Skip to content

Regulation

Ransomware Negotiation Triggers Four Distinct Legal Liabilities

By Editorial TeamUpdated Jul 24, 2026
Authority
Office of Foreign Assets Control (OFAC)
Rule type
regulation
Jurisdiction scope
US federal
Source text
Read primary rule text ↗

This article is legal-risk analysis, not legal advice. It is current as of July 24, 2026, and should be checked against primary materials before use in an active incident. The SEC discussion rests on published interpretations summarized by Morgan Lewis; the DOJ and D&O discussion relies on Skadden’s January 2026 enforcement overview; Delaware payment-authority analysis relies partly on a 2022 Data Protection Report article that predates the 2025–2026 enforcement surge; and the OFAC discussion should be verified against the original Treasury advisory PDF because the analysis relies on authoritative secondary summaries from Hunton Andrews Kurth and Covington’s Inside Privacy rather than a directly reviewed Treasury PDF.[1][2][3][4][5]

The legally dangerous moment in a ransomware incident is not the wire transfer. It starts earlier, when someone says the company should “just open a channel” and see what the attacker wants. From that point forward, the company is creating evidence: who approved contact, what screening was done, whether law enforcement was called, whether disclosure counsel assessed materiality, whether the insurer’s position was treated as advice or merely coverage input, and whether the board record shows oversight rather than surprise.

That is the practical answer for companies: ransomware negotiation legal risk is not one risk. It is at least four. OFAC asks whether a sanctioned person or jurisdiction was facilitated. DOJ asks whether the company or its agents crossed from response into criminal conduct or unlawful facilitation. The SEC asks whether the incident, payment, insurance, and related attacks are material to investors. Shareholders later ask whether officers and directors followed a defensible process before exposing the company to those risks.

Ransomware payment decision splitting into four divergent legal outcomes

The Four Liability Fronts Before Payment Is Even Authorized

FrontTriggerLegal standardDecision-maker at riskRecord that matters before negotiationWhy payment does not close the issue
OFAC sanctionsA payment, facilitation, or service involving a sanctioned person, group, jurisdiction, or blocked propertyStrict civil liability may apply even if the victim did not know of the sanctions nexus; mitigation depends on pre-existing compliance, cybersecurity practices, law-enforcement reporting, and contemporaneous diligence.[3][4][5]The paying company, officers involved in authorization, insurers, negotiators, forensic vendors, and other facilitatorsSanctions screening, wallet and counterparty diligence, escalation notes, law-enforcement contact, cyber controls, and evidence that the process existed before the crisisA paid ransom can still be an apparent sanctions violation; later explanations do not erase the underlying transaction.
DOJ criminal enforcementConduct that prosecutors view as hacking, extortion, unlawful facilitation, false statements, obstruction, money laundering, or knowing support to criminal activityCriminal exposure depends on conduct and intent; the December 2025 indictment of two employees of a major ransomware negotiation vendor shows scrutiny of the facilitation chain, not only attackers.[1]Corporate actors, individual employees, vendors, negotiators, and anyone directing or concealing conductEngagement letters, vendor instructions, communications with attackers, preservation steps, law-enforcement outreach, and internal approvalsA successful decryption or business restoration does not answer whether the method of facilitation created criminal exposure.
SEC disclosureA cyber incident that may be material to investors, including ransom payment facts, insurance recovery, or serial related attacksThe June 2024 C&DIs state that payment does not eliminate the Form 8-K Item 1.05 materiality analysis, insurance coverage does not bar materiality, and related attacks may need collective assessment.[2]Public-company management, disclosure committee members, certifying officers, and directors overseeing disclosure controlsMateriality analysis, timing record, incident facts known at each point, insurance treatment, business impact, and related-incident mappingPaying may reduce operational disruption, but it does not settle the investor-disclosure question.
Fiduciary and shareholder exposureA challenged payment decision, failure to oversee cyber risk, weak sanctions diligence, or post-incident disclosure failureDelaware analysis indicates senior management may hold payment authority unless the board has reserved it in an incident response plan, while directors can still face oversight, bad-faith, or waste theories if the process is inadequate.[1][6]Directors, senior officers, and in some cases board committees responsible for cyber and compliance oversightBoard-approved incident response plan, authority matrix, sanctions and disclosure escalation protocol, minutes, briefings, and dissent or approval recordEven if operations resume, shareholders can challenge whether the company exposed itself to avoidable regulatory and enforcement risk.

