Should you pay a ransom? The Canadian decision
Paying a ransom is not automatically illegal in Canada, but the Government of Canada does not recommend it. A payment that reaches a sanctioned person or a terrorist group can be an offence, paying does not guarantee your data back, and counsel and your insurer must be in the decision before any money moves. The decision is your organization’s, and police should hear about the attack before you consider paying.
What decides whether to pay?
| Question | Why it decides the answer |
|---|---|
| Can we recover without paying? | Tested, isolated backups turn the question into one of time, not survival |
| Is anyone’s safety at risk? | Health and critical services change what delay costs |
| Could the payment be unlawful? | Sanctions and terrorism offences apply to the payer |
| What does our insurer require? | Paying without its consent can put the claim at risk |
| Was data stolen as well as encrypted? | Payment cannot make stolen data un-stolen |
Is it legal to pay a ransom in Canada?
No Canadian law bans ransom payments as such, but a payment can be unlawful where it is caught by terrorism, money-laundering, criminal-organization or sanctions law. Whether a particular payment is lawful is a question for your counsel, answered before any money moves. Public Safety Canada’s 2023 committee notes on ransomware list the same grounds and say the Government of Canada does not recommend paying. As of September 2026, the laws counsel will look at first are these:
- Special Economic Measures Act regulations and the Justice for Victims of Corrupt Foreign Officials Act, whose listed persons appear on the Consolidated Canadian Autonomous Sanctions List.
- Section 83.03 of the Criminal Code, which makes it an offence to wilfully provide property knowing it will be used by or benefit a terrorist group, read with the list of terrorist entities.
- Money-laundering and criminal-organization offences, which the Canadian Centre for Cyber Security (the Cyber Centre) names in its ransomware playbook as grounds on which paying may be unlawful.
The hard part is attribution. You rarely know who controls the wallet, and ransomware brands rename and share infrastructure. That uncertainty is exactly what counsel has to weigh, which is why the analysis starts on day one, not at the deadline.
Does paying get the data back?
Not reliably. The Canadian Centre for Cyber Security warns that paying does not guarantee access to your data, and that attackers may still demand more, leak what they took, or attack you again. The Cyber Centre’s ransomware playbook also notes that some attackers use wiper malware that destroys files after payment. Even a working decryptor can be slow and incomplete, so recovery is still a restore project either way.
Where data was stolen, payment buys only a promise from a criminal to delete it. Counsel’s view on notification is formed on the facts of the theft, and a payment does not change those facts.
What do your insurer and counsel need?
Read the policy before you need it. Many cyber policies require the insurer’s consent before a payment, name a panel of responders, and set short notice windows; acting first and telling them later can prejudice the claim. What insurers look for is in what cyber insurers check at claim time. Your organization decides, with counsel advising on the law and your insurer involved where the policy requires its consent. We help you prepare for that decision and work alongside you during an incident, but the decision is never ours to make.
Investigation and forensic work that informs the decision is delivered with appropriately licensed partners where the law requires it, usually engaged through counsel. Our incident response and forensics page sets out how that works.
Should you report a ransomware attack?
Yes, and before you consider paying, which is the Cyber Centre’s own advice. Report to your local police, the Canadian Anti-Fraud Centre and the Cyber Centre; the decision on payment still rests with your organization. The ransomware playbook says to contact your local police before you even consider paying. The Cyber Centre takes reports through its incident management page. What to expect from police is in working with police after a cyber incident.
How do you prepare for the decision?
The best ransom decision is made months earlier by people who are not frightened: who has authority to decide, how long the business can run without each system, whether backups have been restored for real, and what the policy says. That preparation is ransomware readiness and resilience; the first day of a live incident is covered in the first 24 hours.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
Investigation and forensic work is delivered with appropriately licensed partners where the law requires it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Is it legal to pay a ransom in Canada?
No Canadian law bans ransom payments as such, but a payment can be unlawful where it is caught by terrorism, money-laundering, criminal-organization or sanctions law. Whether a particular payment is lawful is a question for your counsel, answered before any money moves.
Will paying get our data back?
Not reliably. The Canadian Centre for Cyber Security warns that paying does not guarantee access to your data, and that attackers may still demand more, leak what they took, or attack you again.
Should we report to police?
Yes, and before you consider paying, which is the Cyber Centre’s own advice. Report to your local police, the Canadian Anti-Fraud Centre and the Cyber Centre; the decision on payment still rests with your organization.
Who decides whether to pay?
Your organization decides, with counsel advising on the law and your insurer involved where the policy requires its consent. We help you prepare for that decision and work alongside you during an incident, but the decision is never ours to make.
Before the demand arrives
If you are facing a demand now, call counsel and your insurer first. If you are not, send us your incident plan and policy summary; the reply says what a ransom decision would be missing. More of our writing is indexed at writing.