This year alone, almost 100 Australian organisations have found themselves the victim of a ransomware attack – and that’s just the ones we know have been listed on a darknet leak site.
And all of them, and likely many more, have had to face one driving question: Should they pay a ransom to protect their data – and their customers – from exposure to the cybercriminal ecosystem?
For Phoebe Chester, Practice Leader at commercial law firm LegalVision, the answer – and the law – is clear.
“Paying a cyber ransom is a high-risk and potentially illegal decision that Australian businesses should aim to avoid at all costs. Under Australian law, paying a sanctioned hacker is illegal, and businesses cannot plead ignorance,” Chester (pictured) said.
“If the ransom goes to a sanctioned group, your company faces severe penalties, and the payment can also trigger federal money-laundering offences.”
Thousands of individuals and organisations are currently sanctioned by the Australian government. For instance, many Iranians with links to the Iranian Revolutionary Guard Corps, which itself is linked to many hacktivist and cybercriminal groups, are on Australia’s Consolidated List of sanctioned entities.
If a ransom payment is found to have ended up in the hands of the IRGC… Similarly, some hacking groups, such as LockBit, are on the sanctions list as well.
But, sanctions aside, the advice remains the same: don’t pay.
“The Australian Signals Directorate's advice is clear: businesses should never pay. Paying a ransom guarantees nothing about the safety of your data, but it does fund criminal syndicates and can mark your business as an easy target,” Chester said.
“The best defence is a combination of robust cybersecurity to prevent the breach, and strong, tested backups so you are never forced to negotiate with criminals simply to keep your business running.”
The first 24 hours: Dos and Don’ts
According to Chester, that first full day in the wake of a ransomware attack should be focused on preserving evidence, managing risk, and careful communications.
“The business should isolate affected systems, but your team should not wipe machines or destroy data in an attempt to restore operations, as preserving the forensic trail is critical for future regulatory investigations or third-party claims,” Chester said.
“Do not authorise anyone to contact the attackers or discuss payment, as engaging with threat actors without expert legal or crisis-management oversight risks breaching strict-liability sanctions or federal money-laundering laws.”
IT experts and legal counsel should be consulted in order to determine the next steps, cyber insurers should be informed, and the incident itself reported to the Australian Cyber Security Hotline.
Organisations should also avoid making premature public statements or notifying customers while the facts are still emerging, as this could result in regulatory action.
“Concurrently, your legal team should begin assessing the nature of the compromised information to determine your mandatory reporting obligations under the Privacy Act and, if applicable, your continuous disclosure obligations to the market,” Chester said.
What happens if I don’t pay, and the data is leaked?
There is no direct legal penalty for not paying a ransom, whereas payment may run afoul of money laundering laws as well as sanctions.
“The legal risks weigh heavily against making a payment. Refusing to pay does not alter your regulatory burden. Your obligations under the Privacy Act to assess the breach, notify the regulator and notify affected individuals apply regardless of whether you pay,” Chester said.
“Reputational risk is high for both paths, but Australian public and regulatory sentiment has hardened since major public breaches like those at Optus and Medibank. Customers increasingly judge organisations on how transparently, competently and quickly they respond, not on whether they capitulated to criminals.”
In addition, legal consequences for a data breach can remain even if an organisation pays a ransom, particularly if that entity failed to take “reasonable steps” to prevent the incident in the first place. Similar penalties can apply if an organisation fails to assess a suspected breach within 30 days, and if it fails to notify the Office of the Australian Information Commissioner.
“Refusing to pay a ransom does not absolve a business of these duties,” Chester said.
“Where these failures amount to a serious interference with privacy, maximum penalties can reach $50 million, three times the value of any benefit obtained, or 30 per cent of the company's adjusted turnover.”
The biggest mistake
It’s easy to think that a ransomware attack or other cyber incident is an IT problem, but as far as Chester is concerned, focusing on quietly resolving the issue without acknowledging the legal and regulatory requirements is arguably the gravest mistake any organisation can make.
“The second common error is downplaying the breach publicly before the facts are in, then having to walk it back,” Chester said.
“Directors should also note that a mishandled response can attract regulatory and shareholder scrutiny over whether they exercised proper oversight and complied with their statutory duties. To mitigate this, boards should document their decisions and involve legal counsel early.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.