Also it's their money and I don't think the US government has the right to stop them especially if there business is on the line.
Any country that enforces sanctions it has issued is likely to go after anyone found to be in violation of the sanctions, otherwise why bother issuing them in the first place?
Because even if you pay you there is no guarantee that you will be hit back again or what you will receive will be clean.
If there's no backup (or it doesn't work...), or the criminal is threatening to release the information publicly in their unencrypted form, there's enough of an incentive to pay if the encrypted data hold any value.