Paying the Hacker, Funding the Ecosystem: Criminalising Ransomware Payments without Punishing Victim Organisations

Main Article Content

H.B Hasan Basri

Abstract

Existing scholarship had explained how ransom payments sustained ransomware markets, but it had not adequately separated the systemic harm of payment from the criminal culpability of victim organisations acting under pressure. This article examined how ransomware payments could be controlled without making victim organisations the primary targets of criminal punishment. Normative legal research was conducted through statutory, conceptual, and comparative approaches using legislation, sanctions guidance, policy documents, and academic literature from Australia, the United States, and the United Kingdom. The analysis found that ransom payments maintained the profitability of Ransomware-as-a-Service and supported a wider criminal ecosystem, yet the transfer itself did not establish equal culpability in every case. Blanket criminalisation overlooked differences in knowledge, recovery capacity, threat severity, and cooperation with authorities. A victim-protective model was therefore proposed in which payments remained reportable and subject to reasonable pre-payment scrutiny, while criminal liability focused on knowing prohibited payments, concealment, false reporting, and deliberate circumvention. Limited protection for compelled reports and narrowly framed emergency exceptions preserved cooperation and proportionality. The analysis also found that state recovery support was necessary to make refusal to pay operationally realistic.

Article Details

Section

Articles

References

Bhatt, P., Valecha, R., & Rao, H. R. (2025). Situational awareness about data breaches and ransomware attacks: A multi-dimensional cyber threat impact framework and content analyses of practitioner-public discourses. International Journal of Information Management, 83, 102902. https://doi.org/10.1016/j.ijinfomgt.2025.102902

Busetti, S., & Scanni, F. M. (2025). Evaluating incident reporting in cybersecurity: From threat detection to policy learning. Government Information Quarterly, 42(1), 102000. https://doi.org/10.1016/j.giq.2024.102000

Cartwright, A., Cartwright, E., MacColl, J., Mott, G., Turner, S., Sullivan, J., & Nurse, J. R. C. (2023). How cyber insurance influences the ransomware payment decision: Theory and evidence. The Geneva Papers on Risk and Insurance—Issues and Practice, 48(2), 300–331. https://doi.org/10.1057/s41288-023-00288-8

Corbet, S., & Goodell, J. W. (2022). The reputational contagion effects of ransomware attacks. Finance Research Letters, 47, 102715. https://doi.org/10.1016/j.frl.2022.102715

Cyber Security Act 2024 (Cth) (Australia).

Georgiou, M., Giebels, E., Oostinga, M. S. D., & Spithoven, R. (2026). Engaging with cybercriminals: Phases and influence strategies in ransomware negotiations. Computers in Human Behavior, 181, 108953. https://doi.org/10.1016/j.chb.2026.108953

Hansel, M., & Silomon, J. (2024). Ransomware as a threat to peace and security: Understanding and avoiding political worst-case scenarios. Journal of Cyber Policy, 9(2), 159–178. https://doi.org/10.1080/23738871.2024.2357092

Hernandez-Castro, J., Cartwright, A., & Cartwright, E. (2020). An economic analysis of ransomware and its welfare consequences. Royal Society Open Science, 7(3), 190023. https://doi.org/10.1098/rsos.190023

Home Office. (2025a). Ransomware legislative proposals: Reducing payments to cyber criminals and increasing incident reporting. UK Government. https://www.gov.uk/government/consultations/ransomware-proposals-to-increase-incident-reporting-and-reduce-payments-to-criminals/ransomware-legislative-proposals-reducing-payments-to-cyber-criminals-and-increasing-incident-reporting-accessible

Home Office. (2025b). Government response to ransomware legislative proposals: Reducing payments to cyber criminals and increasing incident reporting. UK Government. https://www.gov.uk/government/consultations/ransomware-proposals-to-increase-incident-reporting-and-reduce-payments-to-criminals/outcome/government-response-to-ransomware-legislative-proposals-reducing-payments-to-cyber-criminals-and-increasing-incident-reporting-accessible

Kadir, Z. K. (2024). Dari Dualisme ke Monisme: Transformasi Konsep Mens Rea dalam Kodifikasi KUHP di Negara-Negara Poskolonial. Jurnal Litigasi Amsir, (Special Issue), 142–155.

Kadir, Z. K. (2025). Kejahatan Berbasis Identitas Digital: Menggagas Kebijakan Kriminal untuk Dunia Metaverse. Jurnal Litigasi Amsir, 12(2), 124–137.

Kadir, Z. K. (2026). Preventing Murder Without Expanding Punishment: Rethinking Homicide Policy Beyond Deterrence. Punggawa Law Review, 1(3), 49–58. https://doi.org/10.67707/plr.v1i3.40

Luu, T. J., Samuel, B. M., Jones, M., & Barnes, J. C. (2025). Exploring how the Dark Triad shapes cybercrime responses. Personality and Individual Differences, 244, 113250. https://doi.org/10.1016/j.paid.2025.113250

Marett, K., & Nabors, M. (2021). Local learning from municipal ransomware attacks: A geographically weighted analysis. Information & Management, 58(7), 103482. https://doi.org/10.1016/j.im.2021.103482

Matthijsse, S. R., Moneva, A., van ’t Hoff-de Goede, M. S., & Leukfeldt, E. R. (2025). Examining ransomware payment decision-making among small- and medium-sized enterprises. European Journal of Criminology, 22(4), 625–645. https://doi.org/10.1177/14773708241285671