The table is deliberately procedural. In an actual incident, executives often want a binary answer: can we pay or not? The better first answer is narrower: no one is ready to make that decision until the company knows which legal clocks have started and which record each regulator or plaintiff will later read.

OFAC Is the Strict-Liability Trap

OFAC is the front that most directly changes the payment calculus because it does not wait for proof that the victim knew it was dealing with a sanctioned actor. The advisory summarized by Hunton Andrews Kurth and Covington’s Inside Privacy treats companies that facilitate ransomware payments as exposed to civil sanctions liability even where the sanctions nexus was unknown at the time.[4][5]

That strict-liability feature is not a technicality. It removes the comfort of saying, after the fact, that the company was under pressure, the wallet looked clean, the negotiator had a standard process, or the attacker refused to identify itself. Those facts may matter to mitigation. They do not make the legal exposure disappear.

The 2025 enforcement environment makes the distinction harder to ignore. Corporate Compliance Insights reported that OFAC issued 14 public enforcement actions in 2025 totaling $266 million; the same summary identifies pre-existing sanctions compliance, CISA-aligned cybersecurity practices, and contemporaneous law-enforcement reporting as mitigating factors rather than complete defenses.[3]

For a company deciding whether to negotiate, the practical question is therefore not “can our vendor screen the wallet?” It is whether the company can show, before and during contact, a sanctions diligence process that belongs to the company. That record should identify who performed screening, what identifiers were available, what was inconclusive, who escalated uncertainty, whether law enforcement was notified, and whether the company’s pre-incident compliance program had any ransomware-payment path at all.

The uncomfortable part is that an incident team may not have much information. Ransomware actors use aliases, intermediaries, wallet rotation, and pressure tactics. OFAC’s problem for the victim is that incomplete attribution does not equal legal clearance. Incomplete attribution is a fact to document, test, and escalate.

  • Who authorized any communication with the attacker or intermediary.
  • What sanctions lists, wallet intelligence, jurisdictional indicators, and threat-actor identifiers were checked.
  • What the company did when screening produced uncertainty rather than a clean answer.
  • When law enforcement was contacted and what information was provided.
  • Whether the payment path was controlled by company counsel and compliance, not only by an insurer, broker, or negotiator.

That last point matters because OFAC risk is not outsourced merely because the company retained a specialist. A vendor may collect information, negotiate, or transmit instructions. The company still needs a record showing that it made a legally informed decision rather than purchased a process and hoped it would later be described as diligence.

The DOJ Question Is No Longer Limited to the Attacker

DOJ risk is different from OFAC risk. It is not the same strict-liability framework, and it should not be collapsed into a generic warning that all negotiation is criminal. The sharper point from the current research is that prosecutors are looking beyond the attacker to the payment-facilitation chain.

Skadden’s January 2026 analysis reports that in December 2025 DOJ indicted two employees of a major ransomware negotiation vendor, charging them with computer hacking and extortion for their role in facilitating payments.[1] That is not proof that ordinary negotiators are now presumptive targets. It is proof that the “we used a vendor” answer is no longer a complete risk answer.

The indictment changes the internal call in a practical way. A general counsel cannot treat the negotiator as a liability shield while the business treats the negotiator as the person who will make the problem go away. The vendor’s mandate, communications, compensation structure, and authority limits become part of the company’s risk record.

