Cybercrime

Ransomware and ransom

Criminal law aspects of ransom payments

Ransomware is a form of malicious software that blocks access to data or systems and only releases them again after a ransom is paid. This type of cyberattack is increasing worldwide and presents companies and private individuals with complex legal questions. A central question in this regard is: Do you make yourself liable to prosecution by paying a ransom?

ransomware ransom payment

Table of Contents

Punishability of ransom payment

According to the Austrian Criminal Code (StGB), there is no explicit regulation that penalizes the payment of ransom. However, the payment could be construed as supporting a criminal organization or as contributing to the financing of criminal acts. Each case must be examined individually, which is why legal advice is essential.

Justifying emergency and self-defense

Under Austrian law, the payment of ransom could, under certain circumstances, be covered by the defense of necessity (§ 34 StGB). This requires that the action is necessary to avert an imminent, significant disadvantage. Self-defense (§ 3 StGB) could also be invoked in certain cases if the payment is necessary to fend off a current attack. A precise examination of the individual case and its documentation is essential.

sanctions list screening

Before considering a ransom payment, a sanctions list screening must be performed. It is important to ensure that the payment is not made to a person or organization listed on an international sanctions list. Failure to comply with such a prohibition could result in severe legal consequences.

Documentation

Should you decide to pay the ransom, careful documentation is essential. Keep a record of all communication steps, payment receipts, and the sanctions list screening performed. This documentation can be of great importance in the event of a subsequent legal dispute.

Conclusion and Recommendation

The payment of ransom after a ransomware attack is a complex legal issue that requires careful consideration and individual examination. It is advisable to contact an experienced attorney in such cases in order to minimize legal risks and determine the best possible course of action. For further information and individual consultation, available are Anela Blöch (bloech@atb.law) and Roman Taudes (taudes@atb.law) available at any time. 

If you are currently affected by a ransomware attack, we are available by phone at any time at 0650 860 1778 available. We coordinate an incident response team and support you in all aspects of damage management.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Picture of Roman Taudes
Roman Taudes
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies
Picture of Roman Taudes
Roman Taudes