HALVERTON & CO.

Technology & AI Law · 6 October 2026 · 7 min read

Ransomware and Cyber Insurance: Can Indian Companies Legally Pay a Ransom?

An infographic on ransomware and cyber insurance showing the CERT-In 6-hour rule, DPDP breach notification, sanctions and AML exposure, and typical cyber insurance policy conditions.

It’s the call every CEO dreads. Your systems are encrypted, customer data has been stolen, and a message on the screen demands payment in Bitcoin within 72 hours. Your operations team says paying will be faster than restoring from backups. Your insurer wants to talk first. And someone asks the question that should come first: is it even legal for an Indian company to pay a ransom?

This guide explains the legal position on ransomware payments in India, the anti-money laundering, foreign exchange and anti-terror risks, your reporting duties, how cyber insurance responds, and the remedies available after an attack.

The short answer is that no Indian law expressly prohibits paying a ransom or declares it illegal. Unlike some countries that have debated outright bans, India has no specific ransomware payment statute. We are not aware of any reported Indian prosecution of a victim for paying a ransom.

That doesn’t make paying safe. Negotiating with threat actors and paying them creates a complex mix of ethical, operational and legal risks. The payment can become illegal depending on who receives it and how it’s made. A ransom paid to a terrorist organisation banned under the Unlawful Activities (Prevention) Act, or in a way that violates the Prevention of Money Laundering Act, can turn a victim into an offender.

Authorities also discourage payment. During the WannaCry outbreak in 2017, CERT-In’s advice was not to pay, because payment encourages more attacks. And paying doesn’t guarantee recovery: decryption keys may not work, and stolen data may be leaked anyway.

Most of the legal risk sits in four places. First, anti-money laundering. Ransom payments carry heightened exposure under India’s anti-money laundering framework, because the money becomes proceeds of crime in the attacker’s hands, and anyone who knowingly assists in dealing with those proceeds risks exposure under the PMLA.

Second, foreign exchange. Ransoms are usually demanded in cryptocurrency and paid to unknown persons abroad. Payments involving foreign remittances or crypto may trigger compliance concerns under FEMA, and misdescribing the purpose of a payment to a bank to get it through creates further liability. Our guides to stablecoins in India and crypto tax explain the related crypto rules.

Third, terrorism. If the threat actor is linked to a banned terrorist organisation, payment can violate the UAPA. Fourth, international sanctions. Many ransomware groups are on US or other sanctions lists, and legal counsel should check the attacker’s crypto wallet against international sanctions lists before any negotiation. For Indian companies with US operations, banking relationships or investors, a sanctioned payment can have serious consequences abroad.

Where the legal risk of paying a ransom sits
RiskWhy it arises
PMLAThe ransom becomes proceeds of crime; knowingly assisting in dealing with it risks exposure
FEMACrypto or foreign remittances to unknown overseas persons, and any misdescription to a bank
UAPAPayment to a group linked to a banned terrorist organisation
SanctionsPayment to a wallet linked to a US or other sanctioned group, with consequences for banks and investors abroad

Your reporting duties after a ransomware attack

A ransomware attack triggers reporting obligations whether or not you pay. CERT-In’s 2022 directions require body corporates to report specified cyber incidents, including ransomware, within six hours of noticing them; see our guide to the CERT-In 6-hour rule. Once the DPDP Act’s main obligations apply from 13 May 2027, a personal data breach must be reported to the Data Protection Board and affected individuals without delay, with a detailed report to the Board within 72 hours. Our DPDP Act compliance checklist covers the process.

Sector regulators have their own rules. SEBI-regulated entities, for example, are covered by SEBI’s Cyber Security and Cyber Resilience Framework, and the RBI and IRDAI impose similar duties on banks and insurers. Contracts with customers often add notification obligations too.

Keep a careful timeline from the first sign of the attack. Regulators, insurers and courts will all want to know when you noticed the incident, when you reported it and what you did, and a contemporaneous log is the best evidence. Extortion is also a crime. Filing a police complaint matters for the investigation, and insurers often require an FIR to validate an extortion event and trigger ransom coverage. Report on the National Cyber Crime Reporting Portal as well.