Meurs, T., Junger, M., Cruyff, M., & van der Heijden, P. G. M. (2026). Estimating the number of ransomware attacks. Journal of Quantitative Criminology, 42, 227–243. https://doi.org/10.1007/s10940-025-09625-7

Mott, G., Turner, S., Nurse, J. R. C., Pattnaik, N., MacColl, J., Huesch, P., & Sullivan, J. (2024). “There was a bit of PTSD every time I walked through the office door”: Ransomware harms and the factors that influence the victim organisation’s experience. Journal of Cybersecurity, 10(1), tyae013. https://doi.org/10.1093/cybsec/tyae013

Murray, G., Falkeling, M., & Gao, S. (2025). Trends and challenges in research into the human aspects of ransomware: A systematic mapping study. Information and Computer Security, 33(2), 161–195. https://doi.org/10.1108/ICS-12-2022-0195

Negara, T. A. S. (2023). Normative legal research in Indonesia: Its origins and approaches. Audito Comparative Law Journal, 4(1), 1–9. https://doi.org/10.22219/aclj.v4i1.24855

Neprash, H. T., McGlave, C. C., Rydberg, K., & Henning-Smith, C. (2024). What happens to rural hospitals during a ransomware attack? Evidence from Medicare data. The Journal of Rural Health, 40(4), 728–737. https://doi.org/10.1111/jrh.12834

Neprash, H., McGlave, C., & Nikpay, S. (2026). Hacked to pieces? The effects of ransomware attacks on hospitals and patients. American Economic Journal: Economic Policy, 18(1), 256–281. https://doi.org/10.1257/pol.20240594

Oosthoek, K., Cable, J., & Smaragdakis, G. (2023). A tale of two markets: Investigating the ransomware payments economy. Communications of the ACM, 66(8), 74–83. https://doi.org/10.1145/3582489

Oz, H., Aris, A., Levi, A., & Uluagac, A. S. (2022). A survey on ransomware: Evolution, taxonomy, and defense solutions. ACM Computing Surveys, 54(11s), 1–37. https://doi.org/10.1145/3514229

Reshmi, T. R. (2021). Information security breaches due to ransomware attacks—A systematic literature review. International Journal of Information Management Data Insights, 1(2), 100013. https://doi.org/10.1016/j.jjimei.2021.100013

Robles-Carrillo, M., & García-Teodoro, P. (2022). Ransomware: An interdisciplinary technical and legal approach. Security and Communication Networks, 2022, 2806605. https://doi.org/10.1155/2022/2806605

Ruellan, E., Paquet-Clouston, M., & Garcia, S. (2024). Conti Inc.: Understanding the internal discussions of a large ransomware-as-a-service operator with machine learning. Crime Science, 13, 16. https://doi.org/10.1186/s40163-024-00212-y

Saccone, F., Melillo, P., Sgueglia, A., Di Sorbo, A., & Visaggio, C. A. (2025). The ransomware blueprint: Attack patterns and strategic variations across gangs. Journal of Information Security and Applications, 95, 104264. https://doi.org/10.1016/j.jisa.2025.104264

Taekema, S. (2021). Methodologies of rule of law research: Why legal philosophy needs empirical and doctrinal scholarship. Law and Philosophy, 40, 33–66. https://doi.org/10.1007/s10982-020-09388-1

Teichmann, F. (2026). International legal responses to ransomware: Toward a ban on payments? International Cybersecurity Law Review, 7, 41–68. https://doi.org/10.1365/s43439-025-00167-z

Teichmann, F. M. J., & Wittmann, C. (2023). When is a law firm liable for a data breach? An exploration into the legal liability of ransomware and cybersecurity. Journal of Financial Crime, 30(6), 1491–1498. https://doi.org/10.1108/JFC-04-2022-0093

Turner, A. B., McCombie, S., & Uhlmann, A. J. (2020). Discerning payment patterns in Bitcoin from ransomware attacks. Journal of Money Laundering Control, 23(3), 545–589. https://doi.org/10.1108/JMLC-02-2020-0012

U.S. Department of the Treasury, Office of Foreign Assets Control. (2021). Updated advisory on potential sanctions risks for facilitating ransomware payments. https://ofac.treasury.gov/recent-actions/20210921

Vakhitova, Z., & Mezzetti, C. (2026). Ransomware, emotions, and the decision to pay: Evidence from a factorial experiment. Crime & Delinquency. Advance online publication. https://doi.org/10.1177/00111287261440149

Vinogradskiy, Y., Schubert, L., Taylor, A., Rudoler, S., & Lamb, J. (2024). Radiation oncology ransomware attack response risk analysis using failure modes and effects analysis. Practical Radiation Oncology, 14(5), e407–e415. https://doi.org/10.1016/j.prro.2024.03.001

Welburn, J. W., & Strong, A. M. (2022). Systemic cyber risk and aggregate impacts. Risk Analysis, 42(8), 1606–1622. https://doi.org/10.1111/risa.13715

Whelan, C., Bright, D., & Martin, J. (2024). Reconceptualising organised (cyber)crime: The case of ransomware. Journal of Criminology, 57(1), 45–61. https://doi.org/10.1177/26338076231199793

Worsley, M. K., Kendall-Morwick, J., & Houston, K. A. (2025). Change waits for no one: An examination of the legal response to ransomware attacks. Criminal Justice Policy Review, 36(6), 259–280. https://doi.org/10.1177/08874034251363431

Yuryna Connolly, L., & Borrion, H. (2022). Reducing ransomware crime: Analysis of victims’ payment decisions. Computers & Security, 119, 102760. https://doi.org/10.1016/j.cose.2022.102760