• Home
  • Latest
  • Coins2Day 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Techransomware

Why making companies disclose ransomware payouts may be a good idea

By
Kevin T. Dugan
Kevin T. Dugan
Down Arrow Button Icon
By
Kevin T. Dugan
Kevin T. Dugan
Down Arrow Button Icon
July 22, 2021, 7:00 PM ET

It costs just $10 to hold a company hostage. 

That figure, reported by cybersecurity startup Recorded Future, may be why that firm estimates there were 65,000 ransomware attacks worldwide in 2020. Anyone with an Internet connection, a Bitcoin wallet, and some spare change can hire hackers to deploy malicious software to freeze up a target company’s computer systems, lock them out of it, and demand a nearly untraceable payment of millions of dollars in order to get their information back. No technical knowledge, or even a gun, is needed.

The prevalence of these heists has led to a push to take them out of the shadows and require companies to publicly disclose when they’ve been targeted, or even paid the ransom. Lawmakers and federal agencies like the Securities and Exchange Commission are examining what kinds of reporting, if any, it should impose.

There’s a need for “real-time” disclosure when companies are hit with ransomware attacks, Sen. Angus King, (D-ME) said on CNN’s State of the Union last month. “The Colonial Pipeline, my understanding is, it wasn’t reported to the government for four or five days. I think they’d already paid the ransom.”

Updating disclosure laws may not be so easy, however. Each state has its own disclosure requirements, and while some require transparency when data is “inaccessible,” others are tailored more for attacks that steal data, said Anton L. Janik, Jr., a cybersecurity lawyer at Mitchell, Williams, Selig, Gates & Woodyard in Little Rock, Ark. 

While ramping up disclosures could backfire and end up exposing more weaknesses in companies and governments, transparency does have the benefit of informing consumers about how their data is being used, he said. 

“That choice about who owns, controls, and processes your data are important things to discuss,” Janik said. “There’s room for consumers to have knowledge and understanding and ability to gauge cybersecurity practices of the entities that they come into contact with in their daily life.”

Increased disclosure could help tamp down ransomware and create a better understanding of the problem’s scope, according to a recent report by the Institute for Security and Technology, a think tank with connections to the Obama administration and former U.S. Military officials. As it is, states and the federal governments all have different, and sometimes overlapping, rules around disclosing cyber breaches. Equifax, for instance, took more than two months to disclose a hack that ultimately exposed more than 160 million people’s private data. In the end, many companies that pay off ransomware gangs never say so because of the bad publicity that comes with it.

“Updating breach disclosure laws to include a ransom payment disclosure requirement would help increase the understanding of the scope and scale of the crime, allow for better estimates of the societal impact of these payments, and enable better targeting of disruption activities,” the report said. 

More disclosure can also empower law enforcement to cut the flow of ill-gotten cryptocurrencies, the Institute for Security and Technology added. Authorities could issue “freeze letters” to cryptocurrency exchanges, which handle the ransom transactions, so they can stop ransom payments before they’re made, IST recommended. 

SEC regulators are looking at requiring the disclosure under its rules related to so-called ESG, or environmental, social, and governance. For the regulator, cybersecurity largely falls under “social”, said Jina Choi, a partner at law firm Morrison & Foerster, and former director of the Security and Exchange Commission’s San Francisco office.

“Under the federal securities laws, for public companies the legal standard regarding disclosure to its shareholders is materiality – and the SEC has set forth guidance regarding the costs, including reputational damage, that a company can incur if they are breached,” she said. 

Ransomware is one of the thorniest problems on the Internet today — one so pernicious and complex that Homeland Security Department officials have called it a “national threat.” President Joe Biden recently pushed Vladimir Putin to stop attackers — they tend to be situated in Russia or in the ex-Soviet Union — and offered a $10 million reward to anyone who can uncover the identities of these attacks.

The consequences of the problem came into sharp relief earlier this year following the attack of Colonial Pipeline, the company that transports about half of the East Coast’s oil. It paid 75 bitcoins, amounting to $5 million, in order to get its systems back online, but the damage was already done: Gas prices jumped, the airlines rerouted flights, and the federal government had to warn people not to hoard gas in plastic bags. 

