Cybercrime

Ransomware: Are ransom payments tax-deductible in Austria?

Ransomware attacks are increasingly hitting Austrian companies as well. Systems are encrypted, sensitive data is exfiltrated, and threats of publication are made. Often, only an unpleasant decision remains: to pay or not to pay?

In addition to IT security, criminal law, and compliance, another question arises in practice:

Can an Austrian company deduct the ransom paid for the decryption or deletion of data as a business expense for tax purposes?

Are you currently affected by a hacker attack / ransomware demand? Our Incident Response Team helps 24/7 – Contact us by phone at 06508601778.

Cybercrime

Table of Contents

1. Initial situation: What happens during a ransomware attack?

Typical course of a ransomware incident:

  • Attackers encrypt servers, databases, and workstations.

  • Important company data and backups become inaccessible.

  • In addition, data is frequently exfiltrated.

  • The perpetrators are threatening to publish this data on the dark web.

  • A ransom is being demanded – usually in cryptocurrencies.

In many cases, it involves two specific demands:

  1. Ransom for a working decryption key Decryption Key.

  2. Ransom in exchange for a promise to delete exfiltrated data or not publish it (Data Leak Extortion).

These two exact constellations are what this article is about.

2. Tax Principle: Business Causation as a Starting Point

Under Austrian income tax law, operating expenses are all expenditures caused by the business. Put simply:

  • There must be a clear economic connection to the company.

In the case of ransomware ransom payments, this connection regularly exists:

  • Typically, corporate IT systems and company data are affected.

  • The payment serves to,

    • to restore the company's operational capability (decryption), or

    • preventing further massive damage from data publication (deletion/removal of the leak).

This strongly suggests classifying these payments in principle as business-related expenses. Economically, they are comparable to damage mitigation and restoration costs.

3. Prohibition of deduction for „punishable benefits“ – does it affect the victim?

An obvious counterargument is § 20 para 1 subpara 5 lit a EStG. To put it simply, it states there that contributions whose grant or acceptance is punishable by a court of law are not tax-deductible.

Specialized literature clearly differentiates here:

  • The standard is primarily intended to cover corrupt payments and bribes.

  • This refers to cases in which the payer deliberately obtains an unlawful advantage.

With a ransomware ransom payment, the situation is different:

  • The company is the victim of extortion.

  • It tries to limit existing damage and secure the continuation of operations.

  • It is not about committing a crime of your own or unlawfully influencing someone.

Therefore, it is convincingly argued that Section 20, paragraph 1, item 5, subitem a of the Income Tax Act (EStG) should not, as a rule, lead to the denial of the deduction of business expenses for the victim of a ransomware attack when it is merely a matter of the decryption or non-publication of corporate data.

Borders can run where:

  • It is clear that the ransom is recognizably going to a sanctioned or terrorist organization, right?

  • the company consciously stumbles into criminal complicity.

However, in typical, anonymous ransomware cases, this constellation usually does not exist.

4. Designation of the recipient: What about Section 162 of the Federal Fiscal Code (BAO) if the perpetrators are anonymous?

Another sticking point is the naming of the recipient pursuant to Section 162 of the Federal Fiscal Code (BAO). The tax authority can demand that a company precisely identify the recipient of a payment. If this is not done, the business expense can be disallowed.

Practical problem:

  • Ransomware perpetrators are anonymous,

  • payment is made to a crypto wallet address,

  • There is no realistic chance of determining the recipient's name or address.

According to the view represented in the literature:

  • Section 162 BAO requires a „refusal“ to designate the recipient.

  • If the recipient cannot be objectively determined, it is not a refusal, but an impossibility.

In the context of ransomware, this means:

  • If the company transparently documents the attack and the payment,

  • and demonstrates that an identification of the perpetrators is not possible despite reasonable efforts,

  • the business expense cannot be denied solely due to the failure to name the recipient.

5. Ransom for decryption vs. Ransom for data deletion

For the tax treatment, it makes no fundamental difference in practice whether the ransom is paid for:

  1. Decryption of corporate data

    • Goal: Restoration of work capacity.

  2. Commitment to delete or not publish exfiltrated corporate data

    • Goal: Avoidance of further damage (reputation, trade secrets, GDPR risks, liability claims from affected parties, etc.).

In both cases, the payment is closely linked to operational activity. It serves to mitigate damage and protect the company.

Result: Both options can generally be argued as tax-deductible business expenses, provided that the other requirements (victim status, no discernible violations of sanctions, cleanly documented facts including examination of the factual and legal permissibility of the ransom payment) are met.

6. Technical Background

We are attorneys, not tax advisors. As part of our work in incident response teams, however, we are frequently confronted with the question of the tax treatment of ransom payments and regularly collaborate with specialized tax advisors in the process.

The information presented in this article is based on our current understanding of the legal situation and does not claim to be correct, complete, or up-to-date. As far as can be ascertained, there are currently no final decisions by Austrian supreme courts on the issues discussed here, meaning that the assessment may change due to future jurisprudence or administrative practice.

Parts of the presentation are based in particular on the specialist article by Bräumann / Kofler / Tumpel, „Sind Lösegeldzahlungen bei Ransomware-Angriffen steuerlich abzugsfähig?“, SWK 26/2021, 1194–1205, without this constituting tax advice.

7. FAQ: Frequently asked questions regarding the tax treatment of ransomware ransoms

Are ransom payments tax-deductible in Austria?

Yes, provided it involves the decryption or non-publication of operational data, the company is clearly the victim, and the incident is cleanly documented, these payments can generally be argued as business expenses.

Are ransom payments also tax-deductible if they are only intended to prevent the publication of exfiltrated data?

Yes. If the payment serves to prevent the publication of company data and thereby avert operational damage (e.g., trade secrets, liability risks, reputational damage), there is also a clear business justification.

Do I have to name the recipient of the ransom payment to the tax office?

In principle, the tax office can demand the naming of the recipient. In typical ransomware cases, however, the perpetrators are anonymous. If identification is not possible despite reasonable efforts, naming is impossible. The business expense should then not be disallowed for this reason alone.

Does it make a difference under tax law whether ransom is paid with cryptocurrencies?

Payment in cryptocurrencies does not change the fundamental tax classification as a business expense. Above all, what matters is the documentation of the transaction (wallet, transaction ID, conversion into EUR) and its classification as a damage expense.

Does Section 20, Paragraph 1, Item 5 of the Austrian Income Tax Act (EStG) („punishable contributions“) preclude the deductibility of a ransom payment?

According to the relevant literature, generally no. The provision aims primarily at bribes and corrupt payments, not at victim payments in an extortion situation. In typical ransomware cases, the company is the victim and is merely attempting to limit massive damage. Special cases in which it is clearly recognizable that payments are flowing to sanctioned or terrorist organizations can be problematic.

8. Short Conclusion

For Austrian companies that pay a ransom after a ransomware attack to decrypt data or to promise the deletion or non-publication of exfiltrated company data, tax deductibility as a business expense is, according to current expert opinion, well defensible –
provided that the business purpose is clearly established, the sanctions and terrorism checks are negative, and the incident is comprehensively documented.

For further information Roman Taudes and his team at any time at office@atb.law or by phone at 01 39 12345 available.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Picture of Roman Taudes
Roman Taudes
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies
Picture of Roman Taudes
Roman Taudes