How cyber insurance responds to ransomware

Ransomware coverage under Indian cyber insurance policies is usually part of a broader “cyber extortion” or “cyber crime” cover and is commonly subject to sub-limits. Policies often also cover consequential losses: forensic investigation, legal advice, data restoration, business interruption and notification costs.

The conditions matter as much as the cover. Most policies require prior notification and the insurer’s consent before any ransom payment, and paying without telling the insurer first is one of the most common grounds for a coverage dispute. Many insurers require you to use their approved panel of forensic investigators and lawyers. And ransom payment is generally covered only where it is legal under Indian law.

Insurers also look closely at what happened before the attack. Claims can be disputed where the insured didn’t maintain the security controls declared in the proposal form, such as multi-factor authentication, patching or offline backups, so the accuracy of what you tell your insurer at renewal matters as much as the claims process itself. Read your policy now, not during an attack. Check the extortion sub-limit, the notification and consent requirements, the panel vendors, the exclusions (such as for unpatched systems or state-sponsored attacks) and whether regulatory fines are covered where the law permits.

A ransomware response plan, remedies and quick answers

Small and mid-sized companies are increasingly targeted precisely because attackers assume they lack backups and incident plans. A short ransomware playbook, reviewed once a year, is one of the cheapest forms of protection available. Think about the decision itself, too. Paying a ransom is ultimately a board-level business decision, taken with legal advice, after considering whether backups can restore operations, whether the attacker is sanctioned or linked to terrorism, what the insurer will agree to, and what regulators and customers will expect. Documenting that decision process protects directors if the payment is later questioned.

A good ransomware response plan decides the hard questions in advance: who has authority to decide on payment, which lawyers, forensic firms and negotiators you’ll call, how you’ll meet the six-hour CERT-In deadline, and how you’ll communicate with customers. Tested offline backups remain the best reason never to need to pay. If staff use unapproved AI tools, data can leak long before any attack; see our guide to AI tools at work and confidentiality.

After an attack, the legal remedies include a criminal complaint for extortion and offences under Sections 43 and 66 of the IT Act, claims against vendors whose failures caused the breach, an insurance claim under the policy, and court orders to take down stolen data published online. Recovering paid ransoms is rare, but law enforcement can sometimes trace and freeze crypto wallets, so report early. Where an exchange is the victim, see our guide to what to do when a crypto exchange is hacked.

Quick answers

Is paying a ransom illegal in India?

No law expressly prohibits it, but payment can breach the PMLA, FEMA, UAPA or international sanctions depending on who receives it and how it’s paid.

Do I have to report a ransomware attack?

Yes. CERT-In requires reporting within six hours, and DPDP breach reporting applies from 13 May 2027, plus any sectoral rules.

Will my cyber insurance pay the ransom?

Possibly, if your policy covers cyber extortion, you get the insurer’s prior consent, and the payment is legal.

Final word

At Halverton & Co., we advise founders, technology companies, investors and individuals on ransomware response, cyber insurance claims, CERT-In and DPDP breach reporting. We practise in Jharkhand, Maharashtra and before the Supreme Court of India, and act as fractional legal counsel for technology-driven businesses that need senior legal support without a full in-house legal team. Halverton & Co. is built on a simple idea: Where tech needs law! If this issue affects you or your business, write to us at office@halvertonandco.com, or get in touch, and we’ll help you work out where you stand.

This article reflects the law and developments reported up to early October 2026. It is for general information only and is not legal advice. Please take advice on your specific facts before acting.

Related practice area

Technology & AI Law

Contracts, data protection and AI policies for products that handle other people’s data.

View the practice area
Email this

This article is part of our Technology and AI law guides.

Questions

Write to us about what you are building.

This article is general information, not legal advice for your situation. If something here applies to your business, tell us briefly what you are working on.