Just to be clear, OFAC does not give a list of “banned strings”. It provides a list if individuals and entities that it is illegal to transact with. By which I mean, it’s the entity that matters, not just the raw string.
It’s up to the payment processor to have a process that ensures they don’t send payments to a blocked entity.
You can search for them here: https://home.treasury.gov/policy-issues/office-of-foreign-as... and see the listing for the company in this notice: https://home.treasury.gov/policy-issues/financial-sanctions/...
Note that the standard practice for handling an OFAC hit (e.g. payment to O Bin Laden) is to disambiguate your payee from the blocked individual/entity. This can be easy or difficult depending on how much info you have on the payee; if you have an address and nationality already that don’t match the sanctioned entity then you’re generally ok; typically you would collect a photo of the payee’s ID and run a manual check if there was any doubt.
These “enhanced due diligence” processes can be quite time consuming in aggregate, and I’m not surprised that PayPal isn’t running a detailed EDD process on transactions that will probably net it a few cents of fees.
Having said that, given the structure of their business (online checkout) I’m surprised that they are considering the product (eg “tardigrade”) as being relevant; they have account info on both the payor and payee so they know the payment isn’t going to the sanctioned Cypress company from the OFAC list. This isn’t a Venmo payment that says “pass this payment on to Tardigrade Inc”, which you would want to block.
This seems like either a bug in their screening code or some very risk-averse logic (maybe to do with low-value transactions).