• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'

2

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

3

Pay transparency is exposing a bigger problem: Most companies can't explain why they pay what they pay

1

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'

2

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

3

Pay transparency is exposing a bigger problem: Most companies can't explain why they pay what they pay
Techransomware

Why making companies disclose ransomware payouts may be a good idea

By
Kevin T. Dugan
Kevin T. Dugan
Down Arrow Button Icon
By
Kevin T. Dugan
Kevin T. Dugan
Down Arrow Button Icon
July 22, 2021, 7:00 PM ET

It costs just $10 to hold a company hostage. 

That figure, reported by cybersecurity startup Recorded Future, may be why that firm estimates there were 65,000 ransomware attacks worldwide in 2020. Anyone with an Internet connection, a Bitcoin wallet, and some spare change can hire hackers to deploy malicious software to freeze up a target company’s computer systems, lock them out of it, and demand a nearly untraceable payment of millions of dollars in order to get their information back. No technical knowledge, or even a gun, is needed.

The prevalence of these heists has led to a push to take them out of the shadows and require companies to publicly disclose when they’ve been targeted, or even paid the ransom. Lawmakers and federal agencies like the Securities and Exchange Commission are examining what kinds of reporting, if any, it should impose.

There’s a need for “real-time” disclosure when companies are hit with ransomware attacks, Sen. Angus King, (D-ME) said on CNN’s State of the Union last month. “The Colonial Pipeline, my understanding is, it wasn’t reported to the government for four or five days. I think they’d already paid the ransom.”

Updating disclosure laws may not be so easy, however. Each state has its own disclosure requirements, and while some require transparency when data is “inaccessible,” others are tailored more for attacks that steal data, said Anton L. Janik, Jr., a cybersecurity lawyer at Mitchell, Williams, Selig, Gates & Woodyard in Little Rock, Ark. 

While ramping up disclosures could backfire and end up exposing more weaknesses in companies and governments, transparency does have the benefit of informing consumers about how their data is being used, he said. 

“That choice about who owns, controls, and processes your data are important things to discuss,” Janik said. “There’s room for consumers to have knowledge and understanding and ability to gauge cybersecurity practices of the entities that they come into contact with in their daily life.”

Increased disclosure could help tamp down ransomware and create a better understanding of the problem’s scope, according to a recent report by the Institute for Security and Technology, a think tank with connections to the Obama administration and former U.S. military officials. As it is, states and the federal governments all have different, and sometimes overlapping, rules around disclosing cyber breaches. Equifax, for instance, took more than two months to disclose a hack that ultimately exposed more than 160 million people’s private data. In the end, many companies that pay off ransomware gangs never say so because of the bad publicity that comes with it.

“Updating breach disclosure laws to include a ransom payment disclosure requirement would help increase the understanding of the scope and scale of the crime, allow for better estimates of the societal impact of these payments, and enable better targeting of disruption activities,” the report said. 

More disclosure can also empower law enforcement to cut the flow of ill-gotten cryptocurrencies, the Institute for Security and Technology added. Authorities could issue “freeze letters” to cryptocurrency exchanges, which handle the ransom transactions, so they can stop ransom payments before they’re made, IST recommended. 

SEC regulators are looking at requiring the disclosure under its rules related to so-called ESG, or environmental, social, and governance. For the regulator, cybersecurity largely falls under “social”, said Jina Choi, a partner at law firm Morrison & Foerster, and former director of the Security and Exchange Commission’s San Francisco office.

“Under the federal securities laws, for public companies the legal standard regarding disclosure to its shareholders is materiality – and the SEC has set forth guidance regarding the costs, including reputational damage, that a company can incur if they are breached,” she said. 

Ransomware is one of the thorniest problems on the Internet today — one so pernicious and complex that Homeland Security Department officials have called it a “national threat.” President Joe Biden recently pushed Vladimir Putin to stop attackers — they tend to be situated in Russia or in the ex-Soviet Union — and offered a $10 million reward to anyone who can uncover the identities of these attacks.

