AI Security, Privacy and Compliance

Do You Have to Report a Ransomware Payment in Australia (and Who Does the Rule Apply To)?

Last updated 19 August 2026 · 7 min read

Direct Answer

Yes, if your business meets the threshold. Under the Cyber Security Act 2024, a "reporting business entity" — broadly, a business with annual turnover of $3 million or more, or an entity responsible for a critical infrastructure asset — must report to the Australian Signals Directorate (ASD) within 72 hours of making, or becoming aware that someone made on its behalf, a ransomware or cyber extortion payment. There's no minimum payment amount that's exempt: if a reportable payment is made, it must be reported, whatever the sum. The obligation took effect on 30 May 2025 and has been in an active enforcement phase since 1 January 2026, with civil penalties of up to 60 penalty units (currently $19,800) for a business that misses the 72-hour window. Businesses under the $3 million turnover threshold, and not responsible for critical infrastructure, aren't covered by this specific mandatory obligation — though other obligations, such as notifying an eligible data breach to the OAIC, can still apply separately.

Detailed Explanation

Australia became the first country to introduce a dedicated mandatory ransomware and cyber extortion payment reporting regime when this obligation commenced on 30 May 2025 under the Cyber Security Act 2024. It's a narrow, specific rule — it doesn't require reporting every cyberattack, only ransomware and cyber extortion payments that are actually made — but it catches a meaningful slice of Australian small and mid-sized businesses because the turnover threshold sits at a level many established SMBs clear.

The obligation exists because, historically, most ransomware payments in Australia went unreported to any government body, which left regulators with almost no visibility into how much money was flowing to cybercriminal groups or which sectors were being targeted. Mandatory reporting is a data-gathering and threat-intelligence measure first, and a compliance obligation for individual businesses second.

Who Has to Report

A business is a "reporting business entity" under the Act if either of the following applies:

  • Turnover test. The business had an annual turnover of $3 million or more for its most recently completed financial year. This is measured at the entity level using ordinary accounting turnover, not a narrower profit or revenue-from-Australia-only figure — a business that's grown past $3 million since its last review should treat itself as covered going forward.
  • Critical infrastructure test. The business is a responsible entity for a critical infrastructure asset under the Security of Critical Infrastructure Act 2018 (energy, water, healthcare, communications, and similar regulated sectors), regardless of turnover.

A business under $3 million turnover and outside critical infrastructure isn't a reporting business entity under this specific obligation. That doesn't mean a ransomware incident at a smaller business has no reporting consequences at all — a personal-information breach arising from the same incident can still trigger a separate Notifiable Data Breaches obligation to the OAIC, assessed under different rules with a different threshold.

What Actually Has to Be Reported

The trigger is a ransomware payment or cyber extortion payment — a benefit (typically cryptocurrency or money) provided to an extorting party, whether paid directly by the business or by someone acting on its behalf (an insurer, an incident-response firm, or a negotiator engaged by the business). It's the payment that triggers the obligation, not the attack itself — a business that's hit by ransomware but doesn't pay isn't required to file this particular report, though other incident-notification obligations may still apply depending on what data was affected.

There's no reporting threshold based on the size of the payment. A relatively small extortion payment is just as reportable as a large one.

The 72-Hour Window

The report must be made to the Australian Signals Directorate, through the Australian Cyber Security Centre's online portal, within 72 hours of the payment being made — or, if the business becomes aware only afterward that a payment was made on its behalf (for example, by an insurer without the business's real-time knowledge), within 72 hours of becoming aware of it. That's a short window measured in hours, not business days, which is why building awareness of the obligation into an incident-response plan ahead of time matters more than for most compliance requirements — there's little time to research the rule properly once the clock has started.

What Happens If You Don't Report

A reporting business entity that fails to report within the 72-hour window can face a civil penalty of up to 60 penalty units, currently equivalent to $19,800. The Department of Home Affairs moved from an education-focused introduction into an active enforcement phase from 1 January 2026, meaning late or missed reports are more likely to draw a real regulatory response than during the law's first several months.

