Law Letter Hub Articles
Cyber Extortion – Legal and Ethical Considerations If You Receive a Ransom Demand
1 December 2020
- While payment of a cyber ransom is a last resort in Australia it is generally not illegal.
- However, possible offences under anti-terrorism and anti-money laundering legislation should be considered.
- Ethical issues for lawyers to consider include duties to the administration of justice, to act in the client’s best interests and to maintain confidentiality.
What is Ransomware?
Ransomware is a type of malicious software (malware) that infects computers and makes data unreadable unless a ransom is paid. The ransom demanded will usually be in cryptocurrency such as Bitcoin. Where reliable backups of data are available it may be possible to recreate businesses’ records without paying a ransom. However, this is not always possible, particularly if backups have also been encrypted.
Ransomware is reported to be the fastest growing type of cybercrime. Recent months have seen media reports concerning ransomware attacks impacting businesses globally including Garmin and Travelex. In Australia, organisations impacted include Toll, MyBudget, and Bluescope Steel. Some ransomware threatens not only to encrypt data but also to publish or sell it. This threat can have serious implications for organisations including law firms with special duties to maintain confidentiality of information.
Cases Impacting Law Firms
In May 2020 US law firm Grubman Shire Meiselas & Sacks, which acts for numerous celebrity clients, confirmed it had been the victim of a cyberattack in which hackers accessed 756 gigabytes of data contained in legal files held on behalf of dozens of clients. When it became clear the ransom of US $42 million would not be paid, the hackers reportedly commenced auctioning off files to the highest bidder.
The threat to publish information is clearly a nightmare scenario for a legal practice that holds information it is required to keep confidential. While this is an extreme case, Australian law firms have also been victims of ransomware. Lawyers are of course expected to uphold the law, so what factors should be considered in the event of a ransomware attack?
Public Policy Considerations
There are strong public policy reasons why ransoms should not be paid, namely to discourage further escalation in this type of crime, and the Australian Cyber Security Centre and law enforcement bodies recommend against making ransom payments. There is no guarantee that cybercriminals can or will decrypt your records if a ransom is paid and paying a ransom could also make you a target for further attacks. In September 2020 the former head of the UK’s National Cyber Security Centre reportedly called for the UK government to make it illegal for companies to pay cyber hackers a ransom, describing ransomware as “the single biggest contemporary scourge in cyber space”.
Is it Legal to Pay a Ransom?
While it is generally accepted that in Australia payment of a cyber ransom is not illegal, it is a serious offence to contravene anti-money laundering legislation (Criminal Code Act 1995 (Cth), division 400) or to make funds available to an organisation where a person knows or is reckless as to whether the organisation is a terrorist organisation (Criminal Code Act 1995 (Cth, s 102.7), or to an organisation proscribed by UN sanction (Charter of the United Nations Act 1945 (Cth)). Some commentators have suggested a defence of duress might be available in certain circumstances – where there is any possibility these issues could arise you should seek specialist advice. Organisations subject to anti-money laundering legislation may also be required to disclose the payment of a ransom.
Professional Rules and Fiduciary and other Duties
The Legal Profession Uniform Law Australian Solicitors’ Conduct Rules (rule 3), provide that a lawyer’s paramount duty is to the Court and the administration of justice. However, where there is no clear contravention of that duty the obligation to protect the clients’ interests is otherwise paramount (see D. Bowles, “Is it Ethical (or legal) for law firms to pay cyber-ransom?”, Queensland Law Society, December 2017).
Where a lawyer receives what appears to be a credible threat to publish confidential information held on behalf of others, he or she will need to consider how professional obligations might apply. Under the Australian Solicitors Conduct Rules, which now apply to most Australian lawyers:
- Rule 4.1.1 provides there is a duty to act in the client’s best interests; and
- Rule 7 requires clear and timely advice to assist clients to understand legal issues and make informed choices.
Other factors to consider are the fiduciary relationship between solicitor and client, based on the trust that the client has placed in their lawyer, and the equitable duty to maintain the confidentiality of communications. There may also be duties to maintain the confidentiality of information pertaining to third parties and, if your firm is subject to the Privacy Act 1988, a duty to report an eligible data breach involving personal information where the data breach is likely to result in serious harm to any of the individuals to whom the information relates.
Minimise your risk by making regular backups that aren’t connected to your network, use antivirus software, and keep operating systems and software up to date. With most ransomware delivered via a phishing email, ensure everyone in your practice is educated about cybercrime and how to recognise suspicious emails. Lastly, if you have cyber insurance you should notify your cyber insurer immediately and obtain its consent before making any payment.
This is an updated version of an article first published in September 2020 in the Law Society of NSW Journal.
Simone Herbert-Lowe
Director, Law & Cyber Pty Ltd
Additional sources:
D. Bowles, “Is it Ethical (or legal) for law firms to pay cyber-ransom?”, Queensland Law Society, December 2017).
P. Gunning, “Cyber attacks: is it legal to pay a ransom in Australia?”, https://www.kwm.com/en/au/knowledge/insights/cyber-attacks-is-it-legal-to-pay-a-ransom-in-australia-20200707
J. Jacobs & C. Chivers, “Paying a Cyber Ransom – should you do it?”: https://www.insurancelawtomorrow.com/2019/09/paying-a-cyber-ransom-should-you-do-it/
S. Kantor, “To pay, or not to. pay? When ransomware attacks”: https://www.minterellison.com/articles/when-ransomware-attacks
G. Smith and V. Bloch, “Should you pay a cyber criminal’s ransom?”: https://www.allens.com.au/insights-news/insights/2018/01/pulse-should-you-pay-a-cyber-criminals-ransom/


