Ransomware payment reporting in Australia
Under the Cyber Security Act 2024 (Cth), eligible Australian businesses must report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours.
Australia became the first country in the world to mandate this. The obligation took effect on 30 May 2025. This page summarises what the law actually requires, sourced from ASD, Home Affairs and Australian legal commentary.
72-hour reporting clock
From the moment payment is made
$19,800 civil penalty
Per contravention
Cyber Security Act 2024 (Cth)
Part 3, in force 30 May 2025
The law in plain English
Australia became the first country to mandate ransomware payment reporting.
In force since 30 May 2025.
Part 3 of the Cyber Security Act 2024 (Cth) requires eligible businesses to report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours. The obligation is on the entity that makes (or causes to be made) the payment, including payments made by a third party on the entity's behalf.
Source legislation
Cyber Security Act 2024 (Cth), Part 3, Reporting obligations relating to ransomware and cyber extortion. Royal Assent 29 November 2024, reporting obligation commenced 30 May 2025.
Source · Cyber Security Act 2024 (Cth)Reporting window
Reports must be made within 72 hours of making the payment, or of becoming aware that a payment has been made on your behalf.
Source · ASD guidanceReporting channel
Reports are lodged through the ASD ReportCyber portal. The report is shared with the Department of Home Affairs but is not in itself a notification to the OAIC under the Privacy Act.
Source · ASD guidancePenalty for non-reporting
Civil penalty of 60 penalty units. Penalty units increase each year. At time of writing the unit is $330, producing a $19,800 penalty per contravention.
Source · Hogan Lovells analysisWho is covered
The $3 million turnover test, and the critical infrastructure carve-in.
Smaller businesses are not directly required to report.
Two categories of entity are caught: businesses carrying on a business in Australia with annual turnover above $3 million in the previous financial year, and any entity that is a responsible entity of a critical infrastructure asset under the SOCI Act, regardless of turnover.
Turnover threshold
Annual turnover above $3 million in the previous financial year. Calculated in the same way as the Privacy Act small business operator test.
Source · Thomson Geer analysisCritical infrastructure entities
Responsible entities for assets covered by the Security of Critical Infrastructure Act 2018 are caught regardless of turnover.
Source · Department of Home AffairsCommonwealth bodies excluded
Commonwealth bodies are excluded from the reporting obligation in Part 3.
Source · Cyber Security Act 2024 (Cth)Below-threshold businesses
SMBs under $3 million turnover have no direct reporting obligation, but may still be obligated indirectly through contracts with larger customers or via the Notifiable Data Breaches scheme if personal information is involved.
Source · ASD guidanceWhat triggers a report
A payment, or a benefit, in response to a cyber incident.
Not just cryptocurrency to a ransomware gang.
The trigger is a payment or other benefit provided in response to a cyber security incident affecting the entity, where the payment or benefit is connected to a demand made by the attacker. This is broader than the conventional understanding of a ransomware payment.
Includes cryptocurrency and fiat
The obligation applies regardless of how the payment is made, including cryptocurrency, bank transfer, gift cards, or any other transfer of value.
Source · Thomson Geer analysisIncludes non-monetary benefits
The legislation covers 'other benefits' provided in response to an extortion demand. Hand-delivered goods, services, or information could fall within scope.
Source · Cyber Security Act 2024 (Cth)Payments by third parties on your behalf
If a cyber insurer, ransom negotiator, or any other third party pays on the entity's behalf, the reporting obligation still sits with the entity.
Source · ASD guidanceDoes not require payment to be effective
The obligation arises on payment, not on whether the attacker provided a decryptor or honoured the demand.
Source · Hogan Lovells analysisWhat must be reported
Twelve categories of information, lodged via ReportCyber.
Not the same form as a Notifiable Data Breach report.
The Cyber Security (Ransomware Payment Reporting) Rules 2025 prescribe the categories of information required. Entities should pre-collect this information as part of incident response so the 72-hour deadline is achievable under stress.
Identifying details of the reporting entity
Business name, ABN, contact details, and the role of the person lodging the report.
Description of the cyber incident
Nature of the attack, suspected initial access vector, systems affected, and timeline of events.
Details of the extortion demand
What was demanded, in what amount and currency, the identity of the threat actor (if known), and any communication channels used.
Details of the payment made
Amount, currency or asset, wallet address or transfer reference, date and time, and the party that made the payment.
Outcome
Whether the attacker provided a decryptor, returned data, threatened further action, or made follow-on demands.
Reporting form
Reports are lodged via the ReportCyber portal at cyber.gov.au. The portal collects the prescribed categories.
Source · ASD ReportCyberUse limitation and protections
Limited use protections sit alongside the reporting obligation.
Reports cannot ordinarily be used directly against the reporting entity.
Recognising that reporting could otherwise be seen as self-incriminating, the Cyber Security Act 2024 includes limited use protections. Information disclosed under Part 3 is restricted in how it can be used by Commonwealth bodies in subsequent proceedings against the reporting entity.
Limited use principle
Information disclosed under Part 3 is restricted in its use against the reporting entity in civil proceedings, subject to exceptions for serious offences and proceedings unrelated to the report itself.
Source · Cyber Security Act 2024 (Cth)Does not displace other reporting obligations
Reporting under Part 3 does not satisfy obligations under the Privacy Act (Notifiable Data Breaches), the SOCI Act (mandatory incident reporting), or any other regulatory framework.
Source · Thomson Geer analysisSanctions, money laundering and terrorism financing law still applies
Reporting a ransomware payment does not absolve the payer of obligations under Australian sanctions law (DFAT Consolidated List) or anti-money-laundering and counter-terrorism-financing law.
Source · Hogan Lovells analysisInternal legal privilege
Reports are administrative disclosures rather than legally privileged communications. Affected entities typically retain external counsel separately to manage privilege over the broader incident.
Source · Thomson Geer analysisPractical preparation
The 72-hour clock is unforgiving. Pre-fill what you can.
Most of the prescribed information can be templated before an incident.
Businesses likely to be in scope (turnover over $3 million, or supply chain to critical infrastructure) should build the ASD report template into their incident response plan and rehearse it as part of any tabletop exercise. Two-thirds of the prescribed fields can be answered before an incident ever occurs.
Pre-fill entity identifiers
ABN, legal name, registered office, designated incident response contact and after-hours phone number. None of this changes under stress.
Maintain an asset register
Identifying the systems affected during an incident is materially easier when an asset register already exists.
Document the decision authority for payment
Who is authorised to approve a ransom payment, in what amount, under what conditions. Most boards have never written this down.
Engage a ransom negotiator and counsel in advance
Choosing a negotiator and external counsel during the 72-hour window is far harder than retaining them under a standing arrangement.
Run a quarterly tabletop exercise
Walk through a hypothetical incident from detection through to the lodging of an ASD report. Most teams find that 72 hours is genuinely tight.
Align with the Notifiable Data Breach process
If personal information is involved, the OAIC notification clock (30 days for assessment, then notify) runs in parallel with the 72-hour ASD clock.
Sources referenced
- 01
Cyber Security Act 2024 (Cth), Part 3 : Reporting obligations
Federal Register of LegislationRoyal Assent 29 Nov 2024www.legislation.gov.au - 02
Mandatory ransomware and cyber extortion payment reporting now in force
Australian Signals Directorate30 May 2025www.cyber.gov.au - 03
Cyber security legislation
Department of Home Affairswww.homeaffairs.gov.au - 04
Australia's mandatory ransomware payment reporting rules: what your organisation needs to know
Thomson Geerwww.tglaw.com.au - 05
Australia mandates first-of-its-kind reporting of ransomware payments
Hogan Lovellswww.hoganlovells.com
This page summarises publicly available Australian government, regulator and legal sources. It is general information, not legal advice.
Common questions
Frequently asked about the 72-hour reporting obligation.
From the moment the entity makes the payment, or becomes aware that a payment has been made on its behalf. Not from the moment the ransom demand is received.
Related in this cluster
Other operational and regulatory pages for Australian businesses.
If a ransomware decision is in front of you right now
The 72-hour clock is not the moment to start preparing.
If your business has just been affected by a ransomware or cyber extortion incident, prioritise containment and legal advice first. If you would like to build the ASD reporting requirement into your incident response plan before an incident, we can help structure that work.
This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.

Remote Support