Skip to main content
Category: Incident Response & Reporting

Ransom Payment Reporting

Also known as: Ransomware Payment Reporting, Ransomware and Cyber Extortion Payment Reporting
Simply put

Ransom payment reporting refers to the practice or obligation of notifying government authorities when an organization makes or receives a demand for a ransom payment in connection with a ransomware or cyber extortion incident. In the United States, the government generally encourages victims to report ransomware incidents to bodies such as the FBI and CISA, and some jurisdictions impose formal reporting duties on certain entities. The specific obligations, deadlines, and covered entities vary by jurisdiction and should be confirmed against current official sources.

Formal definition

Ransom payment reporting encompasses the voluntary or mandatory disclosure to government authorities of information concerning a ransom payment, generally defined as the transmission of money, property, or assets delivered as ransom in connection with a ransomware or cyber extortion attack. In the U.S., CISA advises that every ransomware incident be reported to the U.S. government (for example, to the FBI or CISA), and mandatory reporting obligations for ransom payments by covered critical-infrastructure entities are established by statute but depend on the effective date of the applicable implementing rule, which the reader should verify against current authoritative text. Reporting regimes differ across jurisdictions: for example, certain reporting business entities in Australia have a statutory obligation under the Cyber Security Act 2024 to report ransomware or cyber extortion payments to the government. This entry does not cover the specific covered-entity criteria, reporting deadlines, submission mechanisms, or contractual and legal specifics of any particular regime, all of which must be confirmed against the governing statute, rule, or agency guidance in the relevant jurisdiction.

Why it matters

Ransomware and cyber extortion have become among the most disruptive threats facing both public and private organizations, and governments increasingly treat visibility into ransom demands and payments as essential to disrupting the criminal ecosystem behind them. Reporting a ransomware incident, including any ransom demand or payment, gives law enforcement bodies such as the FBI and CISA information that may help identify threat actors, warn other potential victims, and limit further damage. CISA advises that every ransomware incident be reported to the U.S. government, reflecting the view that even unsuccessful or unpaid attacks carry intelligence value.

For compliance officers and security managers, ransom payment reporting is not merely encouraged as good practice; it is increasingly a matter of legal obligation whose specifics depend on jurisdiction and the effective date of the governing rule. Whether a given reporting duty applies, to which entities, and on what timeline are questions that turn on statute and implementing regulation rather than on general guidance. Because the covered-entity criteria and deadlines vary and are subject to change, organizations should not assume that voluntary reporting to the FBI or CISA satisfies every applicable statutory obligation, nor that a single report discharges duties across multiple jurisdictions.

Who it's relevant to

Compliance officers and information system security managers
These practitioners must determine whether their organization qualifies as a covered or reporting entity under an applicable ransom-payment reporting regime, track effective dates of implementing rules, and build internal processes so that a ransom demand or payment triggers timely notification. Because obligations and deadlines vary by jurisdiction and are subject to change, they should confirm current requirements against the governing statute or agency guidance rather than relying on general encouragement to report.
Incident response teams and leadership
Teams managing an active ransomware or cyber extortion event need to integrate reporting steps into their response playbooks, including reporting incidents to bodies such as the FBI or CISA. Reporting even unsuccessful or unpaid attacks can support law enforcement efforts and help warn other potential victims, so response plans should account for notification independent of whether a payment is ultimately made.
Government contractors and critical-infrastructure operators
Organizations that may fall within covered-entity definitions under critical-infrastructure reporting statutes should assess whether ransom-payment reporting duties apply to them and on what timeline once the relevant implementing rule takes effect. The specific covered-entity criteria and deadlines must be verified against current authoritative text and should not be assumed from voluntary reporting guidance alone.
Multinational and cross-border organizations
Entities operating across jurisdictions must reconcile differing reporting regimes, such as the U.S. approach centered on the FBI and CISA and Australia's statutory obligation under section 27 of the Cyber Security Act 2024. A single report in one jurisdiction may not satisfy obligations in another, so these organizations should confirm each applicable regime's covered entities, deadlines, and submission mechanisms separately.

Inside Ransom Payment Reporting

Ransom Payment Reporting (concept)
The obligation or practice of disclosing to a designated authority that an entity has made a payment in response to a ransomware attack. Reporting requirements, timelines, and recipients vary by legal authority and by the sector and status of the reporting entity; readers should confirm which specific mandate applies to their organization against current official sources.
CIRCIA ransom payment reporting requirement
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), codified at 6 U.S.C. 681b, directs the reporting of ransom payments by covered critical-infrastructure entities to CISA. The statute contemplates reporting of a ransom payment within 24 hours of the payment being made. The detailed scope, definitions of covered entities, and effective enforcement generally depend on CISA's implementing final rule; practitioners should verify the current status and text of that rulemaking.
Reporting recipient
Under CIRCIA, the designated federal recipient for covered entity ransom payment reports is CISA. Other frameworks, contracts, or agency-specific requirements may direct additional or separate notifications; the appropriate recipient depends on the governing authority applicable to the entity.
Covered entity scope
CIRCIA's ransom payment reporting obligation applies to covered entities in critical infrastructure sectors as defined by the statute and CISA's implementing rule. Whether a given organization qualifies as a covered entity is determined by that rule; state, local, tribal, and territorial or sector-specific obligations may differ.
Reporting timeline
CIRCIA contemplates a 24-hour window for reporting a ransom payment after it is made. Timelines under other contractual, regulatory, or agency-specific regimes may differ and should be confirmed against the applicable authoritative text.
Relationship to sanctions considerations
Ransom payment reporting is distinct from the legal question of whether making a payment is permissible. Making a payment to certain sanctioned entities may carry separate legal exposure, which is out of scope for a reporting definition and should be confirmed with counsel and current OFAC guidance.

