and law enforcement to regulate, supervise, investigate, and take action against virtual asset exploitation with appropriate protections for privacy, and recognizing that specific actions may vary based on domestic contexts. We will also seek out ways to cooperate with the virtual asset industry to enhance ransomware-related information sharing. Disruption and other Law Enforcement Efforts Beyond implementing measures to improve resilience and harden our financial system from exploitation, we must also act to degrade and hold accountable ransomware criminal operators. Ransomware criminal activity is often transnational in nature, and requires timely and consistent collaboration across law enforcement, national security authorities, cybersecurity agencies, and financial intelligence units. Such collaboration must be consistent with domestic legal requirements, and may be pursued alongside diplomatic engagement so that malicious activity can be identified and addressed, and the actors responsible can be investigated and prosecuted. Together, we must take appropriate steps to counter cybercriminal activity emanating from within our own territory and impress urgency on others to do the same in order to eliminate safe havens for the operators who conduct such disruptive and destabilizing operations. We intend to cooperate with each other and with other international partners to enhance the exchange of information and provide requested assistance where able to combat ransomware activity leveraging infrastructure and financial institutions within our territories. We will consider all national tools available in taking action against those responsible for ransomware operations threatening critical infrastructure and public safety. Diplomacy In addition to disruption of the ransomware ecosystem, diplomatic efforts can promote rules-based behavior and encourage states to take reasonable steps to address ransomware operations emanating from within their territory. We will leverage diplomacy through coordination of action in response to states whenever they do not address the activities of cybercriminals. Such collaboration will be a critical component to meaningfully reduce safe havens for ransomware actors. Noting that law enforcement and cybersecurity capacity can be significant limiting factors in a state’s ability to address cybercrime, diplomacy in the form of coordinated capacity building has potential to serve as a force multiplier in the fight against ransomware. We will share approaches to capacity building, highlight resources and programs that are available, and take steps to coordinate such work when appropriate to ensure capacity building complements other actions to minimize the ransomware threat. 3

Select target paragraph3