Reporting an attack, and the question of paying

Two questions come up in almost every ransomware incident: who do we have to tell, and should we pay? This page sets out what the US and UK agencies actually say, and where a professional adviser needs to take over.

Last reviewed 10 October 2026.

Who to tell, and why it helps

The CISA and FBI guide tells victims to report the incident to CISA, their local FBI field office, the FBI's Internet Crime Complaint Center (IC3) or their local Secret Service field office. The IC3 site invites a report even when you are unsure whether the complaint qualifies. The guide's contact section describes federal assistance as available on voluntary request, and the help it lists includes technical assistance, help identifying the scope of the compromise and, in some cases, information about whether decryption tools exist.

In the UK, the NCSC's ransomware attack page sorts incidents by whether they are stopping you from operating normally, and links to guidance for disruptive attacks. It also lists the NCSC Assured Cyber Incident Response scheme, which helps you find qualified providers.

Beyond government, call your cyber insurer early. Policies often set conditions about when to notify and which responders to use, and acting before you have read yours can cost you cover. The CISA guide lists cyber insurance among the contacts to record in advance.

Notifying customers and regulators

If personal data was involved, separate duties may apply. These depend on location and sector, which is why this is a moment for a lawyer, not a blog. Two things are worth knowing.

In the UK, the ICO's guidance says that the UK GDPR introduces a duty on organisations to report certain personal data breaches to the ICO, within 72 hours of becoming aware of the breach, where feasible. If a breach is likely to result in a high risk to people's rights and freedoms, you must also inform those individuals without undue delay. The ICO also says you must keep a record of any personal data breaches, whether or not you are required to notify.

In the US, the CISA guide says data breach notification procedures must follow applicable state laws, and points readers to the National Conference of State Legislatures listing of state notification laws, adding that you should consult legal counsel when necessary. It notes that breaches involving electronic health information may require notification to the FTC or the Department of Health and Human Services, and in some cases to the media, and that if you store personal information on behalf of other businesses, you should notify those businesses if it is stolen.

The question of paying

Nobody outside your business can make this decision for you, and it is not simply a matter of money. Here is what the authorities say, with their wording kept close.

The US Treasury, in its press release announcing the updated advisory, says the US government continues to strongly discourage the payment of cyber ransom or extortion demands. The OFAC advisory itself explains the risk: making or facilitating ransomware payments can violate US sanctions rules where the recipient is a sanctioned person or in a comprehensively embargoed jurisdiction, and OFAC may impose civil penalties on a strict-liability basis, so a company can be exposed even if it did not know who was behind the demand. The advisory also says OFAC will consider a company's self-initiated and complete report of an attack to law enforcement or other relevant agencies, such as CISA, to be a significant mitigating factor in any enforcement decision.

The NCSC publishes guidance for organisations considering payment, aimed at organisations that are experiencing an attack and the partners supporting them. We recommend reading it before any payment discussion starts, and we do not summarise it here because it is the kind of guidance that changes.

Two practical points follow from those sources, and they are our reading rather than a legal conclusion. First, reporting early is useful whatever you decide, because it opens the door to assistance and, in the US, may count in your favour if a sanctions question arises later. Second, payment does not undo the damage: stolen data may still be published, and a decryption tool may be slow or incomplete. The CISA guide also advises consulting federal law enforcement about decryptors, because security researchers sometimes find flaws that allow files to be recovered without payment.

A route that costs nothing: free decryptors

Before any payment conversation goes further, check whether a decryptor already exists. The No More Ransom project is an initiative of the Dutch National High Tech Crime Unit, Europol's European Cybercrime Centre, Kaspersky and McAfee, set up to help victims of ransomware retrieve their encrypted data without paying the criminals. Its own advice is not to pay, because sending money to cybercriminals only confirms that ransomware works and there is no guarantee you will get the key you need. The project hosts a list of decryption tools, and its page carries a warning worth repeating: read the how-to guide first, and remove the malware from the system before running a decryptor, otherwise the machine will keep locking itself or encrypting files.

A decryptor exists only for some ransomware families, so this is a check to run, not something to plan around. It also does nothing about stolen data. If you are working with a responder or the police, ask them to identify the strain before you try any tool yourself.

Keep a record of every notification

Whatever you decide about who to tell, record when you told them, how, and what you said. The ICO's guidance asks organisations to keep a record of personal data breaches regardless of whether they must notify, and the same habit helps with insurers and law enforcement. A simple table with a date, a recipient, a method and a one-line summary is enough. Store it with the incident log from the first hour. If a regulator or insurer later asks when you became aware of the incident, that record answers the question without argument.

Where to go, by situation

Where to report, by situation
SituationFirst stopWhat the source saysSource
US business, any ransomware incidentCISA, FBI field office or IC3Report; assistance is available on requestCISA and FBI guide
UK organisation, disruption to operationsNCSC ransomware attack pageGuidance for disruptive attacks and assured respondersNCSC
Personal data affected in the UKICO breach reportingReport certain breaches within 72 hours where feasibleICO guidance
Personal data affected in the USYour lawyer; state notification lawsFollow applicable state laws; consult counselCISA and FBI guide
Health information involved in the USYour lawyer; HHS and FTC rulesMay need to notify HHS or the FTCCISA and FBI guide
Considering a ransom paymentYour lawyer, insurer and law enforcementStrongly discouraged; sanctions risk; report earlyUS Treasury; OFAC; NCSC

A short script for the owner

When you are not sure what to say, a short script helps. It is also a good thing to keep with your contact sheet. Tell your insurer and your lawyer what happened, when you noticed, which systems you have isolated and whether personal data may be involved. Ask them for their notification deadlines, in writing. Then tell your IT provider what to preserve. Keep the tone factual. Do not speculate about who the attacker is or what they took, because early guesses are often wrong and written guesses can be quoted back.

How we compiled this page

Methodology: reporting routes come from the CISA and FBI guide, the IC3 site and the NCSC; the description of free decryptors comes from the No More Ransom pages linked above. The 72-hour and record-keeping statements are quoted in substance from the ICO. The payment discussion uses the Treasury press release and the OFAC advisory of 21 September 2021; we did not look for newer enforcement actions, so check the Treasury site for current guidance. This page is not legal advice and it does not tell you what the law requires of you.

Previous: Checklist Next: Protection