Australia may soon introduce new laws that ban local companies from paying ransom to hackers if they fall victim to data breaches.
Speaking to the Australian Broadcasting Corporation’s Insiders program on Nov. 13, Home Affairs Minister Clare O'Neil said the federal government was considering whether it was necessary to make ransom payments illegal following the high-profile cyber attacks on Medibank and Optus.
The minister said while short-term successes were needed in cyber security reform in the wake of the data breaches, the government was examining other long-term outcomes, including a ban on ransom payments.
“We'll have a look at [making ransom payments illegal].”
O'Neil also approved of Medibank’s rejection of paying the ransom demanded by the hackers amid the threat of further sensitive data release, saying it was the right move.
“The idea we’re going to trust these people to delete data they have taken off and may have copied a million times is just, frankly, silly ... we don’t want to fuel the ransomware business model.”
Australian Government Sets up Policing Operation Targeting Hackers
Turning to another topic, O'Neil said the government was setting up a high-tech task force composed of the best cyber experts to proactively go after hackers targeting Australians.Regarding the rationale behind the move, the minister said Australia needed to improve its response to cyber offences due to their number.
To illustrate, she said the National Australia Bank was subject to 50 million attacks a month, while the Australian Taxation Office got three million.
“I don’t think anyone can promise cyber attacks are going to go away, and one of the things people need to understand is really how relentless this is,” she said.
In addition, O'Neil said there was a need for a mechanism ensuring companies only retained customer data when it was useful and that the government was reviewing the privacy law in this regard.
Meanwhile, Nationals leader David Littleproud said he wanted to work closely with the government to fast-track the introduction of new legislation ensuring better cyber security protection for Australians.
“There’s an opportunity to actually expedite it. It comes down to action, and action is not about words.”