The Joe Biden administration on Thursday will announce plans to bar the sale of Kaspersky Lab’s antivirus software in the US, a person familiar with the matter said, citing the firm’s large US customers including critical infrastructure providers and state and local governments.
The company’s close ties to the Russian government were found to pose a critical risk, the person said, adding that the software’s privileged access to a computer’s systems could allow it to steal sensitive information from American computers, install malware or withhold critical updates.
The sweeping new rule, using broad powers created by the Donald Trump administration, will be coupled with another move to add the company to a trade restriction list, according to two other people familiar with the matter, dealing a blow to the firm’s reputation that could hammer its overseas sales.
The plan to add the cybersecurity company to the Entity List, which effectively bars a company’s US suppliers from selling to it, and the timing and details of the software sales curb, have not been previously reported.
A spokesman for the US commerce department declined to comment, while Kaspersky Lab and the Russian embassy in the US did not respond to requests for comment. Previously, Kaspersky has said that it is a privately managed company with no ties to the Russian government.
The moves show the administration is trying to stamp out any risks of Russian cyberattacks stemming from Kaspersky software and keep squeezing Moscow as its war effort in Ukraine has regained momentum and as the US has run low on fresh sanctions it can impose on Russia.
It also shows the Biden administration harnessing a powerful new authority that allows it to ban or restrict transactions between US firms and internet, telecommunications and tech companies from “foreign adversary” nations like Russia and China.
The tools are largely untested.
Trump bans
Former President Trump used them to try to bar Americans from using Chinese social media platforms TikTok and WeChat, but federal courts halted the moves.
The new restrictions on inbound sales of Kaspersky software, which will also bar downloads of software updates, resales and licensing of the product, kick in on 29 September, 100 days after publication, to give businesses time to find alternatives. New US business for Kaspersky will be blocked 30 days after the restrictions are announced.
It is less clear what impact the entity listing will have on Kaspersky, whose Russian business is already subject to sweeping US export restrictions over Ukraine which make it almost impossible for any US-made items other than food or medical equipment to reach Russia.
If the commerce department adds foreign units of Kaspersky to the Entity List that purchase significant inputs from the US, the move could crimp its supply chain. If it only adds the Russian entity, the impact will be largely reputational. Kaspersky has long been in regulators’ crosshairs. In 2017, the US department of homeland security banned its flagship antivirus product from federal networks, alleging ties to Russian intelligence and noting Russian law lets intelligence agencies compel assistance from Kaspersky and intercept communications using Russian networks.
Pressure on the company’s US business grew after Moscow’s move against Kyiv; the US government privately warned some American companies the day after Russia invaded Ukraine in February 2022 that Moscow could manipulate software designed by Kaspersky to cause harm.
The war also prompted the commerce department to ramp up the national security probe into the software that resulted in Thursday’s action.
Kaspersky, which has a UK holding company and operations in Massachusetts, said in a corporate profile that it generated revenue of US$752-million in 2022 from more than 220 000 corporate clients in some 200 countries. Its website lists Italian vehicle maker Piaggio, Volkswagen’s retail division in Spain and the Qatar Olympic Committee among its customers. — Alexandra Alper, with Christopher Bing, Raphael Satter and Karen Freifeld, (c) 2024 Reuters