My business's systems were hit by ransomware, what are our legal obligations and options?
Our company's servers were encrypted by ransomware demanding cryptocurrency payment, and we're unsure whether to pay or what we're legally required to do. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.
My business's systems were hit by ransomware, what are our legal obligations and options? is governed in India primarily by Information Technology Act, 2000 – Section 66, CERT-In Directions, 2022 and Digital Personal Data Protection Act, 2023 – Section 8. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.
Deploying ransomware to encrypt systems and extort payment is an offence under Section 66 (hacking/data theft) and Section 43 of the IT Act, and paying the ransom does not shield you from separate breach-notification obligations.
Under CERT-In's 2022 Directions, ransomware attacks must be reported to CERT-In within 6 hours of noticing the incident, regardless of the severity or whether you plan to pay the ransom.
If personal data of customers/employees was compromised, Section 8 of the DPDP Act requires notifying the Data Protection Board and affected individuals of the breach, with heavy penalties for non-disclosure.
Paying the ransom is legally risky since it could inadvertently fund sanctioned entities or organised crime, and law enforcement (police cyber cells, CERT-In) generally advise against payment as it doesn't guarantee data recovery.
Engage a certified forensic incident response team immediately to preserve evidence, contain the breach, and support both the CERT-In report and any subsequent police complaint.
What to do next: 1) Isolate affected systems immediately to prevent further spread; 2) Report the incident to CERT-In within 6 hours as mandated; 3) Notify the Data Protection Board and affected data principals if personal data was compromised; 4) Engage a forensic response team and file a police complaint under Section 66 IT Act.
If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Information Technology Act, 2000 – Section 66 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.
Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.