Mandatory Ransom Payment Disclosure for Cyberattacks
New rules require businesses and local governments to report ransom payments after cyberattacks. This aims to combat digital crime and enhance data security, though it does not apply to individuals. Information on payments will be collected and analyzed to better protect IT systems.
Key points
Businesses and local governments must report ransom payments for cyberattacks within 48 hours to the Department of Homeland Security.
Disclosures must include the date, amount of ransom, currency type (including cryptocurrency), and any known information about the attacker.
The Department of Homeland Security will publish aggregated data on ransom payments, without revealing the identity of the affected entities.
The regulations aim to better understand and combat cybercrime, as well as protect information systems.
Individuals can voluntarily report ransom payments on a dedicated website.
Expired
Additional Information
Print number: 117_S_2943
Sponsor: Sen. Warren, Elizabeth [D-MA]
Process start date: 2021-10-06