Skip to content
    August 23, 2026| Top Floor Team| 10 min read

    Should You Pay the Ransom? The Legal and Practical Answer

    Paying a ransomware ransom is not, in itself, generally illegal for a US company, but the sanctions exposure is strict liability, which is the part that catches people. OFAC's updated ransomware advisory of September 21, 2021 states that it "may impose civil penalties for sanctions violations based on strict liability, meaning that a person subject to U.S. jurisdiction may be held civilly liable even if such person did not know or have reason to know that it was engaging in a transaction that was prohibited under sanctions laws and regulations administered by OFAC." The same advisory says the US government "strongly discourages all private companies and citizens from paying ransom or extortion demands." Here is the contrarian framing: the payment question is not a decryption question. Paying buys a decryptor of uncertain quality and a criminal's promise about a copy of your data, and it changes none of your notification obligations, so a company with intact backups can still face a payment decision, and a company with no backups can still be right to refuse.

    This article covers what the law actually says, what payment does and does not buy, what the survey data says once you read its denominators, and the four facts that settle the decision in practice.

    Key takeaways

    • OFAC sanctions liability is strict. Not knowing the recipient was designated is not a defense, which is why the sanctions check happens before the transfer and through counsel, not after.
    • License applications for ransomware payments are reviewed "on a case-by-case basis with a presumption of denial," so a license is not a realistic mid-incident plan.
    • OFAC treats a company's self-initiated, complete report of a ransomware attack to law enforcement, made as soon as possible after discovery, as a voluntary self-disclosure and "a significant mitigating factor." Reporting early is free and it moves the enforcement posture.
    • Payment rates are falling. In the Sophos State of Ransomware 2026 survey, 48 percent of organizations whose data was encrypted paid and got data back, the lowest rate in three years, while 66 percent recovered from backups.
    • Payment does not delete stolen data, does not stop notification clocks, and does not restore systems by itself. It buys a decryption tool, and decryption is only one leg of recovery.

    What the law actually says

    There is no general federal statute making ransom payment a crime. What exists is sanctions law, and it bites differently than most executives expect.

    OFAC administers the sanctions programs that list designated persons and blocked entities, and several prolific ransomware actors and the infrastructure they use have been designated. If a payment reaches one of them, the payer has a problem, and the advisory's strict-liability language means the payer's ignorance of who was on the other end does not resolve it. Facilitators are in scope too: the advisory notes that companies that facilitate payments on behalf of victims, "including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response," may risk violating OFAC regulations. That is why your response firm and your carrier will both want counsel driving the decision. It is their exposure as well as yours.

    Two further points from the advisory are worth knowing before an incident rather than during one. Licensing is not an escape hatch: applications involving ransomware payments "will continue to be reviewed by OFAC on a case-by-case basis with a presumption of denial." And cooperation is weighted. OFAC says it will consider a company's "self-initiated and complete report of a ransomware attack to law enforcement or other relevant U.S. government agencies, such as CISA," made as soon as possible after discovery, "to be a voluntary self-disclosure and a significant mitigating factor," and it says full and ongoing cooperation during and after an attack is also a significant mitigating factor. It goes further: OFAC would be more likely to resolve apparent violations with a non-public response such as a No Action Letter or Cautionary Letter where the affected party took those steps.

    None of that is legal advice, and we are a security consultancy rather than a law firm. The operational translation is narrow and reliable: counsel runs the payment decision, the sanctions check happens before the transfer, and the report to law enforcement happens early because it is free and it counts.

    What paying actually buys

    A decryption tool. That is the whole product.

    It does not buy deletion of exfiltrated data, because there is no mechanism by which you could verify deletion and no reason to believe a criminal enterprise deletes its leverage. It does not buy silence, because the same data is frequently monetized twice. It does not stop your regulatory clocks, which run on discovery, awareness or materiality determination depending on the regime, not on whether you settled with the attacker. And it does not restore your environment: decryption is slow, often partial, and it runs alongside the rebuild you were going to do anyway, because a network the attacker held has to be rebuilt regardless of who holds the keys.

    There is one honest case for payment, and it deserves stating plainly rather than being argued away. When backups are gone or compromised, when the encrypted data is genuinely unrecoverable and genuinely necessary to operate, and when counsel has cleared the sanctions position, payment can be the least-bad option. Companies in that position are not being weak. They are being hostage.

    The numbers, and what their denominators mean

    As of August 2026, the most recent public survey data on payment behavior is the Sophos State of Ransomware 2026 report, drawn from 2,158 IT and cybersecurity leaders across 17 countries at organizations between 100 and 5,000 employees, with responses collected from January to March 2026. Sophos sells endpoint and managed detection products, so read it as informed and interested rather than neutral. Its finding: among organizations whose data was encrypted, 48 percent paid the ransom and got data back, the lowest figure in three years, while 66 percent recovered using backups, up from 54 percent the year before.

    Now the part that stops two honest sources from looking like a contradiction. That 48 percent is measured against organizations whose data was actually encrypted, not against everyone hit by ransomware, and it is a count of organizations that paid and recovered data rather than everyone who transferred money. Our first 24 hours after ransomware guide cites Verizon's DBIR on the same question and reports a different figure, because the DBIR counts a different population. Neither is wrong. If you see two payment-rate numbers quoted at you in the same meeting, ask what each one divided by before you decide which to believe.

