You paid the ransom. Now you have 72 hours to tell the government


You paid the ransom. Now you have 72 hours to tell the government

Most Australian business owners have never heard of Part 3 of the Cyber Security Act 2024, and the ones who have usually assume it doesn't apply to them. That assumption is wrong more often than people expect. The threshold isn't enterprise scale — it's $3 million in annual turnover, which captures a mid-sized e-commerce operation, a busy medical practice group, a construction firm, or a seed-stage software company. If you carry on business in Australia and cleared that line in the last financial year, and you pay a cyber extortion demand, the law now requires a report to the federal government within 72 hours.

This is not a proposal or a bill. The obligation commenced on 30 May 2025 under Part 3 of the Cyber Security Act 2024, backed by the Cyber Security (Ransomware Payment Reporting) Rules 2025. Home Affairs ran an education-first phase through to 31 December 2025; since 1 January 2026 the department has been in active compliance mode. The numbers show the regime is already carrying weight: figures obtained under freedom of information showed at least 94 ransomware or cyber extortion payments reported to government in the regime's first eight months, 75 of them from businesses above the turnover threshold. ASD responded to 138 ransomware incidents in the 2024-25 financial year, and 64 per cent of attacked businesses paid. Payments are happening. They are now reportable.

Who is captured

The Act defines a "reporting business entity" two ways, and either is enough:

The $3 million line was chosen deliberately: it mirrors the Privacy Act's small business exemption. The policy logic is that if you're big enough to carry full privacy obligations, you're big enough to report when you pay criminals.

What triggers the duty — and what doesn't

Three design points trip people up:

  1. A demand alone triggers nothing. If you're hit by ransomware, refuse to pay, and restore from backups, Part 3 has no report for you to make. You may have other obligations (more on those below), but not this one. Paying is not illegal under this Act; not reporting is the contravention.
  2. "Payment" is broader than money. The Act captures any benefit — monetary or otherwise — provided in response to an extortion demand connected to a cyber incident. Cryptocurrency, services, anything of value. There's no minimum. A token payment "to make it go away" is reportable, and the definition covers cyber extortion over stolen data even where nothing was encrypted.
  3. Third-party payments are still yours. If your cyber insurer, your incident response firm, your negotiator, or an overseas parent pays on your behalf, the obligation remains yours, and the 72-hour clock runs from the moment you become aware the payment was made. The Act applies extraterritorially, so routing the payment through an offshore entity changes nothing.

What the report must contain

Reports go through ASD's reporting portal on cyber.gov.au and land with the Department of Home Affairs and the Australian Signals Directorate. Section 27 of the Act and the Rules prescribe the content, to the extent it is known or discoverable by reasonable enquiry:

Seventy-two hours is short when you're simultaneously restoring systems, and the report can't be reconstructed from memory on day four. Practitioners writing about the regime — see this ransomware playbook guide — make the same point: the reporting step belongs in the incident response plan as a named task with a named owner, with the incident timeline, variant, demand and negotiation record captured as the incident unfolds, not assembled afterwards. Keep the unique reference number you receive on submission; it is your evidence the deadline was met.

Miss the deadline and the civil penalty is 60 penalty units — $21,840 at the penalty unit value applying to contraventions from 1 July 2026, and a court can multiply that up to five times against a company. The dollar figure is modest by design. The real exposure is what an unreported payment signals to every other regulator examining the same incident — ASIC, APRA, the OAIC — and the sanctions screen you skipped before funds moved.

Limited use, not amnesty

Two protections are built in, and both are narrower than they sound. First, information in a ransomware payment report can only be used for permitted purposes — helping you respond, intelligence functions, administering the regime — and cannot be used for investigating or enforcing civil or regulatory contraventions of other laws. Note the carve-out: criminal offences are expressly excepted. The report itself is inadmissible in most proceedings, but the facts you describe can still inform a sanctions or money laundering investigation. Second, Part 4 gives similar limited-use treatment to information you voluntarily share with the National Cyber Security Coordinator during an incident.

The practical upshot, as startups-focused commentary on the Act puts it, is that reporting is designed to be the safe option — but the payment decision itself remains a board-level legal decision. Sanctions screening happens before funds move, not after. Paying a sanctioned entity can be a criminal offence under Australia's sanctions laws regardless of duress, and government policy strongly discourages payment because it neither guarantees decryption nor prevents publication of stolen data.

The other clocks running in parallel

The payment report discharges exactly one duty. A ransomware incident with data exfiltration typically triggers several others, on separate clocks, to separate recipients:

What this means for your privacy posture

Ransomware is, at its core, a privacy failure: customer and employee records get exfiltrated, and the fallout lands on the people whose data it was. The reporting regime won't stop the first breach, but hardening the basics before an incident still changes outcomes. If your team handles sensitive accounts, a hardware-level reset habit matters — unique passwords, phishing-resistant MFA at login (not just at payment), and verified backups that were actually tested. For staff travelling or working from cafés, a Faraday phone pouch and a USB-C data blocker are cheap layers against the opportunistic attacks that start a chain ending in an extortion demand. For anything you plug into a compromised-feeling network, a faraday laptop sleeve keeps radios dark when the machine is shut.

If your organisation is above the threshold, the checklist is short and the deadline is unforgiving: confirm whether you're a reporting business entity, add the 72-hour payment report to the incident response plan with an owner, pre-legalise the sanctions screening step, and rehearse it. The grace period ended ten months ago. Home Affairs is no longer educating — it's regulating.

This article is general information, not legal advice. For a specific incident, take advice from a qualified Australian lawyer before paying or reporting.


← All posts