Separately, the Act includes limited-use protections for information given in a ransomware payment report — it's generally shielded from being used directly against the reporting entity in most other regulatory or legal proceedings arising from the same incident, with narrow, defined exceptions. This is intended to reduce the incentive to stay quiet rather than report.

Things to Consider

  • This obligation sits alongside, not instead of, other incident-notification duties. A ransomware incident involving personal information may separately trigger a Notifiable Data Breaches report to the OAIC — treat the two as related but distinct checklist items during an incident, not one combined step.
  • The turnover test uses the whole business's turnover, not just the affected part. A $5 million business with a small, separately branded division that was actually hit is still covered — the threshold isn't assessed division by division.
  • Cyber insurance policies increasingly build this obligation into their incident-response process. If the business holds a policy, check whether the insurer's own coverage terms actually respond to a ransomware event — see does business insurance cover mistakes made by an AI tool or AI agent for the broader pattern of confirming what a policy actually covers rather than assuming.
  • Backups reduce the pressure to pay at all. A business with verified, tested backups has a genuinely different negotiating position than one facing total data loss — see how do you automate data backups for a small business, and verify they actually restore for the resilience side of this problem.
  • A ransomware incident is one specific kind of data-security incident, not the only one. If the immediate trigger was an employee action rather than an external attack, what do you do if an employee shares sensitive data with an AI tool by mistake covers that separate, more common incident type and its own response steps.
  • Knowing the rule exists before an incident is most of the value. Confirming in advance who inside the business (or which external adviser) would file this report removes one unknown from what is otherwise a genuinely stressful 72 hours — building baseline cyber hygiene through a framework like the ACSC Essential Eight reduces how often that 72 hours ever happens in the first place.

Common Mistakes

  • Assuming the obligation only applies to large enterprises. A $3 million turnover threshold catches a meaningful number of established small and mid-sized Australian businesses that don't think of themselves as "critical infrastructure" or "big business."
  • Confusing this with a general cyberattack reporting requirement. The obligation is specifically about a payment being made, not about experiencing an attack, a breach, or an outage — a business that's attacked but doesn't pay a ransom has no obligation under this particular rule.
  • Waiting to find out about the rule until an incident is already underway. The 72-hour clock is unforgiving, and a business researching whether it's covered for the first time during an active incident loses time it doesn't have.
  • Assuming reporting the payment means admitting fault or inviting punishment. The limited-use protections exist precisely so a business doesn't have to choose between complying with the law and protecting itself — treat reporting as the compliant, protected path rather than something to avoid.

Frequently Asked Questions

Does paying the ransom itself become illegal once you report it?
No — the Cyber Security Act's reporting obligation doesn't make paying a ransom illegal or require it; it requires disclosure of a payment that was already made. Whether paying a ransom is advisable is a separate question the ASD and most cyber-security professionals generally counsel against, since payment doesn't guarantee data recovery or that stolen data won't be leaked regardless, and it can mark a business as a repeat target — but the reporting law itself is neutral on that decision and applies either way once a covered payment has happened.
Will reporting a ransomware payment trigger a separate investigation or penalty for the breach itself?
Information provided in a ransomware payment report is subject to limited-use protections: it generally cannot be used directly against the reporting entity for a regulatory or enforcement action, or admitted as evidence in most civil or criminal proceedings, with narrow exceptions set out in the Act. The intent is to reduce the disincentive to report. This doesn't remove separate, independent obligations that may still apply to the same incident — most importantly notifying an eligible data breach to the OAIC if personal information was compromised, which is assessed and reported separately.
Does a $3 million turnover business need to do anything before an incident happens?
The reporting obligation itself only triggers once a reportable payment is made, but a business at or near the threshold benefits from knowing in advance, since the 72-hour clock starts immediately and doesn't allow time to research the rule from scratch mid-incident. Confirming who inside the business would need to file the report, and folding it into an existing incident-response or cyber-insurance process, is the practical preparation step — see what is the ACSC Essential Eight, and how do you automate tracking your maturity level for the broader framework this obligation sits inside.

References

Related Questions