ATLAS/BRIEFINGLaw, organized for consequential decisions.

PRIV-08 Privacy, Cyber & AI Security Program Operations Federal

Ransomware: Response Decisions and the Legality of Paying

Paying a ransom is a legal decision before it is a business one. This brief sets out the sanctions analysis, the reporting expectations, and the obligations that continue whether or not payment is made.

Technical diagram marking this brief's subject

Briefing in 60 seconds

  1. OFAC has warned that facilitating a ransom payment to a sanctioned actor risks strict-liability sanctions exposure, meaning intent and knowledge are not defenses.
  2. Timely and complete reporting to law enforcement, and cooperation with it, are treated by OFAC as significant mitigating factors in any enforcement analysis.
  3. CISA urges reporting a ransomware incident regardless of whether the organization pays, and separate federal reporting duties take effect through implementing rules.
  4. A payment ends nothing: breach notification, regulatory reporting, contractual notice, and preservation duties all run on their own clocks either way.

Controlling variables

Status
Whether the organization is a government body, a critical-infrastructure entity, a regulated health or financial institution, or a public company, each adding separate reporting duties.
Facts
Whether data was exfiltrated as well as encrypted, since a pure availability event and a data-theft extortion event trigger different notification analyses.
Jurisdiction
Whether a state bars public entities from paying, and which state residents are affected, because notification duties follow the individual rather than the company.
Timing
Whether the payment decision is made before sanctions screening and counsel review are complete, which is what converts a business choice into legal exposure.
Contract terms
Whether the cyber policy conditions extortion coverage on carrier consent and screening, and whether customer agreements impose notice windows measured in hours.

General legal information about United States law. Not legal advice, not representation, and no attorney–client relationship is created by reading it. Rules differ by jurisdiction and change — verify against the official sources listed below.

There is no general federal statute making it a crime to pay a ransom. What exists is narrower and sharper: U.S. sanctions law prohibits transactions with designated persons and blocked jurisdictions, and the Treasury Department's Office of Foreign Assets Control has warned publicly that facilitating a ransomware payment to a sanctioned actor risks sanctions exposure. That exposure is strict liability — a U.S. person can be liable without knowing the recipient was designated.

So the question is never simply "may we pay." It is who the counterparty is, what screening was done before funds moved, what was reported and when, and what obligations continue afterward.

The sanctions analysis, in the order it happens

The advisory framework from OFAC reaches more than the victim. It reaches the parties that make payment possible — incident response firms, negotiators, digital-asset exchanges, insurers, and financial institutions — because facilitation is itself a prohibited activity. Every one of those actors runs its own screening, and any of them can stop the transaction, which is one reason payment decisions cannot be made quickly no matter how the demand is framed.

Screening in this setting is inference, not lookup. Ransomware crews rebrand, split, and reuse infrastructure, so the name on the ransom note frequently does not appear on any list. The analysis turns on wallet addresses, tooling, negotiation-channel patterns, and the attribution work the response firm can support. A defensible file records what was checked, by whom, against what sources, and what the conclusion was — including honest uncertainty.

OFAC has also been explicit about mitigation. Timely and complete reporting of the attack to law enforcement, and full cooperation with it during and after the incident, are treated as significant mitigating factors, as is a demonstrated meaningful effort to reduce the risk of attack through improved cybersecurity. Those factors are not a license to pay. They are the difference between an enforcement matter and a much worse one if the counterparty turns out to be designated.

Sequence discipline: screening, counsel review, and carrier consent all precede any transfer. A payment made over a weekend to beat a deadline set by the attacker is the fact pattern that removes every mitigating factor at once.

What to report, and to whom

CISA's ransomware resources urge victims to report incidents whether or not they intend to pay, and to report before paying where possible. Reporting is not the same as notification: telling a federal agency does not discharge a state breach-notification duty, does not pause any statutory clock by itself, and does not create privilege over the investigation.

Reporting and notification tracks that can run simultaneously
TrackWho it applies toWhat drives the timing
Federal incident reportingAny victim, voluntarily; and, for designated critical-infrastructure entities, on a mandatory basis under federal law implemented through CISA rulemaking.The mandatory duties, including a separate and shorter clock for reporting a ransom payment, take effect through the implementing rule. Confirm current status directly with the agency.
Law enforcementAny victim.No deadline, but earlier contact is what OFAC's mitigation framework rewards and what preserves investigative options.
Financial-crime reportingInstitutions and intermediaries that process or facilitate payments.Suspicious-activity obligations attach to the facilitator rather than the victim, but they shape what an exchange or bank will do.
State breach notificationAnyone holding covered personal information about residents of that state.Runs from discovery under most statutes, independent of the payment decision and independent of whether data was recovered.
Sector regulatorsHealth, financial, insurance, utility, and defense-adjacent organizations.Regime-specific clocks. Health entities should work from the framework at HHS.
Contractual noticeAny organization holding another party's data.Set by agreement, commonly 24 to 72 hours, and often the shortest clock in the incident.

Public entities face an additional rule in some states. A number of states, including North Carolina and Florida, bar state agencies and local governments from paying ransoms and require reporting instead. Those statutes remove the decision entirely for covered bodies and their contractors, so the first question for a government-adjacent victim is whether payment is lawful at all rather than whether it is wise. The parallel notification mechanics for any victim are set out in data-breach response, privilege, and notification.

