Australia Begins New Ransomware Payment Disclosure Rules
ID: 21d273f0-0e7f-576d-a112-2e3a0af25202
STIX ID: report--21d273f0-0e7f-576d-a112-2e3a0af25202
Feed Name: Dark Reading
Date Published: 2025-06-02
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Australia has introduced mandatory ransomware payment reporting rules for businesses with annual turnover of AUS$3 million, requiring reports to the Australian Signals Directorate within 72 hours of making a ransom payment. Reports must include incident impact, ransomware/malware variants, exploited vulnerabilities, ransom demanded and paid, payment methods, and details of negotiations; non-compliance can lead to civil penalties, while public sector organizations are exempt.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
