Medibank and Optus: Cyber extortion 101: To pay (a ransom), or not to pay (a ransom) – that is the question

Medibank and Optus: Cyber extortion 101: To pay (a ransom), or not to pay (a ransom) – that is the question

Ransomware Surge in Australia: Legal Risks, Regulatory Pitfalls, and Why Paying Isn’t the Answer

Nearly 100 Australian organizations have fallen victim to ransomware attacks this year, with many more likely unreported. The dilemma of whether to pay ransoms often demanded to prevent data leaks has become a critical issue for businesses, compounded by strict legal and regulatory consequences.

Under Australian law, paying a ransom to sanctioned entities, including groups like LockBit or those linked to the Iranian Revolutionary Guard Corps (IRGC), is illegal. Businesses face severe penalties, including federal money-laundering charges, even if they claim ignorance. Phoebe Chester, Practice Leader at LegalVision, emphasizes that paying ransoms not only funds criminal activity but also fails to guarantee data security, marking organizations as repeat targets.

The Australian Signals Directorate (ASD) advises against payment, urging instead a focus on prevention robust cybersecurity measures and tested backups to avoid negotiation with attackers. In the event of an attack, the first 24 hours are critical. Organizations must isolate affected systems without destroying forensic evidence, avoid unauthorized contact with threat actors, and consult legal and IT experts. Cyber insurers should be notified, and incidents reported to the Australian Cyber Security Hotline. Premature public statements or customer notifications risk regulatory backlash while facts remain unclear.

Refusing to pay does not exempt businesses from legal obligations. Under the Privacy Act, organizations must assess breaches, notify the Office of the Australian Information Commissioner (OAIC), and inform affected individuals within 30 days, regardless of ransom decisions. Failure to comply can result in penalties up to $50 million, three times the value of any benefit obtained, or 30% of adjusted turnover. Reputational damage is also a concern, with public sentiment increasingly critical of mishandled responses, as seen in high-profile breaches like Optus and Medibank.

The biggest misstep, according to Chester, is treating ransomware as an IT issue rather than a legal and regulatory crisis. Downplaying breaches before facts are verified or failing to document board-level decisions can attract scrutiny over director duties. Early legal involvement and transparent, well-documented responses are essential to mitigating risks.

Source: https://www.cyberdaily.au/security/14020-cyber-extortion-101-to-pay-a-ransom-or-not-to-pay-a-ransom-that-is-the-question

Medibank TPRM report: https://www.rankiteo.com/company/medibank

Optus TPRM report: https://www.rankiteo.com/company/optus

"id": "medopt1786343034",
"linkid": "medibank, optus",
"type": "Ransomware",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'Australia', 'type': 'Organizations'}],
 'customer_advisories': 'Avoid premature notifications; ensure compliance with '
                        'Privacy Act requirements',
 'data_breach': {'data_encryption': 'Yes (ransomware)',
                 'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Sensitive data, personally '
                                             'identifiable information'},
 'description': 'Nearly 100 Australian organizations have fallen victim to '
                'ransomware attacks this year, with many more likely '
                'unreported. The dilemma of whether to pay ransoms often '
                'demanded to prevent data leaks has become a critical issue '
                'for businesses, compounded by strict legal and regulatory '
                'consequences.',
 'impact': {'brand_reputation_impact': 'High (e.g., Optus, Medibank breaches)',
            'data_compromised': 'Data leaks',
            'legal_liabilities': 'Penalties up to $50 million, federal '
                                 'money-laundering charges'},
 'lessons_learned': 'Ransomware should be treated as a legal and regulatory '
                    'crisis, not just an IT issue. Early legal involvement and '
                    'transparent, well-documented responses are essential to '
                    'mitigating risks.',
 'motivation': 'Financial gain, data exfiltration',
 'post_incident_analysis': {'corrective_actions': 'Enhanced cybersecurity '
                                                  'measures, tested backups, '
                                                  'legal and regulatory '
                                                  'compliance improvements'},
 'ransomware': {'data_encryption': 'Yes',
                'data_exfiltration': 'Yes',
                'ransom_demanded': 'Yes',
                'ransomware_strain': 'LockBit'},
 'recommendations': ['Focus on prevention with robust cybersecurity measures '
                     'and tested backups',
                     'Isolate affected systems without destroying forensic '
                     'evidence in the first 24 hours',
                     'Avoid unauthorized contact with threat actors',
                     'Consult legal and IT experts immediately',
                     'Notify cyber insurers and report incidents to the '
                     'Australian Cyber Security Hotline',
                     'Avoid premature public statements or customer '
                     'notifications',
                     'Assess breaches and notify OAIC and affected individuals '
                     'within 30 days',
                     'Document board-level decisions to avoid scrutiny over '
                     'director duties'],
 'references': [{'source': 'LegalVision, Australian Signals Directorate (ASD), '
                           'Privacy Act, Optus and Medibank breaches'}],
 'regulatory_compliance': {'fines_imposed': 'Up to $50 million, 3x benefit '
                                            'obtained, or 30% of adjusted '
                                            'turnover',
                           'legal_actions': 'Federal money-laundering charges, '
                                            'regulatory backlash',
                           'regulations_violated': ['Privacy Act'],
                           'regulatory_notifications': 'Office of the '
                                                       'Australian Information '
                                                       'Commissioner (OAIC), '
                                                       'affected individuals '
                                                       '(within 30 days)'},
 'response': {'communication_strategy': 'Avoid premature public statements or '
                                        'customer notifications',
              'containment_measures': 'Isolate affected systems without '
                                      'destroying forensic evidence',
              'law_enforcement_notified': 'Australian Cyber Security Hotline',
              'recovery_measures': 'Tested backups, robust cybersecurity '
                                   'measures',
              'third_party_assistance': 'Legal and IT experts, cyber insurers'},
 'stakeholder_advisories': 'Board-level decisions should be documented to '
                           'mitigate legal risks',
 'threat_actor': ['LockBit',
                  'Groups linked to the Iranian Revolutionary Guard Corps '
                  '(IRGC)'],
 'title': 'Ransomware Surge in Australia: Legal Risks and Regulatory Pitfalls',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.