zlacker

[parent] [thread] 6 comments
1. yreg+(OP)[view] [source] 2025-11-13 11:58:27
> Until there is legislation to stop these payments, there will be countless situations where paying is simply the best option.

Paying the ransom is not exactly legal, is it? Surely the attackers don't provide you with a legitimate invoice for your accounting. As a company you cannot just buy a large amount of crypto and randomly send it to someone.

replies(2): >>wallet+X4 >>mapont+X6
2. wallet+X4[view] [source] 2025-11-13 12:37:09
>>yreg+(OP)
Paying the ransoms is almost always legal in basically all western countries unless the recipient has been sanctioned.

> As a company you cannot just buy a large amount of crypto and randomly send it to someone.

You can totally do that, why wouldn’t you be able to?

replies(1): >>yreg+Ad
3. mapont+X6[view] [source] 2025-11-13 12:50:37
>>yreg+(OP)
Most of the time the company doesnt pay directly.

They hire a third party, sometimes their cyber insurance provider, to "cleanup" the ransomware. That third party then pays another third party who is often located in a region of the world with lax laws to perform the negotiations.

At the end of the day nobody breaks any laws and the criminals get paid.

◧◩
4. yreg+Ad[view] [source] [discussion] 2025-11-13 13:33:36
>>wallet+X4
Because its fraud. You cannot just take money out of the company, you have to put something in your books.
replies(1): >>wallet+ji
◧◩◪
5. wallet+ji[view] [source] [discussion] 2025-11-13 14:03:23
>>yreg+Ad
So you obviously put “ransomware payment” in the books.
replies(1): >>yreg+xg2
◧◩◪◨
6. yreg+xg2[view] [source] [discussion] 2025-11-14 00:46:13
>>wallet+ji
What invoice or receipt do you include?
replies(1): >>wallet+VQ2
◧◩◪◨⬒
7. wallet+VQ2[view] [source] [discussion] 2025-11-14 07:59:18
>>yreg+xg2
That’s something you don’t actually have to do anywhere I know of.

Sure, in the US, you want to have those things to prove your expenses to the IRS, but it’s all pretty freeform. You could just document the ransomware payment process with screenshots, for example.

Besides, if you ask, I’m sure the ransomware group will send you a very professional-looking invoice and receipt.

Normally, you’d be going through an IR company anyway, who would invoice you and handle the payment process on your behalf.

[go to top]