- Current official form for reports under section 27 and the practical submission fields.
"Ransomware payment and cyber extortion payment reporting"
A reporting business entity must give a ransomware payment report within 72 hours of making the payment or becoming aware that the payment has been made.
This page explains the statutory trigger, reporting-business-entity scope, report contents, current filing route, and evidence to preserve. It does not replace case-specific legal, sanctions, insurer, or law-enforcement advice.
Structured answer sets in this page tree.
Cited legal and guidance references.
Australia's Cyber Security Act 2024 has imposed a 72-hour reporting duty on a since Part 3 commenced on 29 May 2025. The report must be given to the , in the form approved by the Secretary if one exists and in any manner prescribed by the rules. The Australian Government provides the section 27 reporting form on cyber.gov.au.
Part 3 applies only when the incident is a cyber security incident, the incident has had, is having, or could reasonably be expected to have a direct or indirect impact on a , an extorting entity makes a demand to benefit from the incident or its impact, and the reporting business entity provides or becomes aware that another entity has provided a payment or benefit on its behalf that is directly related to the demand.
For this Act, a cyber security incident must be an event covered by the Security of Critical Infrastructure Act meaning or an unauthorised impairment of electronic communications to or from a computer, including mere interception for this purpose, and it must have one of the constitutional connections in section 9(2). For incidents outside the critical-infrastructure-asset and constitutional-corporation limbs, section 26 presumes the event is a cyber security incident if it was probably internet-enabled, probably impaired a computer's connection, or probably seriously prejudiced specified Australian interests. The presumption cannot make an entity liable to the Part 3 civil penalty when the relevant condition did not exist in fact.
Document the trigger analysis before classifying a ransom negotiation as reportable. Capture the incident facts, the demand, the payment or benefit, who paid, whether the payment was on behalf of the , and how the incident connects to that entity.
The duty applies to a at the time the is made. One route covers an entity carrying on a business in Australia whose annual turnover for the previous financial year exceeds the threshold, provided it is not a Commonwealth body, State body, or responsible entity for a critical infrastructure asset. The other covers a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies.
The 2025 Rules set the ordinary turnover threshold at $3 million for the previous financial year and include a pro-rata formula where the business operated for only part of that year. The Act says turnover must exceed the threshold. The Rules' Explanatory Statement describes $3 million or more as captured, and the current cyber.gov.au form labels its turnover option "equal to or exceeds $3 million." Those non-binding descriptions do not match section 26. An entity at exactly $3 million should promptly confirm the filing position rather than treating either description as a change to the Act.
Once the scoped entity makes the payment, or becomes aware that the payment has been made, the report is due within 72 hours, whichever clock-start is applicable.
Section 27 requires the report to contain information the knows, or is able by reasonable search or enquiry to find out at the time of reporting, about the relevant entity details, the cyber security incident, the demand, the , and communications with the extorting entity.
The Rules prescribe details within those categories: ABN if any and address; incident and awareness timing; infrastructure and customer impacts; ransomware or malware variants and exploited vulnerabilities if any; information that could assist response, mitigation, or resolution; the amount or quantum and method demanded and provided; and the nature, timing, description, and pre-payment negotiation details of communications with the extorting entity. Section 27 also permits the entity to include other incident information.
The report must be given to the . Under the Act's definition, if no rules specify another body, the designated bodies are the Department of Home Affairs and the Australian Signals Directorate. Section 27 requires the Secretary-approved form, if any, and any manner prescribed by the rules.
The Australian Government currently provides the and cyber extortion payment reporting form on cyber.gov.au. The form allows a third party to submit on behalf of the and asks for both organisations' details where applicable. Confirm the live filing instructions at submission time and keep the completed report, confirmation page or transmission record, and submission timestamp.
The report-content duty is limited to information the knows or can find out by reasonable search or enquiry within the 72-hour reporting period. The search log should show what was checked, who was asked, what was known at submission time, and which items remained genuinely unknown.
Failure to give a required report carries an express civil penalty of 60 penalty units. The report protections are qualified: the Act limits specified use, disclosure, and admissibility of report information and preserves privilege claims in most proceedings, but those protections do not cover the same information when a body obtains it independently or when it is already lawfully public. They also contain exceptions for enforcement of Part 3, specified criminal-law matters, coronial inquiries, Royal Commissions, and certain federal-court proceedings.
Keep the report itself, the deadline calculation, the scope assessment, the demand and payment evidence, communication records, malware or vulnerability findings, customer and infrastructure impact notes, approval records, and any follow-up corrections or incident-response actions. Separate the report from other SOCI, privacy, law-enforcement, insurer, or contractual notifications so each obligation has its own trigger and evidence trail.
Assign the trigger review, deadline calculation, report-field collection, and evidence preservation tasks in Sorena.
Convert the ransomware payment reporting trigger, 72-hour clock, and report fields into assigned evidence tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"Ransomware payment and cyber extortion payment reporting"
"within the 72 hour time period for giving the report"
"within 72 hours of making the ransomware payment"
"must give the designated Commonwealth body a report"
"within 72 hours of making the ransomware payment"
"knows or is able, by reasonable search or enquiry"