Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Australia Enforces Mandatory Ransomware Payment Reporting: Who Must Report Within 72 Hours

By TheFinanceBase Team7 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Australia now requires certain businesses and critical-infrastructure entities to report qualifying ransomware and cyber-extortion payments within 72 hours. The regime has applied since 30 May 2025 under Part 3 of the Cyber Security Act 2024 and the Cyber Security (Ransomware Payment Reporting) Rules 2025. It is a mandatory reporting scheme—not a blanket ban on paying ransom.

The short answer

  • The reporting obligation has been active since 30 May 2025.
  • It broadly covers businesses carrying on business in Australia with previous-financial-year turnover exceeding AUD $3 million, subject to statutory exclusions.
  • It separately covers responsible entities for certain critical-infrastructure assets under Part 2B of the Security of Critical Infrastructure Act 2018.
  • A qualifying payment or benefit generally must be reported within 72 hours of payment or becoming aware that a payment was made.
  • Failure to report can attract a civil penalty of 60 penalty units.
  • The report does not replace privacy, critical-infrastructure, financial-crime, contractual, insurance or sector-specific notifications.

Home Affairs described the period from 30 May to 31 December 2025 as an “Education First Approach”. From 1 January 2026, the regime moved into a more active compliance-and-education phase. Businesses should therefore treat the obligation as operational and enforceable, rather than as a proposed or merely transitional measure.

Who must report?

Businesses above the turnover threshold

A business will broadly be covered where it:

  1. carries on business in Australia;
  2. had annual turnover exceeding AUD $3 million in the previous financial year;
  3. is not a Commonwealth or State body; and
  4. is not being considered under the separate critical-infrastructure responsible-entity category.

The relevant figure is not simply a current-year estimate. The Rules prescribe how turnover is assessed, including a pro-rata calculation for a business that operated for only part of the previous financial year. Groups, subsidiaries and businesses with Australian operations should obtain advice on which legal entity’s turnover and activities are relevant.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Critical-infrastructure responsible entities

A responsible entity for a critical-infrastructure asset covered by the specified SOCI Act provisions may be subject to the reporting requirement regardless of whether it exceeds the AUD $3 million threshold.

#1 Best Overall
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Being a supplier to a critical-infrastructure operator does not automatically make a company a covered responsible entity. Coverage depends on the statutory status of the entity and the relevant asset.

What triggers the reporting obligation?

The trigger is cumulative. A covered entity should assess whether:

  • an incident has occurred, is occurring or is imminent;
  • the incident is a cyber-security incident;
  • the incident directly or indirectly impacts the reporting business entity;
  • an extorting entity makes a demand intended to benefit from the incident or its impact; and
  • the business provides a payment or benefit—or knows that another entity provided one on its behalf—and that payment is directly related to the demand.

“Payment” is broader than a conventional cryptocurrency ransom. Depending on the circumstances, it may include cryptocurrency, a bank transfer, gift cards, another transfer of value or a non-cash benefit. The statutory concept also matters where an insurer, negotiator, incident-response provider, affiliate, parent company or other representative pays on the business’s behalf.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If no ransom is paid

Generally, no ransomware-payment report is triggered if no ransomware or cyber-extortion payment or benefit is provided. That does not make the incident reporting-free. A data breach may still require notification under the Privacy Act and Notifiable Data Breaches scheme, while critical-infrastructure, telecommunications, financial-crime, contractual, insurance or sector-specific duties may also apply.

Fraudulent demands and unusual transfers

A suspected scam, fraudulent invoice or extortion attempt should be assessed against the statutory elements rather than automatically treated as reportable. Conversely, a transfer described internally as a “test” or operational payment may require legal assessment if it was actually a ransom, settlement or benefit to the extorting entity.

Rank #2
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
  • Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

When does the 72-hour clock start?

The report is generally due within 72 hours of:

  • making the payment; or
  • becoming aware that another entity made the payment on the business’s behalf.

For example, if the business pays at 3:00 p.m. on 18 August 2026, the 72-hour period runs from that payment time. If an insurer or negotiator paid at 6:00 p.m. on 18 August but the business first became aware at 10:00 a.m. on 19 August, the awareness event may be the relevant starting point for the business’s obligation. The exact application should be checked against the Act and the facts.

Do not assume the clock waits for forensic confirmation. The Rules address information the entity knows, or can find through reasonable search or inquiry, within the reporting period. Submit the information available by the deadline, document material gaps and continue the investigation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information must be reported?

The report requires information concerning, at minimum:

  • the reporting entity’s contact and business details, including its ABN where applicable;
  • the other entity’s contact and business details where relevant;
  • the cyber-security incident and its impact;
  • the extortion demand;
  • the payment or benefit provided;
  • communications with the extorting entity; and
  • other information prescribed by the Rules or known after reasonable inquiry.

Prepare a working incident record containing:

  • the date and time of compromise, demand and payment;
  • the attacker’s claimed identity and all communications;
  • the requested amount, currency, wallet address, bank account or payment method;
  • each staged payment, amount and transaction reference;
  • the person or organisation that authorised and made the payment;
  • any insurer, broker, negotiator, vendor, affiliate or contractor involved;
  • systems and data affected;
  • sanctions, law-enforcement and financial-crime checks;
  • containment and restoration actions; and
  • other notifications already made.