Working the decision

  1. Establish the facts that matter

    Two questions decide the shape of the event: is the data recoverable from backups that the attacker did not reach, and was data exfiltrated as well as encrypted. Extortion of stolen data is a disclosure problem that payment does not solve, because there is no way to verify deletion.

  2. Stand up the structure

    Counsel directs the forensic engagement so the work sits inside a privileged investigation. Notify the carrier and request consent to counsel, forensics, and any negotiator, since extortion coverage is usually conditioned on it.

  3. Preserve before you rebuild

    Image affected systems and suspend routine log deletion. A litigation hold issues as soon as litigation or investigation is reasonably anticipated, and rebuilding a server without imaging it first creates a spoliation problem stacked on top of the intrusion.

  4. Screen the counterparty

    Run sanctions and attribution analysis with the response firm before any negotiation position is taken. Record the sources checked and the conclusion, including what could not be determined.

  5. Price the alternative honestly

    Compare the demand against the real cost and time of restoration, tested against actual recovery rates rather than backup policy documents. Decryptors supplied by attackers are frequently slow, partial, or corrupt.

  6. Decide at the right level, and write it down

    Whoever holds the authority — normally the board or a designated executive — records the basis: what was known, what was screened, what alternatives were weighed, what the carrier consented to. That memorandum is the primary evidence if the decision is later questioned.

Free decryption tools exist for some strains, and checking before negotiating is basic diligence; the resources at CISA are the standard starting point. It is also worth stating plainly what payment does not buy: no assurance of a working decryptor, no verifiable deletion of stolen data, no protection against a second demand from the same or an affiliated crew, and no reduction in any notification obligation.

What survives the decision either way

  • Notification duties are unaffected. Recovering files does not undo unauthorized access. If personal information was accessed or acquired, the state statutes apply on their own terms and their own clocks.
  • Exfiltration claims resurface. Data promised to be deleted appears on leak sites months later. Assume publication when assessing risk of harm, and say so in the internal record rather than relying on the attacker's assurance.
  • Regulators ask about controls, not just the incident. Multifactor authentication on remote access, segmentation, and offline backups are the first three questions in nearly every inquiry, and the same answers drive whether a cyber carrier pays, as covered in cyber insurance coverage disputes.
  • Vendor incidents shift the roles, not the duties. When the encrypted systems belong to a processor, the contract decides who investigates, who notifies, and who pays — allocation terms discussed in contracting with AI vendors.
  • Statements made in week one are quoted in year two. Early public assurances that no data was taken are the most commonly regretted sentences in ransomware response.
  • The payment record is discoverable. Transfer instructions, negotiation transcripts, and the decision memorandum will be read by someone else. Write them for that reader.

Questions the desk gets

Is paying a ransom illegal?

Not as a general matter under federal law. The prohibition is transacting with a sanctioned person or blocked jurisdiction, and that prohibition operates on a strict-liability basis, so a good-faith belief about who the attacker was does not by itself resolve exposure. Some states separately bar payments by public bodies. The correct framing is that payment is lawful only after screening supports it and only if no other prohibition applies.

If we report to CISA and the FBI, are we protected?

Reporting improves your position without immunizing the decision. OFAC treats timely, complete reporting and cooperation as meaningful mitigating factors, and law enforcement occasionally holds decryption keys or attribution that changes the analysis. But reporting does not authorize a prohibited transaction, does not satisfy state notification duties, and does not create privilege. Report early and treat it as one workstream among several.

Can we pay through a third party so the payment is not ours?

No. Facilitation is itself covered, which is why response firms, negotiators, exchanges, and insurers run independent screening and will refuse a transaction they cannot clear. Routing payment to obscure the counterparty makes the position worse, not better, and it destroys the mitigating factors that would otherwise apply.

The attacker gave us a deadline. Does that change the analysis?

It changes the pressure, not the law. Deadlines and escalating demands are negotiation tools, and they are frequently extended. The one thing an artificial deadline reliably produces is a payment made before screening, carrier consent, and counsel review are complete — which is the single worst version of this decision.

Do we have to tell customers even if we restored from backups?

Possibly, and the answer does not depend on restoration. Notification turns on whether personal information was accessed or acquired without authorization, which is a forensic question about the intrusion, not about the outcome. Where logging is insufficient to rule out access, many statutes push toward notice, and the FTC's guidance reflects the same expectation of candor.

Decisions that cannot wait

Three things should be settled before an incident, because none of them can be built during one. Who holds payment authority and whether the board must approve. Which counsel and which response firm are pre-engaged, so counsel can direct the work from hour one. And whether backups are genuinely offline or immutable and have been restored in a test within the last year — the single fact that most often removes the payment question entirely.

During an incident, hold the sequence: preserve, screen, consult the carrier, decide, document. Afterward, expect the controls conversation, not the ransom conversation, to dominate regulator and insurer attention, and expect retention practices to be examined closely because they determine what evidence exists at all — the discipline is set out in data retention schedules and deletion obligations. Related material sits on the Privacy, Cyber & AI desk.

Sources

  1. U.S. Department of the Treasury — Office of Foreign Assets Control
  2. CISA — StopRansomware
  3. Cybersecurity and Infrastructure Security Agency
  4. U.S. Department of Health and Human Services — HIPAA for Professionals
  5. Federal Trade Commission — Privacy and Security business guidance

Atlas Research Desk

ATLAS briefs are researched and edited by the Research Desk, an editorial organization — not attorneys acting for you. Method and limits: editorial method · source standards · corrections.