Since 30 May 2025, an Australian business that turns over more than $3 million and pays a ransom has to report that payment to the Australian Signals Directorate (ASD) within 72 hours. The Department of Home Affairs spent the first six months educating businesses about the rule. From 1 January 2026 it moved to active enforcement.
The rule itself is simple. The problem is timing. Those 72 hours land in the worst week your business will ever have, while systems are down, staff are idle, customers are calling and an insurer's incident response team is working through the night. If nobody has planned for the report, it gets missed or rushed.
This guide covers who the rule applies to, what counts as a payment, when the clock starts, what goes in the report and what to put in place now so it is a 20 minute task instead of a scramble.
The ransomware payment reporting rule in one paragraph
Part 3 of the Cyber Security Act 2024 says that if your business is a reporting business entity, is hit by a ransomware or cyber extortion incident and a payment is made to the attacker, by you or by anyone on your behalf, you must report it to ASD within 72 hours. Three conditions, one deadline.
Does it apply to your business?

You are a reporting business entity if you carry on business in Australia, are not a Commonwealth or state body and meet either of these tests:
- Your annual turnover for the previous financial year was more than $3 million. If you only traded for part of that year, the threshold is scaled down. Home Affairs gives the example of a business that traded for 73 days: its threshold is $600,000, not $3 million.
- You are a responsible entity for a critical infrastructure asset covered by Part 2B of the Security of Critical Infrastructure Act 2018, whatever your turnover.
A few things fall outside the rule. If a demand was made but nothing was paid, there is no payment report. Scams and physical extortion threats are not covered. And if your turnover is under the threshold, you are not required to report a payment, although you can report voluntarily.
None of that means you stay quiet about the incident itself. Reporting the attack through ReportCyber is how you get ASD's help, and if personal information was involved the Notifiable Data Breaches scheme may apply separately (more on that below).
What counts as a ransomware payment?
More than a crypto transfer. Home Affairs is explicit that the rule captures both monetary and non monetary benefits given to an extorting entity, such as gifts, services or other benefits.
It also does not matter who pays. Payments made through an overseas office or by a third party must be reported, and the obligation stays with your business. This catches a lot of people out. Where a cyber insurer or its incident response firm negotiates and pays, the business can easily assume the insurer has handled everything. The insurer or another third party can submit the report for you, but it must include the details of both the business that was attacked and whoever made the payment. If it does not get lodged, it is your business that has failed to report.
When does the 72 hour clock start?
From the moment the payment is made, or from when you become aware that a payment was made on your behalf. Not from when the attack started, and not from when the forensics are finished.

Here is how that plays out. Picture a Perth engineering firm with 60 staff and $14 million in turnover. Its servers are encrypted in the early hours of a Tuesday. By Wednesday its insurer's incident response team is negotiating. At 4pm on Friday, after the backups turn out to be incomplete, the insurer pays. The firm's report is now due by 4pm on Monday, across a weekend, while everyone is focused on getting systems back. If the firm only learns on Saturday morning that the payment went through, the clock runs from Saturday morning instead.
That is why the report needs a named owner before anything happens.
What goes in a ransomware payment report
You report through ASD's ransomware and cyber extortion payment reporting form at cyber.gov.au, and you get a reference number when it is submitted. The report asks for the following, where it is known or can reasonably be found out:
- Your contact and business details, including your ABN, and the details of any third party that made the payment for you.
- When the incident happened, or roughly when, and when you became aware of it.
- The impact on your business and your customers.
- The ransomware or other malware variant used, if known.
- Any vulnerabilities that were exploited.
- What the attacker demanded, including the amount and the payment method they asked for.
- What was paid and how it was provided.
- The nature and timing of communications with the attacker, including any negotiation before payment.
- Any other information that would help the government respond.
"Known or reasonably discoverable" matters. You report what you know inside the 72 hours. You do not wait for the forensic report.
What happens to the information you report
This is the part most businesses worry about, and the protections are stronger than people expect. Under section 29 of the Act, information in a payment report can only be used for limited purposes, such as helping you respond to and recover from the incident, supporting the functions of intelligence agencies and keeping Ministers informed. It cannot be used for enforcement action against you, except for enforcing the reporting rule itself.
The report is also not admissible in criminal proceedings, civil penalty proceedings or proceedings for breaches of other Commonwealth, state or territory laws, with narrow exceptions such as giving false or misleading information, Royal Commissions and coronial inquiries.
One trap: sharing information voluntarily with the National Cyber Security Coordinator does not count as your mandatory payment report. They are separate processes, so do both if you are doing one.
