• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

2

The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises

3

Current price of oil as of May 19, 2026

1

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

2

The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises

3

Current price of oil as of May 19, 2026
Techransomware

Why making companies disclose ransomware payouts may be a good idea

By
Kevin T. Dugan
Kevin T. Dugan
Down Arrow Button Icon
By
Kevin T. Dugan
Kevin T. Dugan
Down Arrow Button Icon
July 22, 2021, 7:00 PM ET

It costs just $10 to hold a company hostage. 

That figure, reported by cybersecurity startup Recorded Future, may be why that firm estimates there were 65,000 ransomware attacks worldwide in 2020. Anyone with an Internet connection, a Bitcoin wallet, and some spare change can hire hackers to deploy malicious software to freeze up a target company’s computer systems, lock them out of it, and demand a nearly untraceable payment of millions of dollars in order to get their information back. No technical knowledge, or even a gun, is needed.

The prevalence of these heists has led to a push to take them out of the shadows and require companies to publicly disclose when they’ve been targeted, or even paid the ransom. Lawmakers and federal agencies like the Securities and Exchange Commission are examining what kinds of reporting, if any, it should impose.

There’s a need for “real-time” disclosure when companies are hit with ransomware attacks, Sen. Angus King, (D-ME) said on CNN’s State of the Union last month. “The Colonial Pipeline, my understanding is, it wasn’t reported to the government for four or five days. I think they’d already paid the ransom.”

Updating disclosure laws may not be so easy, however. Each state has its own disclosure requirements, and while some require transparency when data is “inaccessible,” others are tailored more for attacks that steal data, said Anton L. Janik, Jr., a cybersecurity lawyer at Mitchell, Williams, Selig, Gates & Woodyard in Little Rock, Ark. 

While ramping up disclosures could backfire and end up exposing more weaknesses in companies and governments, transparency does have the benefit of informing consumers about how their data is being used, he said. 

“That choice about who owns, controls, and processes your data are important things to discuss,” Janik said. “There’s room for consumers to have knowledge and understanding and ability to gauge cybersecurity practices of the entities that they come into contact with in their daily life.”

Increased disclosure could help tamp down ransomware and create a better understanding of the problem’s scope, according to a recent report by the Institute for Security and Technology, a think tank with connections to the Obama administration and former U.S. military officials. As it is, states and the federal governments all have different, and sometimes overlapping, rules around disclosing cyber breaches. Equifax, for instance, took more than two months to disclose a hack that ultimately exposed more than 160 million people’s private data. In the end, many companies that pay off ransomware gangs never say so because of the bad publicity that comes with it.

“Updating breach disclosure laws to include a ransom payment disclosure requirement would help increase the understanding of the scope and scale of the crime, allow for better estimates of the societal impact of these payments, and enable better targeting of disruption activities,” the report said. 

More disclosure can also empower law enforcement to cut the flow of ill-gotten cryptocurrencies, the Institute for Security and Technology added. Authorities could issue “freeze letters” to cryptocurrency exchanges, which handle the ransom transactions, so they can stop ransom payments before they’re made, IST recommended. 

SEC regulators are looking at requiring the disclosure under its rules related to so-called ESG, or environmental, social, and governance. For the regulator, cybersecurity largely falls under “social”, said Jina Choi, a partner at law firm Morrison & Foerster, and former director of the Security and Exchange Commission’s San Francisco office.

“Under the federal securities laws, for public companies the legal standard regarding disclosure to its shareholders is materiality – and the SEC has set forth guidance regarding the costs, including reputational damage, that a company can incur if they are breached,” she said. 

Ransomware is one of the thorniest problems on the Internet today — one so pernicious and complex that Homeland Security Department officials have called it a “national threat.” President Joe Biden recently pushed Vladimir Putin to stop attackers — they tend to be situated in Russia or in the ex-Soviet Union — and offered a $10 million reward to anyone who can uncover the identities of these attacks.

