Ransom Payment Reporting
Ransom payment reporting refers to the practice or obligation of notifying government authorities when an organization makes or receives a demand for a ransom payment in connection with a ransomware or cyber extortion incident. In the United States, the government generally encourages victims to report ransomware incidents to bodies such as the FBI and CISA, and some jurisdictions impose formal reporting duties on certain entities. The specific obligations, deadlines, and covered entities vary by jurisdiction and should be confirmed against current official sources.
Ransom payment reporting encompasses the voluntary or mandatory disclosure to government authorities of information concerning a ransom payment, generally defined as the transmission of money, property, or assets delivered as ransom in connection with a ransomware or cyber extortion attack. In the U.S., CISA advises that every ransomware incident be reported to the U.S. government (for example, to the FBI or CISA), and mandatory reporting obligations for ransom payments by covered critical-infrastructure entities are established by statute but depend on the effective date of the applicable implementing rule, which the reader should verify against current authoritative text. Reporting regimes differ across jurisdictions: for example, certain reporting business entities in Australia have a statutory obligation under the Cyber Security Act 2024 to report ransomware or cyber extortion payments to the government. This entry does not cover the specific covered-entity criteria, reporting deadlines, submission mechanisms, or contractual and legal specifics of any particular regime, all of which must be confirmed against the governing statute, rule, or agency guidance in the relevant jurisdiction.
Why it matters
Ransomware and cyber extortion have become among the most disruptive threats facing both public and private organizations, and governments increasingly treat visibility into ransom demands and payments as essential to disrupting the criminal ecosystem behind them. Reporting a ransomware incident, including any ransom demand or payment, gives law enforcement bodies such as the FBI and CISA information that may help identify threat actors, warn other potential victims, and limit further damage. CISA advises that every ransomware incident be reported to the U.S. government, reflecting the view that even unsuccessful or unpaid attacks carry intelligence value.
For compliance officers and security managers, ransom payment reporting is not merely encouraged as good practice; it is increasingly a matter of legal obligation whose specifics depend on jurisdiction and the effective date of the governing rule. Whether a given reporting duty applies, to which entities, and on what timeline are questions that turn on statute and implementing regulation rather than on general guidance. Because the covered-entity criteria and deadlines vary and are subject to change, organizations should not assume that voluntary reporting to the FBI or CISA satisfies every applicable statutory obligation, nor that a single report discharges duties across multiple jurisdictions.
Who it's relevant to
Inside Ransom Payment Reporting
Common questions
Answers to the questions practitioners most commonly ask about Ransom Payment Reporting.