The penalty, and the bigger legal risk
Failing to report is a civil penalty of 60 penalty units. The Commonwealth penalty unit rose from $330 to $364 on 1 July 2026, which puts that at $21,840. A company can face up to five times that amount, around $109,000.
The larger risk sits in who you pay. Paying a ransom is not illegal in Australia in itself, but paying a person on the sanctions list is. Australia has placed cyber sanctions on ransomware figures, including LockBit's alleged leader Dmitry Khoroshev in May 2024. The Department of Foreign Affairs and Trade says making or facilitating a ransomware payment to a sanctioned person or entity would breach sanctions law. For companies these are strict liability offences with fines of up to 10,000 penalty units or three times the value of the transaction, unless the company can show it took reasonable precautions and exercised due diligence. DFAT also says that engaging with government and voluntarily disclosing the payment will be taken into account in any enforcement decision.
The government's position is that businesses should not pay. Payment does not guarantee your data is deleted or that the decryption key works, and it funds the next attack. Some businesses will still pay when the alternative is closing the doors. If that happens, the report and the sanctions check need to be part of the decision, not an afterthought.
The other clocks running in the same week
- Notifiable Data Breaches: if personal information was accessed and serious harm is likely, you have up to 30 days to assess the breach, then must notify the OAIC and affected individuals as soon as practicable. This applies to businesses covered by the Privacy Act, which includes health service providers of any size.
- Critical infrastructure: responsible entities under the SOCI Act have their own incident reporting deadlines of 12 or 72 hours depending on the impact.
- Your cyber insurer: most policies require notice as soon as practicable, and many only cover response costs from providers they approve.
- ReportCyber: reporting the incident to ASD, or calling 1300 CYBER1 (1300 292 371), gets you access to government help.
What to put in place now
- Add the 72 hour rule to your incident response plan. Name an owner and a backup, and say who confirms the turnover threshold. If you do not have a plan, start with our guide to building an incident response plan.
- Fill in the parts of the report that never change ahead of time: legal entity name, ABN, contacts and last year's turnover. Keep a copy somewhere that will still be reachable if your systems are encrypted.
- Read your cyber insurance policy with this in mind. Who negotiates, who pays and who lodges the report? Get the answer in writing from your broker.
- Decide in advance who can approve a payment, and make a sanctions check a required step before any payment is made.
- Keep a timestamped log from the first minute of an incident. Most of the report comes straight out of that log: when you found it, what was demanded, what was said and when.
- Make paying unnecessary. MFA on every account, immutable backups that are kept off your network and tested regularly, plus endpoint detection and response watched around the clock. These are what give you the option of saying no.
- Run a tabletop exercise that includes the report. An hour with the leadership team walking through a scenario like the one above will show the gaps quickly.
For context on why this matters: ASD responded to 138 ransomware incidents in 2024 to 2025, about 11% of all the incidents it handled, and the average self reported cost of cybercrime for a medium business rose 55% to $97,166 (ASD Annual Cyber Threat Report 2024 to 2025).
How we help
Our SecureShield plans include 24/7 detection and response on every plan and, from the Gold plan up, a documented incident response plan that is tested every year. That plan is where the payment report, its owner and your insurer's role should be written down. If you would like a second opinion on your current plan or your insurance cover, talk to our team. If you are dealing with an incident right now, call 1300 787 429.
Ransomware payment reporting questions
Do we have to report if we did not pay?
Not under the payment reporting rule. You should still report the incident to ASD through ReportCyber, and check whether the Notifiable Data Breaches scheme applies.
Our insurer paid the ransom. Who reports it?
Your business is responsible. The insurer or its incident response firm can lodge the report on your behalf, but it must include the details of both your business and the party that paid. Confirm in writing that it has been done.
Is paying a ransom illegal in Australia?
Not in itself. Paying a sanctioned person or entity is, and for companies that is a strict liability offence. Ransomware groups do not advertise who is behind them, which is why a sanctions check belongs in the decision.
Will our report be made public?
No. Reports are protected by limited use provisions in the Cyber Security Act and cannot be used for enforcement against you, other than for failing to report.
This article is general information, not legal advice. For decisions during an incident, involve your lawyer and your insurer.
Sources
- Department of Home Affairs, Mandatory ransomware and cyber extortion payment reporting factsheet
- Department of Home Affairs, Cyber Security Act 2024
- Department of Foreign Affairs and Trade, Guidance note: cyber sanctions
- Minister for Foreign Affairs, Cyber sanction imposed on Russian citizen for ransomware activity (8 May 2024)
- Australian Signals Directorate, Annual Cyber Threat Report 2024 to 2025
- Office of the Australian Information Commissioner, Notifiable data breaches