How to submit the report

Use the official Cyber.gov.au ransomware payment and cyber extortion payment reporting form. The form asks whether the submitter is:

  • a business operating in Australia that meets the relevant turnover threshold;
  • a responsible entity for a covered critical-infrastructure asset; or
  • a third party submitting on behalf of the reporting business entity.

Before submitting, confirm the covered entity, apply the statutory trigger test, identify the earliest applicable time, provide information known or reasonably discoverable, and preserve the supporting evidence. Keep a copy of the completed report and submission confirmation, and record unresolved facts and follow-up actions.

Rank #3
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
  • Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

What if an insurer or third party paid?

A payment by an insurer, negotiator, contractor, parent company or other representative can still create consequences where it was made on behalf of the impacted reporting business entity and the business knows about it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Contracts and incident-response procedures should require immediate notice of any payment, including:

  • the exact payment time;
  • amount and currency;
  • recipient, wallet or account details;
  • transaction evidence; and
  • the communications and approvals supporting the payment.

For group companies, identify separately which legal entity was affected, which entity authorised or made the payment, which entity carried on business in Australia, and which entity met the coverage test. Do not automatically file only through the parent company or only through the entity whose systems were encrypted.

Penalties and information protections

Section 28 of the Cyber Security Act provides for a civil penalty of 60 penalty units for failing to comply. The dollar value of a penalty unit can change, so it should not be converted without checking the value applicable on the relevant date.

The Act also provides regulatory mechanisms including civil-penalty proceedings, infringement notices, enforceable undertakings, injunctions, monitoring and investigation powers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
  • Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Reports receive qualified protections. Restrictions apply to some use and disclosure of information, and submitting information does not by itself remove a person’s ability to claim legal professional privilege. These protections are not absolute immunity or a blanket confidentiality guarantee. Information may still be used for purposes connected with responding to, mitigating or resolving the incident; administering or enforcing the Act; and proceedings involving false or misleading information, obstruction or criminal offences. Information already lawfully public may not receive the same protection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Reporting does not replace other duties

A ransomware-payment report is a separate obligation. Depending on the incident, also consider:

  • Privacy Act and Notifiable Data Breaches notifications;
  • Security of Critical Infrastructure Act incident reporting;
  • telecommunications reporting;
  • AUSTRAC suspicious-matter or financial-crime obligations;
  • notifications to customers, regulators, lenders, insurers and contractual partners;
  • law-enforcement engagement; and
  • sector-specific reporting rules.

AUSTRAC’s ransomware-payment guidance addresses detecting and stopping ransomware payments and suspicious activity involving possible ransomware proceeds. It is not the same form or obligation as the Cyber Security Act report.

Practical incident-response checklist

Before an incident

  • Write a ransomware-response plan and legal-regulatory decision tree.
  • Name an incident commander and reporting owner.
  • Document how the AUD $3 million threshold is assessed.
  • Maintain a current critical-infrastructure asset and responsible-entity inventory.
  • Set payment approvals across legal, finance, security, insurance and executive teams.
  • Require third parties to notify the business immediately of payments made on its behalf.
  • Pre-approve access to the Cyber.gov.au form.
  • Test isolated backups and evidence-preservation procedures.

During the incident

  • Preserve ransom notes, emails, chat logs, wallet addresses, bank details and negotiation records.
  • Record every payment, benefit, approval and exact time.
  • Contain affected accounts and systems while preserving forensic evidence.
  • Track payments made by insurers, negotiators and other representatives.
  • Assess sanctions, financial-crime, privacy and critical-infrastructure implications separately.

Before 72 hours expires

  • Confirm whether the entity is covered.
  • Confirm whether the statutory trigger is met.
  • Calculate the deadline from payment or awareness of a third-party payment.
  • Submit known and reasonably discoverable information without waiting for a complete investigation.
  • Retain the report, confirmation and evidence.
  • Obtain specialist legal advice on privilege, sanctions, criminal law and overlapping duties.

Key edge cases

Situation What to check
Turnover just above or below AUD $3 million Use the previous-financial-year test and the Rules’ calculation, not an informal current-year estimate.
Staged payments Record each payment and seek advice rather than assuming only the final transfer matters.
Overseas group with Australian activity Assess whether the relevant entity carries on business in Australia and how turnover is attributed.
Supplier to critical infrastructure Confirm statutory responsible-entity status; supplying a covered operator alone is not enough.
No conventional cryptocurrency ransom Assess whether another payment or benefit was directly connected to the extortion demand.

For borderline cases—particularly those involving critical infrastructure, third-party payments, sanctions, privilege or multiple regulators—use Australian-qualified legal and incident-response advisers promptly. A security product, backup platform or generic compliance system may help detect, contain, recover or track an incident, but none determines the legal trigger or replaces an accountable reporting process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$128.00
Bestseller No. 2
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$208.99
Bestseller No. 3
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.80
Bestseller No. 4
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$189.90

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.