The consequences of the problem came into sharp relief earlier this year following the attack of Colonial Pipeline, the company that transports about half of the East Coast’s oil. It paid 75 bitcoins, amounting to $5 million, in order to get its systems back online, but the damage was already done: Gas prices jumped, the airlines rerouted flights, and the federal government had to warn people not to hoard gas in plastic bags. 

The idea of requiring companies to disclose attacks does have its critics, however. Nick Merrill, a postdoctoral fellow at director of the Daylight Security Research Lab at the University of California at Berkeley’s Center for Long-Term Cybersecurity, said he was concerned that ramping up disclosure, without strengthening other security measures, may not be enough. 

“It’s tempting because it’s simple. And the real answers are much bigger and much broader than that,” Miller said. “I just worry that it’s a box checking exercise. And once it’s done, where would we be?”

One problem, he added, is that hackers could change their tactics so their attacks wouldn’t qualify as “ransomware”. He cited an attack on the Washington D.C. Metro Police that threatened to out its confidential informants, which he called “extortionware.” 

Another potential problem is rooted in ransomware’s ubiquity. Miller compared it to European data disclosure requirements on just about every web page — which users typically ignore. “These reporting requirements can go awry to such a degree that people just learn to ignore them,” he said, “and that would be worse than where we are now.”

But even informing consumers about some of a breach’s scope could better inform consumers. 

“I don’t think you need to disclose the dollar value of a hack, but you can disclose that there was a hack,” Janik said. “You could disclose the size of a hack — this is 600,000 patient records. I think those parameters are helpful to a customer in the marketplace to evaluate, ‘where do I feel comfortable?’”

 

Subscribe to Fortune Daily to get essential business stories straight to your inbox each morning.

About the Author
By Kevin T. Dugan
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

trader
CommentarySoftware
The 50-year-old law that governed every software company just broke. Here’s what replaces it
By Martin Casado and Abhishek NagarajMay 20, 2026
3 minutes ago
Exclusive: Circle cofounder raises $30 million for Series A ‘AI-native bank’ Catena Labs
CryptoVenture Capital
Exclusive: Circle cofounder raises $30 million for Series A ‘AI-native bank’ Catena Labs
By Ben WeissMay 20, 2026
33 minutes ago
FJ Campbell, MD, is chief medical officer at Ardent Health.
CommentaryHealth
A doctor shortage is coming. AI could be the only realistic fix
By FJ CampbellMay 20, 2026
2 hours ago
Alex Israel crosses his arms
AITerm Sheet
How Metropolis built a $5 billion AI infrastructure company out of America’s parking problem
By Lily Mae LazarusMay 20, 2026
2 hours ago
Alphabet CEO Sundar Pichai in Mountain View, California on May 19, 2026. (Photo: David Paul Morris/Bloomberg/Getty Images)
NewslettersFortune Tech
At Google I/O 2026, it’s AI, AI, and more AI
By Andrew NuscaMay 20, 2026
3 hours ago
Exclusive: Advocacy groups file complaint against Roblox, alleging its manipulative design puts kids at risk
CybersecurityRoblox
Exclusive: Advocacy groups file complaint against Roblox, alleging its manipulative design puts kids at risk
By Catherina GioinoMay 20, 2026
3 hours ago

Most Popular

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
Workplace Culture
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
By Preston ForeMay 19, 2026
15 hours ago
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
8 days ago
Current price of oil as of May 19, 2026
Personal Finance
Current price of oil as of May 19, 2026
By Joseph HostetlerMay 19, 2026
23 hours ago
Employers are quietly pausing 401(k) matches again. The last time this happened was the 2008 recession and Covid
Personal Finance
Employers are quietly pausing 401(k) matches again. The last time this happened was the 2008 recession and Covid
By Courtney Vinopal and HR BrewMay 18, 2026
2 days ago
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
Future of Work
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
By Mike Householder and The Associated PressMay 17, 2026
3 days ago
Current price of silver as of Monday, May 18, 2026
Personal Finance
Current price of silver as of Monday, May 18, 2026
By Joseph HostetlerMay 18, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.