIS and its supporters accountable – wherever they operate and however they move money. We remain fully committed to protecting American lives, defending religious minorities, and working with international partners to eliminate the threat that ISIS poses to global peace and security.

    Today’s action is being taken pursuant to the counterterrorism authority, Executive Order (E.O.) 13224, as amended.  The U.S. Department of State designated ISIS, then known by its former name of al-Qa’ida in Iraq, as a Specially Designated Global Terrorist (SDGT) pursuant to E.O. 13224 on October 15, 2004, and as a Foreign Terrorist Organization pursuant to section 219 of the Immigration and Nationality Act on December 17, 2004. More information on today’s designations can be found in Treasury’s Press Releases.