In most countries it is not illegal for a private company to pay a ransomware demand, but it can become illegal the moment the money reaches a sanctioned group, and in 2026 that risk is the one that matters. The United States has no federal ban but treats sanctions breaches as strict liability. The United Kingdom is legislating to ban public bodies and critical infrastructure operators from paying. Australia lets you pay but makes you report it within 72 hours. The European Union requires incident reporting and bans nothing. This piece sets out each rule as it stands, what is still only proposed, and what paying legally still does not get you.
This is reporting on the law, not legal advice. The rules below change quickly and vary by sector; anyone facing a live demand should involve counsel who knows the jurisdiction, and should do so before the first message to the attackers, not after.
Is paying ransomware illegal in the United States?
No federal law prohibits a private organisation from paying a ransom. What the law prohibits is paying anyone on a sanctions list, and the Treasury’s Office of Foreign Assets Control has been explicit since 2020 that ransomware payments are covered. Its October 2020 advisory, updated in September 2021, warns that a payment to a sanctioned person or group violates US sanctions law on a strict-liability basis: it does not matter whether the victim knew who was on the other end. Several ransomware operators and their infrastructure have been designated over the years, and the list grows, which is why the first question in any serious negotiation is now attribution.
OFAC also set out what it treats as mitigating: a documented compliance programme, prompt reporting to law enforcement, and cooperation during and after the incident. Reporting to the FBI does not make a payment legal, but it changes how a violation is handled. The same 2021 update reminded the intermediaries, the negotiators, insurers and cryptocurrency exchanges who move the money, that they carry the same exposure as the victim.
Below the federal level, two states have gone further for their own public bodies. North Carolina became the first state to prohibit state and local government entities from paying, or even communicating with an attacker about payment, under a law passed in 2021. Florida followed in 2022, banning state agencies, counties and municipalities from paying. Both laws bind public entities only; a private company in Charlotte or Miami can still pay. Other states have debated similar measures without passing them.
Is paying ransomware illegal in the United Kingdom?
Not yet for anyone, and soon for some. On 22 July 2025 the government confirmed it would legislate a targeted ban on ransom payments by public sector bodies, including local government, and by operators of critical national infrastructure. As of February 2026 that ban remained a proposal being developed with industry rather than an enacted law, and it is separate from the Cyber Security and Resilience Bill, which deals with supply-chain and reporting duties more broadly. Suppliers to the public sector are explicitly outside the current draft of the ban, though the government has said supply-chain risk remains under consideration.
Two companion measures sit alongside it. A payment prevention regime would require any organisation outside the ban to notify the government through a central mechanism before paying, so that officials can warn the victim if the recipient is sanctioned and, in that case, block the payment. And a mandatory reporting duty would require organisations to report ransomware incidents whether or not they intend to pay, with a 72-hour initial deadline under consideration and the threshold for who must report still to be set. In the consultation, 63% of respondents backed mandatory reporting and 47% backed the prevention regime.
What already applies today is sanctions law. Paying a group or individual designated under UK sanctions regulations is a criminal offence, and the UK has designated Russian-based ransomware actors alongside its allies. So the practical position for a British company in 2026 is the same as the American one: legal in principle, criminal if the attacker is on the list, and about to be prohibited outright if you are a hospital trust, a council or a water company.
Is paying ransomware illegal in Australia?
No, but since 30 May 2025 you have to tell the government you did it. Under the Cyber Security Act 2024, any entity carrying on business in Australia with annual turnover above A$3 million, and any responsible entity for a critical infrastructure asset, must report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours of making it or learning that someone made it on their behalf. The Department of Home Affairs factsheet is clear on both halves: “the payment of a ransom or cyber extortion demand is not generally prohibited,” and failing to report one carries a civil penalty of 60 penalty units.
The regime captures non-monetary benefits as well as cash, so handing over something other than cryptocurrency does not avoid the duty. It also sits on top of Australia’s sanctions and anti-money-laundering laws, which apply to a ransom exactly as they apply to any other transfer. Australia was the first country to make payment reporting mandatory, and the UK’s proposed prevention regime borrows the idea.
// Free tool
How does your own site score?
Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.
No signup. Nothing installed. We only request what your site already serves publicly.
Is paying ransomware illegal in the European Union?
There is no EU-wide ban on paying, and as far as we can find no member state has enacted one. What the EU requires is disclosure. NIS2, transposed into national law across 2024 and 2025, obliges essential and important entities to send an early warning of a significant incident within 24 hours and a fuller notification within 72, and a ransomware attack that takes systems down is a significant incident by any reading. EU sanctions apply to ransom payments in the same way US and UK sanctions do, and the EU has designated ransomware-linked individuals under its cyber sanctions regime. Data-protection law adds a second clock: a breach involving personal data must be reported to the supervisory authority within 72 hours under the GDPR, whatever happens with the ransom.
