Industries in Focus

Ransomware and Ransom Payments: What Is Legally Permitted – and What Are the Risks?

Ransomware and Ransom Payments: What Is Legally Permitted – and What Are the Risks?

Ransomware and Ransom Payments: What Is Legally Permitted – and What Are the Risks?

Last updated:

8 min.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann

It is every management's nightmare: Monday morning, 7:30 a.m. A message appears on all screens stating that all data has been encrypted. Anyone who wants their files back is asked to transfer a seven-figure sum in Bitcoin within 72 hours. What now?

Exactly at this moment, the most expensive hours in history begin for many companies – and at the same time a series of legal questions that hardly anyone has thought through beforehand. Is it permissible to pay? Do authorities have to be informed? Does cyber insurance provide protection? And what happens if you simply do not pay?

Teichmann has systematically analyzed these questions in several scientific papers – from criminal law, compliance law, and insurance law perspectives. The findings are relevant for every entrepreneur, not just for law firms.

What ransomware really is today

Ransomware has long ceased to be a technical niche phenomenon. Behind it lies an organized shadow economy with a high division of labor and billions in turnover, which in some countries is tolerated or even promoted by the state (Teichmann, Ransomware-Erpressung: Umgang, Rechtsfragen und Cyberversicherung, ZBJV 2025, pp. 553–578).

The business model works on an industrial scale. So-called Initial Access Brokers first gain access to corporate networks via phishing or known security vulnerabilities. They then resell this access on the darknet to specialized ransomware groups, who perform the actual encryption and organize the extortion. Increasingly, this leads to so-called double extortion: prior to encryption, sensitive corporate data is exfiltrated, and the perpetrators additionally threaten to publish it – even if the victim pays and gets their data back (Teichmann, ZBJV 2025, pp. 553–578).

An important finding from Teichmann's research: no company is too small or too uninteresting for ransomware attackers. The choice of victims is usually opportunistic – whoever has a security vulnerability gets hit. Professional perpetrator groups calculate the ransom demand so that it is just below the expected costs of independent data recovery in order to maximize the incentive to pay (Teichmann, ZBJV 2025, pp. 553–578).

The scale of damage is enormous. Among other things, Teichmann documents the Change Healthcare attack in 2024, in which six terabytes of sensitive patient data were stolen and around 100 million people were affected (Teichmann, Ransomware-Bedrohung im Gesundheitswesen, Compliance Berater 2025, pp. 227–233). In Germany, a ransomware attack on the company Fasana in 2025 directly led to insolvency – a wake-up call that Teichmann assesses as exemplary for medium-sized businesses (Teichmann, Cyberangriff als Insolvenzauslöser: Der Fall Fasana als Weckruf, ZRI 2026, pp. 6–13).

The crucial question: Is paying ransom forbidden?

The answer surprises many: in Germany, Austria, and Switzerland, paying ransom to ransomware extortionists is fundamentally not criminalized. There is no explicit legal prohibition. Formally, the decision lies within the entrepreneurial responsibility of the victim.

However, this by no means implies freedom from legal risk. In several articles, Teichmann outlines the circumstances under which a ransom payment can nevertheless become relevant under criminal law (Teichmann, ZBJV 2025, pp. 553–578).

The first risk factor is the support of criminal organizations. If the attackers are members of a criminal organization in the legal sense – which can certainly be the case with large, professionally organized ransomware groups – then the ransom payment can be interpreted as financial support for this organization. Conditional intent (dolus eventualis) is sufficient: anyone who anticipates that the money will benefit a criminal structure and accepts this risks criminal liability. At the same time, in such an acute scenario, a justification based on necessity would regularly be considered – the company is acting under significant pressure to prevent a worse outcome (Teichmann, ZBJV 2025, pp. 553–578).

The second risk factor is terrorist financing. If the attackers demonstrably belong to a terrorist organization – which is rarely clearly identifiable in practice – a payment would affect the offense of terrorist financing. In this case, a payment would clearly be impermissible.

The third risk factor, and the one most frequently underestimated in practice, is international sanctions. Many large ransomware groups are on the sanctions lists of the US, the EU, or other countries – in particular, groups suspected of having ties to North Korea or Russia. The US Office of Foreign Assets Control (OFAC) has made it clear that payments to sanctioned recipients can be punished under civil law – even if the paying company did not know it was serving a sanctioned party (Teichmann, ZBJV 2025, pp. 553–578). For companies with international activities or US connections, this is a significant compliance trap: you can get into legal trouble without having had bad intentions.

Why authorities and experts still advise against it

Even if paying is not forbidden per se, law enforcement agencies and cybersecurity experts worldwide unanimously advise against it – and for good reason.

A payment does not guarantee that the data will actually be decrypted. Perpetrators can make further demands after receiving the money or sell the stolen data on the darknet, regardless of whether a payment has been made. Every successful payment funds the next wave of attacks and makes the paying company known as a reliable debtor – increasing the likelihood of further attacks. Furthermore, a company known for paying appears to be a lucrative target (Teichmann, ZBJV 2025, pp. 553–578).

The decision of whether to pay should therefore depend on several concrete questions: Are there functioning, offline secured backups that can restore the data without payment? How sensitive is the exfiltrated info – does publication threaten irreparable damage to customers, clients, or business partners? And is the requested sum in reasonable proportion to the threatened total damage? In an emergency, this assessment must be made under significant time pressure – which is why it makes sense to have run through it in principle beforehand.

Reporting obligations: Who must report what, and when?

A common misconception: many companies believe they can keep a ransomware incident internal and simply pay without having to inform anyone. Increasingly, this is no longer true.

Under the EU General Data Protection Regulation (GDPR) and German data protection law, a personal data breach – and a ransomware attack affecting personal data is almost always one – triggers an obligation to notify the competent data protection supervisory authority within 72 hours. If it can be proven that affected individuals are also exposed to a high risk, they must also be informed.

Under the NIS 2 Directive, implemented in Germany by the NIS2UmsuCG, affected companies are subject to an even stricter 24-hour reporting obligation to the BSI in the event of significant security incidents (Teichmann, Die neue 24-Stunden-Meldepflicht für Cyberangriffe nach ISG, Jusletter, September 29, 2025). Anyone who reports too late or not at all risks substantial fines.

In addition, authorities in Germany, Austria, and Switzerland recommend filing a criminal complaint early on. This has practical advantages: investigative authorities can provide technical support, track the communication channels of the perpetrators, and, in the best-case scenario, provide decryption tools. Filing a criminal report does not make the victim criminally liable – and it increases the chance of holding perpetrators accountable (Teichmann, ZBJV 2025, pp. 553–578).

The connection to insolvency: an underestimated risk

Teichmann uncovers a connection that is barely known in business practice: a ransomware attack can trigger insolvency filing duties. If an attack induces or threatens insolvency, Section 15a of the German Insolvency Code (InsO) applies – the duty to file for insolvency without undue delay. Anyone who then hesitates or delays risks not only civil liability but also criminal consequences for delaying insolvency proceedings (Teichmann, Cyberbedingte Insolvenzreife und § 15a InsO, ZInsO 2025, pp. 2193–2207; id., Cyberkrise und Insolvenzverschleppung, ZRI 2025, pp. 877–884).

The NIS 2 regime aims precisely at prevention here: it obliges companies to take cyber risks seriously and manage them before they become life-threatening. Those who do so protect themselves not only from the attack itself, but also from the legal consequences afterward (Teichmann, Cyberrisiken und Insolvenzgefahr: Präventive Schutzpflichten des NIS2-Regimes, InsA 2026, pp. 3–10).

What cyber insurance provides – and what it does not

Many companies trust that cyber insurance will solve all problems in an emergency. This is a dangerous misconception.

Good cyber insurance policies indeed cover a wide spectrum: costs for IT forensics and external crisis specialists, business interruption losses, liability claims from damaged third parties and – in many cases – also the reimbursement of a ransom payment made. Some insurers even provide a crisis manager immediately in the event of a claim.

But the pitfalls lie in the details. Almost all cyber policies contain exclusion clauses for payments to sanctioned recipients – meaning that if the ransomware group is found to have been on a sanctions list, the insurance will not cover it. Following the NotPetya attacks in 2017, some insurers denied coverage arguing that the attack was state-sponsored and fell under the war exclusion clause. And almost all policies require that the insurer be consulted before any ransom payment is made – anyone who pays on their own authority without involving the insurance company risks losing coverage (Teichmann, ZBJV 2025, pp. 553–578).

Cyber insurance is a sensible tool as part of an overall concept. However, it replaces neither technical protective measures nor thought-out crisis planning. Relying solely on insurance is negligent.

What really needs to be done in an emergency

Teichmann's research suggests that dealing with a ransomware attack in practice is characterized by a central problem: decisions must be made under maximum time pressure, without sufficient information about the perpetrators, the scope of the damage, and the legal consequences of the various courses of action.

Therefore, preparation is key. Companies that have an emergency plan – who is responsible, who is informed when, which external specialists are brought in, where offline backups are located – act in a structured rather than chaotic manner in an emergency. Companies without a plan improvise under panic and regularly make decisions they later regret (Teichmann & Boticiu, The Importance of Cybersecurity Incident Response Plans for Law Firms, Jusletter, April 3, 2023).

In an acute case: disconnect affected systems from the network immediately to prevent further spread. Secure backups and isolate them from production systems. Save log files before systems are cleaned – they are crucial for subsequent forensics. Inform insurance. File a criminal complaint. Seek legal advice before even considering a payment. And: keep an eye on reporting requirements. The data protection authority and BSI have clear deadlines.

The question of whether to pay should be the last question asked – not the first. And it should never be answered without professional support.

International developments: where the journey is heading

Teichmann observes a clear direction internationally: states are increasingly tightening obligations for companies and simultaneously debating whether to regulate ransom payments more strictly or even ban them (Teichmann, International legal response to ransomware: toward a ban on payments?, International Cybersecurity Law Review 2026, pp. 1–28).

In the US, the Office of Foreign Assets Control (OFAC) has made it clear that payments to sanctioned groups carry civil consequences – and the Department of Justice has set up its own Ransomware Task Force. At the same time, there are political initiatives that would generally ban critical infrastructure from making ransom payments.

In the EU, the GDPR and NIS 2 Directive set clear obligations for prevention, reporting, and response – with heavy fines for violations. The direction is clear: those who do not prepare pay twice – once to the extortionists, and once to the legislator.

Conclusion: Preparation is the only effective protection

Ransomware is a threat that can hit anyone – and it is becoming more professional, not more amateurish. The legal situation is complex: paying is not design-prohibited on its face, but is associated with substantial risks. Not paying is the officially recommended strategy – but is only practically feasible if the company is prepared.

Teichmann's research shows: the decisive path is set not at the moment of the attack, but within the months and years beforehand. Functioning backups, clear emergency plans, trained employees, known reporting obligations, and reviewed cyber insurance – these are the components that, in an emergency, make the difference between a controllable crisis and a threat to existence.

All source citations refer to published scientific papers by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the list of publications (as of May 2026).

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

We use cookies to improve your experience. By continuing, you agree to our cookie policy.