    What the two agree on is the direction of travel, and it is the useful part: the share of victims paying is falling, and the share recovering from backups is rising. Refusal is now the ordinary outcome rather than the brave one, which changes the negotiating dynamic for everyone who comes after you.

    The four facts that decide it

    Backup integrity, verified by a restore. Not a green checkmark in the console. Restore one meaningful system into an isolated environment and confirm the data is intact and recent enough to matter. Check the restore point against the intrusion timeline as well, because attackers commonly dwell for weeks and a backup from before detonation may still contain their tooling.

    Sanctions exposure. Who is the actor, what variant is this, and is there a designation in the chain? Counsel and your response firm run this, and it is the reason no money moves on day one.

    Whether data left. If the attacker holds a copy of your data, decryption solves the availability problem and leaves the disclosure problem untouched. Your notification analysis proceeds identically whether or not you pay, which means paying to make a breach go away is buying the wrong thing.

    Your carrier's position. Most policies condition coverage on prompt notice and require consent before a payment, and many route you to panel counsel who will drive the decision. Calling the carrier before you engage vendors is the sequencing that protects reimbursement.

    When we would tell you not to hire us

    Two situations, stated against our own interest.

    If your cyber policy has a panel and we are not on it, use the panel firm. Payment decisions run through breach counsel, counsel is usually assigned from the panel, and paying out of pocket for an off-panel responder rarely pays for itself. We would rather work alongside the panel on recovery and the compliance aftermath than sit in a role your carrier will not reimburse.

    And if the honest answer is that your backups are tested, your data inventory is clean, and your leadership has already decided it will not pay under any circumstance, you do not need a payment-decision engagement. You need the recovery drill. Spend the money there.

    Where Top Floor fits

    Our incident response work sits on the technical half of this decision: establishing whether backups are viable, whether data actually left, and what the realistic recovery path looks like without a decryptor, so that the payment conversation happens against facts rather than against fear. Digital forensics produces the exfiltration finding that decides whether your notification analysis proceeds regardless of payment. The legal position, the sanctions check, and the payment itself belong to counsel and to specialist negotiators, and we will say so in the room.

    How to decide this week

    1. Test-restore one production system into an isolated environment and time it. That number is your real leverage in a payment conversation.

    2. Read your cyber policy for three things: the notice deadline, whether payment requires consent, and whether counsel and responders come from a panel.

    3. Write the sanctions step into your incident response plan explicitly, including who calls counsel and at what hour.

    4. Decide, in peacetime, who has authority to approve a payment and what the ceiling is. A decision made under duress by whoever is in the room is the worst version of this.

    5. Add the law enforcement report to your first-day checklist. It costs nothing, and OFAC treats an early self-initiated report as a significant mitigating factor.

    Frequently asked questions

    Is it illegal to pay a ransomware ransom in the United States?

    There is no general federal law making payment itself a crime, but sanctions law creates real exposure and OFAC applies strict liability, meaning a payer can be held civilly liable even without knowing that the recipient was sanctioned. The practical consequence is procedural: the sanctions check runs before any transfer, counsel directs the decision, and firms that facilitate payments carry their own exposure, which is why your response firm and your carrier will both insist on that sequence. Applying for a license is not a workable alternative mid-incident, because OFAC reviews such applications with a presumption of denial.

    Does paying the ransom mean the stolen data gets deleted?

    No, and you should treat any assurance to the contrary as worthless. Payment buys a decryption tool; deletion of an exfiltrated copy cannot be verified, and the data retains value to the attacker whether or not you paid. What follows for notification does not turn on whether you settled, and it does not turn only on whether data left. Each regime runs from its own trigger: HIPAA from discovery of an impermissible acquisition, access, use or disclosure of protected health information, which is presumed to be a breach unless a risk assessment shows a low probability of compromise; GDPR from awareness that a personal data breach occurred, a definition that reaches destruction, loss and alteration as well as unauthorized access or disclosure; the SEC from a materiality determination; and state statutes and customer contracts from triggers of their own. So counsel starts the regime-by-regime trigger analysis whether or not exfiltration is ever confirmed, and our breach notification deadlines guide sets out which event starts which clock. Plan on the assumption that anything exfiltrated is permanently outside your control.

    Should we tell law enforcement if we pay?

    Yes, and early. OFAC states that it will treat a company's self-initiated and complete report of a ransomware attack to law enforcement or another relevant agency, made as soon as possible after discovery, as a voluntary self-disclosure and a significant mitigating factor in any enforcement response, and that full and ongoing cooperation counts the same way. It also indicates it is more likely to resolve apparent violations with a non-public response where the affected party reported promptly and cooperated. Reporting is one of the few moves in an incident that costs nothing and improves your position.

    Will cyber insurance cover a ransom payment?

    Often, subject to conditions, and the conditions are where claims go wrong. Most policies require prompt notice, and many require the carrier's consent before a payment is made, so a payment arranged before the carrier is notified may not be reimbursed. Carriers also commonly route you to panel breach counsel who run the sanctions and payment analysis. Read the notice deadline, the consent language, and the panel requirements now rather than during the incident, because all three are decided in the first hours.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.