What does a legal payment still not get you?
Clearing the legal hurdle does not make paying a good decision, and the data on outcomes is not encouraging. Among the 1,748 confirmed ransomware attacks since 2018 where the victim’s decision is on the public record, 244 paid and 1,504 refused, a disclosed payment rate that has fallen from 29% in 2018 to under 10% now. The payment-rate analysis has the full series by sector and country.
The reason fewer victims pay is that payment buys less than it promises. A decryptor is not a recovery plan; rebuilding from a working key can take as long as rebuilding from backups. A promise to delete stolen data is unenforceable, and groups that keep it one year sell the data the next. And paying does not always end the extortion: the US government’s advisory on Medusa records a victim who paid, then was contacted by a second actor from the same group claiming the negotiator had stolen the money and asking for half of it again. Our guide to negotiation tactics starts from the assumption that every group is capable of that.
What should an organisation do before deciding?
Four things, in order. First, identify the group as precisely as the evidence allows, because sanctions exposure turns on it; leak-site branding, ransom-note wording and tooling all help, and our attribution guide covers the method. Second, notify law enforcement and, where the law requires it, the regulator, before any payment discussion, since in the US that is the main mitigating factor OFAC recognises and in Australia and soon the UK it is a legal duty. Third, involve counsel and the insurer, both of whom carry their own sanctions exposure and will want a say. Fourth, run the incident-response runbook as if you will not pay, because the organisations that recover fastest are the ones that never needed to.
Frequently asked questions
Is it illegal to pay a ransomware ransom?
For most private organisations in the US, UK, EU and Australia, no. It becomes illegal if the payment goes to a sanctioned person or group, which applies on a strict-liability basis in the US and is a criminal offence in the UK. Public bodies in North Carolina and Florida are banned from paying, and the UK is legislating to ban public sector bodies and critical infrastructure operators.
Can you go to jail for paying a ransomware ransom?
Only where the payment breaches sanctions or anti-money-laundering law, for example by paying a designated group. In that case penalties can include criminal charges. Paying a non-sanctioned group is not itself a crime in the US, UK, EU or Australia as of 2026.
Do you have to report a ransomware payment?
In Australia, yes: entities with turnover above A$3 million and critical infrastructure operators must report any payment to the Australian Signals Directorate within 72 hours. In the EU, NIS2 requires incident reporting within 24 and 72 hours regardless of payment. In the UK, a mandatory reporting duty is proposed. In the US, reporting to the FBI is voluntary but is the main factor OFAC treats as mitigating.
Has the UK banned ransomware payments?
Not yet. On 22 July 2025 the government confirmed it will ban payments by public sector bodies and critical national infrastructure operators. As of February 2026 the ban was still a proposal under development, alongside a payment prevention regime and a mandatory reporting duty for everyone else.
What is the OFAC ransomware advisory?
A US Treasury advisory first issued in October 2020 and updated in September 2021 warning that ransomware payments to sanctioned persons violate US sanctions law on a strict-liability basis, and that victims, negotiators, insurers and exchanges all carry that exposure. It lists a compliance programme, prompt law-enforcement reporting and cooperation as mitigating factors.
Does cyber insurance cover ransomware payments?
Many policies cover extortion payments, but insurers face the same sanctions exposure as the victim and will refuse to fund a payment to a designated group. Coverage terms vary by policy and jurisdiction, and some policies now require the insurer’s consent and law-enforcement notification before any payment.
How many ransomware victims actually pay?
Fewer than one in ten, on the public record. Of 1,748 confirmed ransomware attacks since 2018 where the outcome is known, 244 paid and 1,504 refused, and the disclosed payment rate has fallen from 29% in 2018 to under 10% in 2025 and 2026.
Sources and further reading
- Harvard Law School Forum on Corporate Governance: a guide for boards and companies facing ransomware demands, on the OFAC advisories
- Nelson Mullins: North Carolina becomes the first state to prohibit public entities from paying ransoms
- CPO Magazine: Florida and North Carolina ban ransomware payments by public entities
- Computer Weekly: UK government to bring in ransomware payment ban, July 2025
- Goodwin: the UK’s ransomware strategy, what the government’s response signals, February 2026
- Australian Department of Home Affairs: mandatory ransomware and cyber extortion payment reporting factsheet
- Infosecurity Magazine: mandatory ransomware payment disclosure begins in Australia
- Ransomnews: the disclosed ransom payment rate, 2018 to 2026 and confirmed ransomware statistics
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