Corporate negotiation table with four legal actors placing documents around a ransomware laptop

That record should make clear whether the vendor was authorized only to communicate and gather information, whether it could suggest payment terms, whether it could arrange cryptocurrency acquisition or transfer, and who inside the company had final authority. If a vendor proposes tactics that change the legal character of the response, the company needs contemporaneous legal review, not a post-incident reconstruction.

The DOJ and OFAC standards are diverging here. OFAC asks whether a prohibited transaction occurred and whether mitigation exists. DOJ asks what people did, what they intended, and whether their conduct crossed criminal lines. A single payment file may need to answer both, but the answers will not be identical.

SEC Materiality Survives the Ransom Receipt

For public companies, payment can create a false sense of closure. The systems may come back. The attacker may provide a decryption tool. The insurer may indicate coverage. None of that answers whether the cyber incident is material under the securities laws.

Morgan Lewis’s summary of the SEC’s June 2024 Compliance and Disclosure Interpretations, including C&DIs 104B.05 through 104B.09, identifies three points that matter in ransom situations: payment does not eliminate the Form 8-K Item 1.05 materiality determination; insurance coverage of the payment does not itself make the incident immaterial; and serial related attacks may need to be assessed collectively rather than as isolated events.[2]

Those interpretations should be read as a warning against payment-as-resolution thinking. A ransom payment might reduce one category of operational harm and increase another category of investor-relevant fact. A covered payment may still affect liquidity, operations, controls, legal exposure, customer relationships, or future risk. A series of smaller attacks may look immaterial one by one and material when viewed as a pattern.

Fact after or during negotiationSEC question it raises
The company pays the ransom and receives a decryption key.Did the incident nevertheless have, or is it reasonably likely to have, a material impact?
Insurance covers all or part of the ransom payment.Does coverage reduce financial exposure without eliminating operational, legal, reputational, or control-related materiality?
The company experiences related intrusions or repeated extortion attempts.Should the incidents be assessed collectively for materiality?
The company delays disclosure while facts are still developing.Does the record show a reasoned materiality process based on known information at each point in time?

The SEC file should not be built after the cyber team announces restoration. It should begin while the company is still deciding whether to negotiate. The disclosure committee, securities counsel, incident responders, finance, and management need a shared chronology of what is known, what is suspected, what is still unknown, and why the company reached each materiality judgment when it did.

That does not mean every ransomware event is material. It means the company should be able to show the analysis rather than point to payment, insurance, or temporary restoration as a substitute for analysis.

Fiduciary Exposure Follows the Process

The fiduciary-duty issue is not a separate morality play about whether directors should ever allow payment. It is the governance consequence of the OFAC, DOJ, and SEC questions. If the company cannot show who had authority, what information was reviewed, and whether legal risk was escalated, the board record will look improvised even if the payment restored operations.

The older Delaware-law analysis summarized by Data Protection Report is useful because it starts with authority. Unless the board has expressly reserved the ransom-payment decision in a board-approved incident response plan, senior management may hold authority to decide whether to pay.[6] That allocation may be operationally sensible. It is also why the incident response plan matters before the incident.

If the board wants to reserve payment authority, the plan should say so. If management will hold payment authority, the plan should identify escalation thresholds, sanctions-review requirements, law-enforcement notification expectations, securities-disclosure coordination, and board-notification triggers. Ambiguity in a crisis tends to produce two bad records at once: executives acting as if they have authority and directors later appearing not to have overseen the risk.

Skadden’s 2026 analysis and Moody’s 2025 D&O liability context, as reflected in the research materials, place that governance question in a harsher enforcement environment than the 2022 authority analysis originally addressed.[1] A payment authorized without documented sanctions screening can become more than a questionable business judgment. It can be framed later as conscious disregard of a known compliance risk, waste, or bad faith.