The idea of requiring companies to disclose attacks does have its critics, however. Nick Merrill, a postdoctoral fellow at director of the Daylight Security Research Lab at the University of California at Berkeley’s Center for Long-Term Cybersecurity, said he was concerned that ramping up disclosure, without strengthening other security measures, may not be enough. 

“It’s tempting because it’s simple. And the real answers are much bigger and much broader than that,” Miller said. “I just worry that it’s a box checking exercise. And once it’s done, where would we be?”

One problem, he added, is that hackers could change their tactics so their attacks wouldn’t qualify as “ransomware”. He cited an attack on the Washington D.C. Metro Police that threatened to out its confidential informants, which he called “extortionware.” 

Another potential problem is rooted in ransomware’s ubiquity. Miller compared it to European data disclosure requirements on just about every web page — which users typically ignore. “These reporting requirements can go awry to such a degree that people just learn to ignore them,” he said, “and that would be worse than where we are now.”

But even informing consumers about some of a breach’s scope could better inform consumers. 

“I don’t think you need to disclose the dollar value of a hack, but you can disclose that there was a hack,” Janik said. “You could disclose the size of a hack — this is 600,000 patient records. I think those parameters are helpful to a customer in the marketplace to evaluate, ‘where do I feel comfortable?’”

 

Subscribe to Coins2Day Daily to get essential business stories straight to your inbox each morning.

About the Author
By Kevin T. Dugan
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

Latest in Tech

AsiaChina
What global executives need to ask about China in 2026
By Joe Ngai and Jeongmin SeongJanuary 11, 2026
9 hours ago
A smartphone displaying the app icon for Anthropic AI chatbot Claude displayed against a backdrop that also says "Claude."
AIAnthropic
Anthropic unveils Claude for Healthcare, expands life science features, and partners with HealthEx to let users connect medical records
By Jeremy KahnJanuary 11, 2026
10 hours ago
Investingtech stocks
Magnificent 7’s stock market dominance shows signs of cracking
By Jeran Wittenstein, Ryan Vlastelica and BloombergJanuary 11, 2026
10 hours ago
Eric Vaughan
AILayoffs
This CEO laid off nearly 80% of his staff because they refused to adopt AI fast enough. 2 years later, he says he’d do it again
By Nick LichtenbergJanuary 11, 2026
13 hours ago
Elon Musk, wearing a suit, puts his knuckles together and looks upward.
TechElon Musk
Elon Musk asked people to upload their medical data to X so his AI company could learn to interpret MRIs and CT scans
By Sasha RogelbergJanuary 11, 2026
14 hours ago
RetailRetail
Walmart teams with Alphabet for AI-assisted shopping on Gemini
By Jaewon Kang and BloombergJanuary 11, 2026
16 hours ago

Most Popular

placeholder alt text
Economy
Trump may be raising your taxes with his tariffs but he could actually cut inflation with them, too, SF Fed says
By Jake AngeloJanuary 6, 2026
5 days ago
placeholder alt text
AI
This CEO laid off nearly 80% of his staff because they refused to adopt AI fast enough. 2 years later, he says he'd do it again
By Nick LichtenbergJanuary 11, 2026
13 hours ago
placeholder alt text
Economy
As U.S. debt soars past $38 trillion, the flood of corporate bonds is a growing threat to the Treasury supply
By Jason MaJanuary 10, 2026
2 days ago
placeholder alt text
Economy
A Supreme Court ruling that strikes down Trump's tariffs would be the fastest way to revive the stalling job market, top economist says
By Jason MaJanuary 11, 2026
11 hours ago
placeholder alt text
Health
Bill Gates warns the world is going 'backwards' and gives 5-year deadline before we enter a new Dark Age
By Eleanor PringleJanuary 9, 2026
3 days ago
placeholder alt text
Success
Gen Z are arriving to college unable to even read a sentence—professors warn it could lead to a generation of anxious and lonely graduates
By Preston ForeJanuary 9, 2026
3 days ago

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.