Ransomware Payments
A ransomware attack locks a company's systems and demands crypto for the key to unlock them. Germany's cybersecurity authority advises against paying, but the decision sits with the victim, and the legal picture around it has several separate layers: reporting the incident, checking the demand against sanctions lists, and tracing the payment once it leaves the company's wallet. Each layer applies regardless of whether the company decides to pay.
The BSI's position: paying does not end the problem
Germany's Federal Office for Information Security, the BSI, advises companies against paying a ransom. Its reasoning covers several points: payment does not guarantee a working decryption key, it marks the company as willing to pay for future attacks, and it does nothing to remove the malware still present on the network. Paying also does not end a company's other duties. It does not satisfy the requirement under the EU's NIS2 framework to maintain recoverable backups, and it does not stop a criminal investigation the company may still be obliged to support.
NIS2 in Germany: a 24-hour reporting clock
The new German BSI Act, transposing the EU's NIS2 Directive, puts cybersecurity incidents on a board-level reporting clock for companies in critical and important sectors, which include much of financial services. A significant incident needs an initial notification to the BSI within 24 hours of the company becoming aware of it, followed by fuller reports later. NIS2 does not force a company to disclose whether it paid a ransom, but a ransomware incident serious enough to disrupt operations or expose data almost always crosses the threshold that triggers the reporting duty on its own, which puts the incident on the BSI's radar regardless of the payment decision.
Sanctions risk: paying the wrong wallet is illegal on its own
Paying a ransom is not itself illegal under EU law, but paying a sanctioned person or entity is, independent of the ransomware angle. Several major ransomware groups and their known wallet addresses appear on sanctions lists maintained by the US Treasury's Office of Foreign Assets Control (OFAC) and by the EU. A company facing a ransom demand, or the payment facilitator it hires to negotiate, has to screen the demanded wallet address against these lists before sending funds, exactly the sanctions screening duty payment institutions already run on every transfer.
What happens to the payment after it is sent
Once a ransom moves onchain, it becomes a target for blockchain forensics: investigators and insurers trace the funds through the same wallets and exchanges that any other stolen crypto passes through. The Chainalysis 2026 Crypto Crime Report tracks ransomware among the categories feeding into the 154 billion US dollars received by illicit addresses in the prior year, and notes that state-linked groups now run some of the largest ransomware operations, which is part of why sanctions checks on the receiving wallet matter as much as the decision to pay.
Upcoming events on compliance and digital assets
Finance Loop and ransomware payments
Ransomware sits at the crossing point of the topics Finance Loop's compliance events cover: sanctions law, payment security and blockchain tracing. At When Banks Say 'No' in Frankfurt, Dr. Julia Pfeil of Dentons spoke on payments governed by sanctions and anti-money laundering law. Ransomware belongs to Finance Loop's Risk & Compliance track, next to blockchain forensics and crypto AML.
Risk & Compliance
Payments & Digital Money
Should a company ever pay a ransomware demand?
The BSI advises against it, and German and EU law enforcement agree, since payment funds future attacks without guaranteeing recovery. The decision stays with the company, but it does not remove the duty to report the incident, restore from backups, or screen the demanded wallet against sanctions lists first.
Does a company have to report a ransomware payment?
NIS2, transposed in Germany through the BSI Act, requires companies in critical and important sectors to report a significant cybersecurity incident to the BSI within 24 hours of discovery. The rule targets the incident itself, not specifically the payment, but a ransomware attack serious enough to demand a ransom almost always meets that threshold.
Can a ransomware payment violate sanctions law?
Yes, if the wallet or entity receiving the payment is on a sanctions list maintained by OFAC or the EU. This risk exists independent of whether paying a ransom is otherwise legal, and it is why companies negotiating a ransom, or the firms they hire to do so, screen the receiving address before any funds move.
Ransomware Payments and Finance Loop
Ransomware payments touch the same rules Finance Loop's payments and compliance events cover: sanctions screening and anti-money laundering law, addressed at the When Banks Say 'No' seminar in Frankfurt for treasury, legal and compliance teams. The topic sits in Finance Loop's Risk & Compliance track, alongside blockchain forensics and crypto AML.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi.