Your systems are locked, and a ransom demand appears on the screen. The first decision is whether to authorize payment, and that decision can have significant legal consequences before any funds are transferred.
Dilendorf Law Firm PLLC serves as ransomware response counsel for companies, family offices, trustees, and individuals nationwide.
Supported by retired cybercrime law enforcement professionals, our team leads the legal response from New York and represents clients nationwide.
3,611Ransomware complaints reported to the FBI in 2025. Reported losses exclude business interruption and remediation costs.
$3.05BBusiness email compromise losses reported to the FBI in 2025, the second-largest loss category.
58%Share of attempted theft frozen in 2025 when the FBI’s Financial Fraud Kill Chain was initiated after a prompt complaint.
Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 7–8, 16–18, https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
The first 72 hours
- Hour 0–Preserve evidence
- Hour 1–Engage counsel
- Hours 1–6–OFAC screening
- Hours 6–24–Law enforcement notification
- Hours 24–72–Recovery window closes
Is Paying a Ransom Legal?
Payment may be lawful, but a payment to a sanctioned person or entity may violate U.S. sanctions law.
The Treasury Department’s Office of Foreign Assets Control (OFAC) has advised that companies facilitating ransomware payments “may risk violating OFAC regulations” (OFAC, Updated Advisory, Sept. 21, 2021, p. 1).

Liability is strict. OFAC may impose civil penalties “even if such person did not know or have reason to know” that the transaction was prohibited (OFAC Advisory, p. 4).
OFAC has designated several ransomware operations and their operators, including Evil Corp and the Lazarus Group (OFAC Advisory, pp. 2–3). Wallet screening therefore must occur before anyone authorizes payment.
OFAC also treats a prompt, self-initiated report to law enforcement as a significant mitigating factor (OFAC Advisory, p. 5). Cyber extortion teams starts building that record from the moment the incident is discovered.
What OFAC has said
“OFAC may impose civil penalties for sanctions violations based on strict liability.”
“The U.S. government strongly discourages all private companies and citizens from paying ransom or extortion demands.”
What OFAC treats as mitigating
- A self-initiated and complete report of the attack to law enforcement, made as soon as possible after discovery.
- Cooperation with OFAC, law enforcement, and other relevant agencies.
- A risk-based sanctions compliance program that accounts for ransomware payments.
Source: OFAC, Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (Sept. 21, 2021), pp. 1, 4–5, https://ofac.treasury.gov/media/912981/download?inline
Who Actually Sends the Payment?
The company does not send the funds itself. Ransom demands are denominated in cryptocurrency, and most organizations have no mechanism to acquire or transfer it.
Payment is executed through licensed firms. The Financial Crimes Enforcement Network (FinCEN) has stated that entities facilitating these payments may be engaged in money transmission and must register and file reports (FinCEN, FIN-2021-A004, Nov. 8, 2021, p. 3).

Those firms conduct sanctions screening and any required filings. Counsel should confirm the screening results and documents the basis for the decision before any payment is authorized to comply with OFAC regulations.
The record should identify (i) who approved the payment; (ii) what screening was performed; (iii) and when law enforcement was notified. If regulators later ask, that record provides the answer.
| Step | Timing | Who acts and what the record shows |
|---|---|---|
| Wallet screening | Before authorization | The licensed intermediary screens the attacker’s address against OFAC lists. Counsel records the result and the date. |
| Law enforcement report | As soon as possible after discovery | The company files an IC3 complaint and notifies the FBI field office. OFAC treats a self-initiated report as a mitigating factor. |
| Payment execution | Only after screening clears | The licensed firm acquires and transmits the cryptocurrency and makes its required filings. The company never holds the asset. |
| Insurer notice | As the policy requires | Notice under every policy that may respond, in the form the policy specifies. Late notice is a common ground for denial. |
Sources: OFAC Advisory, p. 5; FinCEN, FIN-2021-A004, p. 3, https://www.fincen.gov/sites/default/files/advisory/2021-11-08/FinCEN%20Ransomware%20Advisory_FINAL_508_.pdf
Hour 0 — all four workstreams begin togetherHour 72
Workstream 1
Technical containment
- Isolate affected systems.
- Image before rebuild.
- Restore from clean backups.
Workstream 2
Legal & regulatory
- Preserve logs and telemetry.
- Counsel-directed forensics.
- Nationwide notification analysis.
Workstream 3
Sanctions & payment
- Screen wallet addresses.
- Licensed payment intermediary.
- Document the decision record.
Workstream 4
Recovery & insurance
- Request wire recall.
- Review policy and sublimits.
- Prepare claim notice.
The four workstreams must proceed simultaneously. Delaying one until another is complete can create unnecessary legal, regulatory, and operational risk.
What Are Our Notification Obligations?
Data breach notification requirements are typically triggered by the residence of affected individuals, not the company’s principal place of business.
According to the Federal Trade Commission, every U.S. state, the District of Columbia, Puerto Rico, and the U.S. Virgin Islands maintain laws mandating notice in the event of qualifying breaches involving personal information. (FTC, Data Breach Response: A Guide for Business).
A single incident can trigger obligations in multiple states at once, with each state imposing its own deadlines, notice requirements, and reporting thresholds.
Businesses in regulated industries may also face additional sector-specific requirements.
Does Cyber Insurance Cover Ransomware?
Often only in part. Many cyber policies carry extortion sublimits far below the stated policy limit.
Many policies also exclude digital assets. Since Lloyd’s Market Bulletin Y5381 took effect on 31 March 2023, policies in that market contain exclusions for state-backed cyberattacks.
Coverage analysis is a distinct workstream. We help clients to review the policy, prepare the notice, and handle denied-claim disputes; we do not place coverage.
Stated limit versus extortion sublimit (illustrative)
Illustrative example only, not a real policy. Actual limits, sublimits, retentions, and exclusions vary by policy. A demand above the sublimit is uninsured exposure unless another coverage part responds.
What Should Happen in the First 72 Hours?
Preservation should come before remediation.
Cloud audit logs, mailbox sign-in records, and endpoint data may be retained for only 30 to 90 days under default settings.
The FTC’s guidance is straightforward: “Do not destroy evidence.” Before rebuilding systems, companies should preserve relevant data and issue appropriate preservation instructions.
Forensic investigators should be retained through counsel whenever appropriate. Reports commissioned directly by a company are generally more likely to be discoverable, while investigations conducted at the direction of counsel may be afforded stronger attorney-client privilege protections.
The order of these steps matters.
Poorly managed investigations can create unnecessary legal risk. We regularly work with independent forensic investigators and incident response professionals, including former federal law enforcement personnel.
Federal coordination begins with a complaint to the FBI’s Internet Crime Complaint Center (IC3), which forwards complaints to law enforcement and partner agencies (IC3, Frequently Asked Questions).
Where funds were transferred by fraud rather than extorted, the FBI directs victims to contact their bank immediately and request a recall of the funds (FBI IC3, 2025 Internet Crime Report, p. 17).
That recall window generally closes within 24 to 72 hours. Recovery litigation against banks, exchanges, and payment processors follows when a recall fails.
Recovery in 2025
3,900 kill-chain actions
The FBI’s Recovery Asset Team initiated 3,900 Financial Fraud Kill Chain actions in 2025, covering $1.16 billion in attempted theft.
Funds frozen
$679 million held
Banks froze $679 million of those funds, a 58 percent success rate. The FBI attributes results to complaints filed “as quickly as possible.”
Source: FBI IC3, 2025 Internet Crime Report, pp. 17–18, https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
How We Help
Dilendorf Law Firm PLLC provides nationwide representation as ransomware response counsel and cybercrime counsel. Our legal work proceeds alongside technical containment efforts, not after they are completed..
- Sanctions screening and a documented payment decision under OFAC guidance.
- Counsel-directed forensics that protect privilege.
- Federal law enforcement coordination, including IC3 complaints and recall requests.
- Nationwide notification analysis across every affected state.
- Insurance coverage review and denied-claim disputes.
- Recovery litigation against banks, exchanges, and payment processors.
Call at the moment ransoware payment is being considered. The record created in the first hours determines every later step.
Dilendorf Law Firm PLLC · New York · Nationwide Representation · 212.457.9797 · dilendorf.com
Frequently Asked Questions
Can our company be penalized for paying a ransom if we did not know the attacker was sanctioned?
Yes. OFAC may impose civil penalties on a strict-liability basis, so knowledge of the recipient’s status is not required (OFAC Advisory, p. 4).
The exposure extends to companies that facilitate a payment on a victim’s behalf (OFAC Advisory, p. 1). Wallet screening before authorization is the only reliable safeguard.
Should we contact law enforcement before deciding whether to pay?
Yes. OFAC treats a company’s self-initiated and complete report to law enforcement, made as soon as possible after discovery, as a significant mitigating factor in any enforcement action (OFAC Advisory, p. 5).
The report begins with a complaint at ic3.gov. Anyone affected by a cyber-enabled crime may file, including non-U.S. persons (IC3 FAQ).
Can our IT vendor commission the forensic report?
It can, but the report may then be discoverable by regulators and plaintiffs. A forensic examination directed by counsel for the purpose of providing legal advice has a materially stronger privilege posture.
The FTC recommends consulting counsel and considering independent forensic investigators as part of the response team (FTC Data Breach Response Guide). The order of engagement matters.
How quickly do we need to preserve logs?
Immediately, and before remediation begins. Cloud audit logs, mailbox sign-in records, and endpoint telemetry commonly expire within 30 to 90 days under default retention settings.
The FTC instructs businesses not to destroy forensic evidence during investigation and remediation (FTC Data Breach Response Guide). Rebuilding a system without a preserved image may erase the record permanently.
Do we have to notify individuals who live in other states?
Usually, yes. Notification duties are triggered by the residence of the affected individuals, and every state, the District of Columbia, Puerto Rico, and the Virgin Islands has a breach notification law (FTC Data Breach Response Guide).
Deadlines, content requirements, and regulator notice thresholds differ by state. Regulated industries may face additional sector-specific requirements.
Will our cyber insurance pay the ransom?
It depends on the policy language. Many policies carry an extortion sublimit far below the stated limit and exclude digital assets.
Policies written in the Lloyd’s market also contain state-backed cyberattack exclusions following Market Bulletin Y5381, effective 31 March 2023. Counsel reviews these provisions before notice is given and handles any denial.
Can stolen funds be recovered after a fraudulent wire transfer?
Possibly, depending on the facts and the speed of the response. The FBI directs victims to contact their financial institution immediately to request a recall and any necessary indemnification documents (FBI IC3, 2025 Internet Crime Report, p. 17).
A prompt IC3 complaint supports the FBI’s Recovery Asset Team process, which froze 58 percent of attempted theft in 2025 (FBI IC3, 2025 Internet Crime Report, pp. 17–18). When a recall fails, recovery claims against banks, exchanges, and payment processors may follow.
When should we retain a ransomware lawyer?
Before any payment decision is made and before remediation begins. Sanctions screening, privilege over forensics, evidence preservation, and notification deadlines all depend on decisions made in the first hours.
Dilendorf Law Firm PLLC serves as incident response counsel for clients in any state. We coordinate with independently retained investigators and forensic examiners with federal law enforcement backgrounds.
Attorney Advertising. Prior results do not guarantee a similar outcome. This is not legal advice.
Sources
[1] U.S. Department of the Treasury, Office of Foreign Assets Control, “Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments,” Sept. 21, 2021. https://ofac.treasury.gov/media/912981/download?inline
[2] Financial Crimes Enforcement Network, “Advisory on Ransomware and the Use of the Financial System to Facilitate Ransom Payments,” FIN-2021-A004, Nov. 8, 2021. https://www.fincen.gov/sites/default/files/advisory/2021-11-08/FinCEN%20Ransomware%20Advisory_FINAL_508_.pdf
[3] Federal Trade Commission, “Data Breach Response: A Guide for Business.” https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business
[4] FBI Internet Crime Complaint Center, “Frequently Asked Questions.” https://www.ic3.gov/Home/FAQ
[5] FBI Internet Crime Complaint Center, “2025 Internet Crime Report,” pp. 7–8 (crime types and losses), 16 (ransomware), 17–18 (Recovery Asset Team and Financial Fraud Kill Chain). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[6] Lloyd’s, Market Bulletin Y5381, “State backed cyber-attack exclusions,” effective 31 March 2023. [Partner to confirm URL before publication.]

