Ransomware Payment
A ransomware payment is money handed over to attackers who have used malicious software (ransomware) to lock a victim out of their own data or devices until a ransom is paid. Victims sometimes pay in the hope of regaining access to their systems or preventing the release of stolen data. Making such a payment can raise legal and compliance concerns, particularly where the recipient may be a sanctioned person.
A ransomware payment is the transfer of value, frequently demanded in cryptocurrency, made by or on behalf of a victim to threat actors deploying ransomware, malware that restricts access to files, systems, or data until a demand is met. From a compliance perspective, such payments carry significant financial crime exposure: in the United States, paying a ransom is not inherently unlawful, but making a payment to a sanctioned person or entity may be prohibited, and the anonymity of many attackers complicates identifying the ultimate recipient. Whether a given payment is permissible, and what reporting or due diligence obligations attach, depends on the applicable sanctions and AML frameworks in the relevant jurisdiction, which should be confirmed against the specific regulations in force; the descriptions here reflect general characterizations from the cited evidence rather than an exhaustive legal test.
Why it matters
Ransomware payments sit at the intersection of cybersecurity incident response and financial crime compliance, and they create acute exposure for the victims, insurers, incident-response firms, and financial institutions that may facilitate them. Ransomware itself is malware that holds a victim's data and devices hostage until a ransom is paid, and the payment is frequently demanded in cryptocurrency. The core compliance concern is that, while paying a ransom is not inherently unlawful in some jurisdictions such as the United States, making a payment to a sanctioned person or entity may be prohibited. Because many attackers operate anonymously, identifying the ultimate recipient can be difficult or effectively impossible, which complicates any assessment of whether a payment would breach applicable sanctions.
Who it's relevant to
Inside Ransomware Payment
Common questions
Answers to the questions practitioners most commonly ask about Ransomware Payment.