To include requirements relating to ransomware attack deterrence for a covered U.S. financial institution in the Consolidated Appropriations Act, 2021, and for other purposes.
About This Bill
Committee
Latest Action · April 11, 2024
Referred to the House Committee on Financial Services.
This bill creates new rules for major financial institutions to follow when they fall victim to ransomware attacks, which are cybercrimes where hackers block access to computer systems and demand payment to restore them. The legislation applies to large banks, stock exchanges, and critical financial technology providers designated as systemically important by federal regulators. Under the new requirements, these institutions must notify the Financial Crimes Enforcement Network before paying ransoms and cannot pay more than $100,000 without written authorization from federal law enforcement. The bill provides legal protection for financial institutions that comply with these rules, preventing them from being punished by regulators or prosecuted under money laundering laws for making approved ransomware payments. The rules take effect either 30 days after implementing regulations are published or one year after enactment, whichever comes first, and automatically expire 10 years after that date.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.