Common questions

Answers to the questions practitioners most commonly ask about Ransom Payment Reporting.

Does the United States have no statutory requirement to report ransom payments?
That is a common misconception. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) directs covered critical-infrastructure entities to report ransom payments to CISA, generally within 24 hours of making the payment, under the statute's implementing rulemaking. Because these obligations take effect through CISA's final rule and depend on how a covered entity is defined, readers should verify the current effective date, applicability, and reporting mechanics against the authoritative CIRCIA text and CISA guidance rather than assume no mandate exists.
If I report a ransom payment, does that mean the payment itself is legally cleared?
No. Reporting an incident or a ransom payment is distinct from establishing that the payment is lawful. Reporting obligations and the legality of a given payment arise from separate authorities and considerations, and satisfying a reporting requirement does not by itself resolve sanctions, contractual, or other legal exposure. Confirm the specific legal and regulatory implications of any payment with qualified counsel and against current official sources.
Who within our organization is responsible for determining whether a reporting obligation applies?
Applicability generally depends on whether your organization meets the definition of a covered entity and whether the triggering event falls within the reporting scope, which can involve incident response, legal, compliance, and information system security roles. Because these definitions and thresholds are set by the governing rule and may be tailored, coordinate across those functions and confirm the current criteria in the authoritative text before concluding whether an obligation applies.
What is the general timeframe for reporting a ransom payment?
Under CIRCIA, covered entities are generally expected to report a ransom payment to CISA within 24 hours of making it once the applicable rule is in effect. The precise clock, starting point, and any exceptions are established by the implementing regulation, so verify the exact timing requirement and how it is measured against the current authoritative text.
How does ransom-payment reporting relate to broader cyber incident reporting obligations?
Ransom-payment reporting and cyber incident reporting are related but distinct obligations that may arise under the same or different authorities, with their own triggers and timelines. In most implementations an organization should track both separately so that one report does not substitute for another. Confirm which specific reports are required, to whom, and by when under the applicable governing rule.
What information should we be prepared to provide when reporting a payment?
Organizations generally benefit from preparing details about the incident, the demand, and the payment in advance, but the specific data elements required are defined by the governing rule and any agency-issued guidance. Because required fields can change across revisions, build your reporting process around the current authoritative requirements and verify the exact content elements before submission.

Common misconceptions

There is no U.S. statutory mandate requiring the reporting of ransom payments.
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), codified at 6 U.S.C. 681b, establishes a requirement for covered critical-infrastructure entities to report ransom payments to CISA, with the statute contemplating reporting within 24 hours of the payment. The precise scope and enforcement generally depend on CISA's implementing final rule, which readers should verify against current official sources.
Reporting a ransom payment is the same as being authorized to make one.
Reporting and legality are distinct. Satisfying a reporting obligation does not resolve whether the payment itself was lawful, particularly where sanctioned parties may be involved. Those legal questions are separate and should be confirmed with counsel and current authoritative guidance.
Any organization that suffers a ransomware attack is automatically obligated to report a ransom payment under CIRCIA.
CIRCIA's obligation applies to covered entities in critical infrastructure as defined by the statute and CISA's implementing rule. Whether a specific organization is in scope depends on that rule, and other frameworks or state, local, tribal, and territorial requirements may impose different obligations.

Best practices

Determine whether your organization qualifies as a CIRCIA covered entity by checking the statute (6 U.S.C. 681b) and the current status and text of CISA's implementing final rule before relying on any assumption about applicability.
Build internal procedures capable of meeting a 24-hour reporting window for ransom payments, since CIRCIA contemplates reporting to CISA within that timeframe once a payment is made.
Confirm the correct reporting recipient and any additional notification obligations, recognizing that CISA is the designated recipient under CIRCIA while other contractual or agency-specific regimes may require separate notifications.
Treat the legality of a payment as a separate analysis from the reporting obligation, and involve legal counsel to address potential sanctions exposure before making any payment.
Verify reporting timelines, definitions, and thresholds against current authoritative sources, as scope and effective enforcement generally depend on rulemaking that may change.
Maintain documentation of any ransom payment and related decisions to support timely and accurate reporting to the appropriate authority.