Insurance does not solve that governance problem. The available research notes that D&O policies typically exclude fraud, criminal conduct, and regulatory fines—the same categories most likely to matter if a payment violates sanctions law or triggers enforcement. Aon’s recommendation, as referenced in the Skadden context, is a side-by-side cyber and D&O policy audit before an incident, not a coverage search during one.[1]

CIRCIA Adds Another Clock, but Not the Whole Architecture

CIRCIA belongs in the pre-negotiation analysis, but it should not crowd out the four primary liability fronts. For covered critical infrastructure entities, the reporting regime creates an additional clock that may run alongside ransom discussions, law-enforcement engagement, sanctions review, and securities analysis.

The DWT Blog summary states that CISA’s final rule has been delayed to May 2026, separately notes four town halls in June 2026, and says covered entities will be required to report covered cyber incidents within 72 hours and ransom payments within 24 hours.[7] The timing in that summary should be checked against the final regulatory record before publication or incident use, because the dates are consequential and the current research captures a secondary description.

The key point for incident governance is limited: paying a ransom does not discharge the incident-reporting obligation. A company that treats payment as the endpoint may miss the reporting record it needed to build while negotiation was still underway.

The Commercial Case for Paying Is Also Weaker Than It Looks

Legal risk does not require proof that paying is commercially irrational. A company may face an operational emergency in which negotiation looks like the least bad option. Still, the commercial premise behind payment has become less comfortable.

Cybersecurity Essential’s 2026 discussion of ransomware negotiation reports Coveware data showing payment rates dropping to approximately 20% in Q4 2025, described as a historic low; it also states that less than half of paying organizations recovered uncorrupted data.[8] Those figures should be treated as payment-efficacy data, not legal proof. They matter because they weaken the business-side argument that legal risk is being accepted in exchange for a reliable operational fix.

If payment is no longer a reliable restoration path, the burden on the legal record increases. The company is not merely choosing between downtime and money. It may be accepting sanctions exposure, criminal-facilitation scrutiny, disclosure obligations, shareholder claims, and insurance uncertainty for a result that may not restore clean data.

What Must Exist Before Negotiation Begins

A defensible pre-negotiation threshold is narrower than a full incident-response playbook. Before treating ransom as a commercial option, the company should be able to document six things.

  • Sanctions diligence: the company’s own OFAC screening path, uncertainty escalation, and contemporaneous record of what was known before any payment-related step.
  • Law-enforcement engagement: when law enforcement was contacted, by whom, with what information, and how that contact affected the decision process.
  • SEC materiality analysis: a dated record for public-company disclosure judgments, including payment, insurance, operational impact, and related incidents.
  • Payment authority: whether management or the board has authority under the incident response plan, and what approval thresholds apply.
  • Board oversight: evidence that directors received the right risk information at the right time, rather than a ratification request after the decisive steps were taken.
  • Insurance limitations: an understanding of what cyber and D&O policies may cover, exclude, or refuse to advance if sanctions, criminal conduct, regulatory fines, or fraud exclusions are implicated.

None of this produces a universal “never pay” rule. It produces a more disciplined threshold. Ransomware negotiation cannot be evaluated as a single operational decision until the company has satisfied legal regimes that ask different questions, protect different interests, and punish different failures in the record.

References

  1. Ransomware: What You Need to Know as Attacks, Regulation and Enforcement Increase, Skadden, January 2026.
  2. SEC Releases Interpretations on Ransomware Attacks and Payment Disclosures, Morgan Lewis, July 2024.
  3. The State of OFAC Sanctions Enforcement in 2025-26, Corporate Compliance Insights.
  4. OFAC's Updated Advisory on Ransomware Payments, Hunton Andrews Kurth.
  5. OFAC Issues Updated Guidance on Ransomware Payments, Inside Privacy / Covington.
  6. Who Gets to Decide to Pay the Ransom in a Ransomware Attack?, Data Protection Report, 2022.
  7. CISA Delays Cyber Incident Reporting Rules Until May 2026, DWT Blog, September 2025.
  8. Ransomware Negotiation in 2026, Cybersecurity Essential, 2026.

Operationalizing workflow

No workflow has been explicitly linked to this obligation yet. See Workflows generally.

Illustrative cases

No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.

← Back to Regulation

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →