In force since 30 May 2025Six chapters · sourced

Ransomware payment reporting in Australia

Under the Cyber Security Act 2024 (Cth), eligible Australian businesses must report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours.

Australia became the first country in the world to mandate this. The obligation took effect on 30 May 2025. This page summarises what the law actually requires, sourced from ASD, Home Affairs and Australian legal commentary.

72-hour reporting clock

From the moment payment is made

$19,800 civil penalty

Per contravention

Cyber Security Act 2024 (Cth)

Part 3, in force 30 May 2025

Editorially reviewed
Last reviewed18 May 2026
Sources verified18 May 2026
Effective from30 May 2025
01

The law in plain English

Australia became the first country to mandate ransomware payment reporting.

In force since 30 May 2025.

Part 3 of the Cyber Security Act 2024 (Cth) requires eligible businesses to report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours. The obligation is on the entity that makes (or causes to be made) the payment, including payments made by a third party on the entity's behalf.

01

Source legislation

Cyber Security Act 2024 (Cth), Part 3, Reporting obligations relating to ransomware and cyber extortion. Royal Assent 29 November 2024, reporting obligation commenced 30 May 2025.

Source · Cyber Security Act 2024 (Cth)
02

Reporting window

Reports must be made within 72 hours of making the payment, or of becoming aware that a payment has been made on your behalf.

Source · ASD guidance
03

Reporting channel

Reports are lodged through the ASD ReportCyber portal. The report is shared with the Department of Home Affairs but is not in itself a notification to the OAIC under the Privacy Act.

Source · ASD guidance
04

Penalty for non-reporting

Civil penalty of 60 penalty units. Penalty units increase each year. At time of writing the unit is $330, producing a $19,800 penalty per contravention.

Source · Hogan Lovells analysis
02

Who is covered

The $3 million turnover test, and the critical infrastructure carve-in.

Smaller businesses are not directly required to report.

Two categories of entity are caught: businesses carrying on a business in Australia with annual turnover above $3 million in the previous financial year, and any entity that is a responsible entity of a critical infrastructure asset under the SOCI Act, regardless of turnover.

01

Turnover threshold

Annual turnover above $3 million in the previous financial year. Calculated in the same way as the Privacy Act small business operator test.

Source · Thomson Geer analysis
02

Critical infrastructure entities

Responsible entities for assets covered by the Security of Critical Infrastructure Act 2018 are caught regardless of turnover.

Source · Department of Home Affairs
03

Commonwealth bodies excluded

Commonwealth bodies are excluded from the reporting obligation in Part 3.

Source · Cyber Security Act 2024 (Cth)
04

Below-threshold businesses

SMBs under $3 million turnover have no direct reporting obligation, but may still be obligated indirectly through contracts with larger customers or via the Notifiable Data Breaches scheme if personal information is involved.

Source · ASD guidance
03

What triggers a report

A payment, or a benefit, in response to a cyber incident.

Not just cryptocurrency to a ransomware gang.

The trigger is a payment or other benefit provided in response to a cyber security incident affecting the entity, where the payment or benefit is connected to a demand made by the attacker. This is broader than the conventional understanding of a ransomware payment.

01

Includes cryptocurrency and fiat

The obligation applies regardless of how the payment is made, including cryptocurrency, bank transfer, gift cards, or any other transfer of value.

Source · Thomson Geer analysis
02

Includes non-monetary benefits

The legislation covers 'other benefits' provided in response to an extortion demand. Hand-delivered goods, services, or information could fall within scope.

Source · Cyber Security Act 2024 (Cth)
03

Payments by third parties on your behalf

If a cyber insurer, ransom negotiator, or any other third party pays on the entity's behalf, the reporting obligation still sits with the entity.

Source · ASD guidance
04

Does not require payment to be effective

The obligation arises on payment, not on whether the attacker provided a decryptor or honoured the demand.

Source · Hogan Lovells analysis
04

What must be reported

Twelve categories of information, lodged via ReportCyber.

Not the same form as a Notifiable Data Breach report.

The Cyber Security (Ransomware Payment Reporting) Rules 2025 prescribe the categories of information required. Entities should pre-collect this information as part of incident response so the 72-hour deadline is achievable under stress.

01

Identifying details of the reporting entity

Business name, ABN, contact details, and the role of the person lodging the report.

02

Description of the cyber incident

Nature of the attack, suspected initial access vector, systems affected, and timeline of events.

03

Details of the extortion demand

What was demanded, in what amount and currency, the identity of the threat actor (if known), and any communication channels used.

04

Details of the payment made

Amount, currency or asset, wallet address or transfer reference, date and time, and the party that made the payment.

05

Outcome

Whether the attacker provided a decryptor, returned data, threatened further action, or made follow-on demands.

06

Reporting form

Reports are lodged via the ReportCyber portal at cyber.gov.au. The portal collects the prescribed categories.

Source · ASD ReportCyber
05

Use limitation and protections

Limited use protections sit alongside the reporting obligation.

Reports cannot ordinarily be used directly against the reporting entity.

Recognising that reporting could otherwise be seen as self-incriminating, the Cyber Security Act 2024 includes limited use protections. Information disclosed under Part 3 is restricted in how it can be used by Commonwealth bodies in subsequent proceedings against the reporting entity.

01

Limited use principle

Information disclosed under Part 3 is restricted in its use against the reporting entity in civil proceedings, subject to exceptions for serious offences and proceedings unrelated to the report itself.

Source · Cyber Security Act 2024 (Cth)
02

Does not displace other reporting obligations

Reporting under Part 3 does not satisfy obligations under the Privacy Act (Notifiable Data Breaches), the SOCI Act (mandatory incident reporting), or any other regulatory framework.

Source · Thomson Geer analysis
03

Sanctions, money laundering and terrorism financing law still applies

Reporting a ransomware payment does not absolve the payer of obligations under Australian sanctions law (DFAT Consolidated List) or anti-money-laundering and counter-terrorism-financing law.

Source · Hogan Lovells analysis
04

Internal legal privilege

Reports are administrative disclosures rather than legally privileged communications. Affected entities typically retain external counsel separately to manage privilege over the broader incident.

Source · Thomson Geer analysis
06

Practical preparation

The 72-hour clock is unforgiving. Pre-fill what you can.

Most of the prescribed information can be templated before an incident.

Businesses likely to be in scope (turnover over $3 million, or supply chain to critical infrastructure) should build the ASD report template into their incident response plan and rehearse it as part of any tabletop exercise. Two-thirds of the prescribed fields can be answered before an incident ever occurs.

01

Pre-fill entity identifiers

ABN, legal name, registered office, designated incident response contact and after-hours phone number. None of this changes under stress.

02

Maintain an asset register

Identifying the systems affected during an incident is materially easier when an asset register already exists.

03

Document the decision authority for payment

Who is authorised to approve a ransom payment, in what amount, under what conditions. Most boards have never written this down.

04

Engage a ransom negotiator and counsel in advance

Choosing a negotiator and external counsel during the 72-hour window is far harder than retaining them under a standing arrangement.

05

Run a quarterly tabletop exercise

Walk through a hypothetical incident from detection through to the lodging of an ASD report. Most teams find that 72 hours is genuinely tight.

06

Align with the Notifiable Data Breach process

If personal information is involved, the OAIC notification clock (30 days for assessment, then notify) runs in parallel with the 72-hour ASD clock.

Common questions

Frequently asked about the 72-hour reporting obligation.

From the moment the entity makes the payment, or becomes aware that a payment has been made on its behalf. Not from the moment the ransom demand is received.

If a ransomware decision is in front of you right now

The 72-hour clock is not the moment to start preparing.

If your business has just been affected by a ransomware or cyber extortion incident, prioritise containment and legal advice first. If you would like to build the ASD reporting requirement into your incident response plan before an incident, we can help structure that work.

This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.