Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

UK Warns Lawyers Not to Advise Ransomware Payments

The NCSC and the ICO have warned UK lawyers not to advise clients to pay a ransom to cybercriminals

In a letter addressed to UK lawyers dated July 7, 2022, the UK’s National Cyber Security Center (NCSC) and the Information Commissioner’s Office (ICO), have reiterated – with teeth – the official stance on not paying a ransom.

The NCSC and the ICO have warned UK lawyers not to advise clients to pay a ransom to cybercriminals

In a letter addressed to UK lawyers dated July 7, 2022, the UK’s National Cyber Security Center (NCSC) and the Information Commissioner’s Office (ICO), have reiterated – with teeth – the official stance on not paying a ransom.

From the law enforcement standpoint, the letter explains, “Law Enforcement does not encourage, endorse nor condone the payment of ransoms. While payments are not usually unlawful, payers should be mindful of how relevant sanctions regimes (particularly those related to Russia) – and their associated public guidance – may change that position.”

The implicit warning is that sanctions against Russia could technically make payment of a ransom to a Russian cyber gang effectively if not actually illegal. Ignorance of the attackers’ nationality would be a dangerous tactic, since the NCSC specifically states that NCSC is part of GCHQ – and GCHQ, like the NSA, would know.

The law enforcement warning will only apply to companies with a presence in the UK – but other countries operating current sanctions against Russia might take a similar stance.

The second warning refers to the UK data protection regulator, the ICO. In setting regulatory fines, the ICO will normally consider actions taken to mitigate the risk of harm to individuals involved in a data breach. This does not apply to paying a ransom in the hope of recovering personal data stolen in a double extortion attack.

Advertisement. Scroll to continue reading.

“For the avoidance of doubt,” says the letter, “the ICO does not consider the payment of monies to criminals who have attacked a system as mitigating the risk to individuals and this will not reduce any penalties incurred through ICO enforcement action.”

In short, paying a ransom could leave a company open to charges of sanctions busting, while having no effect on any subsequent ICO enforcement. Given the international nature of GDPR and the UK’s current implementation of the UK GDPR, this would also apply to North American and other countries’ companies who pay a ransom to recover stolen European PII.

Related: It Doesn’t Pay to Pay: Study Finds 80% of Ransomware Victims Attacked Again

Related: The Psychology of Ransomware Response

Related: SecurityWeek Cyber Insights 2022: Ransomware

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.

Delinea has appointed Timothy Regan as Chief Financial Officer.

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.