The consequences of the problem came into sharp relief earlier this year following the attack of Colonial Pipeline, the company that transports about half of the East Coast’s oil. It paid 75 bitcoins, amounting to $5 million, in order to get its systems back online, but the damage was already done: Gas prices jumped, the airlines rerouted flights, and the federal government had to warn people not to hoard gas in plastic bags. 

The idea of requiring companies to disclose attacks does have its critics, however. Nick Merrill, a postdoctoral fellow at director of the Daylight Security Research Lab at the University of California at Berkeley’s Center for Long-Term Cybersecurity, said he was concerned that ramping up disclosure, without strengthening other security measures, may not be enough. 

“It’s tempting because it’s simple. And the real answers are much bigger and much broader than that,” Miller said. “I just worry that it’s a box checking exercise. And once it’s done, where would we be?”

One problem, he added, is that hackers could change their tactics so their attacks wouldn’t qualify as “ransomware”. He cited an attack on the Washington D.C. Metro Police that threatened to out its confidential informants, which he called “extortionware.” 

Another potential problem is rooted in ransomware’s ubiquity. Miller compared it to European data disclosure requirements on just about every web page — which users typically ignore. “These reporting requirements can go awry to such a degree that people just learn to ignore them,” he said, “and that would be worse than where we are now.”

But even informing consumers about some of a breach’s scope could better inform consumers. 

“I don’t think you need to disclose the dollar value of a hack, but you can disclose that there was a hack,” Janik said. “You could disclose the size of a hack — this is 600,000 patient records. I think those parameters are helpful to a customer in the marketplace to evaluate, ‘where do I feel comfortable?’”

 

Subscribe to Fortune Daily to get essential business stories straight to your inbox each morning.

About the Author
By Kevin T. Dugan
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Elon Musk puts one hand to his chin and he looks up. He is in front of a blue "World Economic Forum" background.
InvestingSpaceX
‘SpaceX is his new baby at the expense of Tesla’: Elon Musk’s IPO could be bad news for his EV maker, investors warns
By Sasha RogelbergMay 21, 2026
3 hours ago
matthew prince
AILayoffs
Cloudflare posted record revenue, then cut 20% of its workforce. CEO Matthew Prince says AI has made an entire category of workers obsolete
By Jake AngeloMay 21, 2026
3 hours ago
Prakash Arunkundrum, HP’s first-ever chief strategy and transformation officer, bets edge AI will ‘bring the token cost down’
AIConsumer electronics
Prakash Arunkundrum, HP’s first-ever chief strategy and transformation officer, bets edge AI will ‘bring the token cost down’
By Angelica AngMay 21, 2026
3 hours ago
malaysia
CybersecuritySocial Media
Malaysia slams ‘grossly offensive, false, menacing and insulting’ TikTok memes about its king
By The Associated PressMay 21, 2026
5 hours ago
Meta laid off 10% of its workforce as Mark Zuckerberg warns that in the AI race ‘success isn’t a given’
AILayoffs
Meta laid off 10% of its workforce as Mark Zuckerberg warns that in the AI race ‘success isn’t a given’
By Marco Quiroz-GutierrezMay 21, 2026
5 hours ago
bock
Cybersecurityfraud
Minnesota fraudster at center of $250 million scam, controversial ICE crackdown sentenced to 42 years
By Tim Sullivan and The Associated PressMay 21, 2026
6 hours ago

Most Popular

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
Success
Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
By Preston ForeMay 20, 2026
1 day ago
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
Workplace Culture
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
By Preston ForeMay 19, 2026
2 days ago
Pay transparency is exposing a bigger problem: Most companies can't explain why they pay what they pay
Workplace Culture
Pay transparency is exposing a bigger problem: Most companies can't explain why they pay what they pay
By Sydney LakeMay 20, 2026
1 day ago
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
Success
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
By Preston ForeMay 21, 2026
9 hours ago
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
Future of Work
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
By Mike Householder and The Associated PressMay 17, 2026
4 days ago
Dr. Bernice King on why companies that walked back DEI were never truly committed: 'If you retreat that quick…that reveals who you really are'
Workplace Culture
Dr. Bernice King on why companies that walked back DEI were never truly committed: 'If you retreat that quick…that reveals who you really are'
By Preston ForeMay 19, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.