23

Australia - the first country in the world to make it mandatory for organisations to declare to the government if a ransomware payment is made on their behalf to cyber extortionists

Reports will have to be made to the ASD within 72 hours

What do you think? Good idea? Would you like a similar mandatory approach in your country?

More details on which businesses the law applies to, and penalties, can be found at https://therecord.media/australia-ransomware-victims-must-report-payments

#cybersecurity #ransomware

top 3 comments
sorted by: hot top controversial new old
[-] samueljohnson@mstdn.social 2 points 1 month ago

@gcluley@mastodon.green Seems like a good idea. I can think of several upsides.

[-] bontchev@infosec.exchange 1 points 1 month ago

@gcluley@mastodon.green Good idea in principle, because the gathered data will give us a much better picture of the severity of the problem. I have two worries, though:

  1. Will adequate measures be taken to preserve the anonymity of the victims?

  2. Might this not be just a first step towards banning ransom payments - something I am strongly opposed to?

[-] etchedpixels@mastodon.social 1 points 1 month ago

@gcluley@mastodon.green It's a start but the right approach is to require all ransomware payments go through full money laundering and know your customer rules. In other words to make them unpayable and the penalties for doing so or even assisting in doing so huge.

this post was submitted on 30 May 2025
23 points (100.0% liked)

Cybersecurity

2 readers
18 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

founded 2 years ago
MODERATORS