Bitcoin Ransomware Response: A Four-Step Plan for Firms
A ransomware attack that demands payment in Bitcoin puts any firm, bank, or corporate treasury in unfamiliar territory almost instantly. The clock is ticking, the technical steps are non-trivial, and the compliance obligations do not pause simply because the organisation is under duress. Blockchain intelligence firm Elliptic has published a structured four-step response framework built on casework across the United States, United Kingdom, and European Union, and it has direct implications for how accounting teams and CFOs should prepare their crypto-incident procedures today.
Why Bitcoin Ransomware Is a Distinct Operational and Compliance Problem
Ransomware is not a new threat, but its intersection with cryptocurrency creates a specific set of challenges that conventional IT incident response plans rarely address. When an attacker delivers a Bitcoin payment address alongside a deadline, the organisation must simultaneously make a legal and financial decision (pay or not pay), execute a technical transaction it may never have performed before, and preserve evidence for law enforcement, all under severe time pressure.
The Misconception That Nothing Can Be Done
A common assumption is that once a ransom is paid in Bitcoin, any trail goes cold. Elliptic's co-founders directly challenge that view. Bitcoin transactions are public and permanent on the blockchain. With the right investigative tooling and law-enforcement coordination, it is possible to trace fund flows, cluster addresses, and attribute activity to real-world actors. The irreversibility of a transaction is real, but irreversibility does not mean invisibility.
AML and Sanctions Exposure for Payers
For compliance officers and CFOs, the payment decision also carries regulatory risk entirely separate from the IT incident. In the US, the Treasury's Office of Foreign Assets Control (OFAC) has made clear that ransomware payments to sanctioned individuals or entities can expose the payer to civil liability, even where the firm did not know it was dealing with a sanctions target. In the UK, the Office of Financial Sanctions Implementation (OFSI) operates on a similar basis. EU firms face comparable restrictions under Council regulations on asset freezing. This means the payment assessment phase is not just a question of whether decryption is likely; it is also a sanctions screening exercise.
For firms already tracking their exposure to digital asset risks, our coverage of US compliance priorities for AML and fraud in 2026 sets out the broader regulatory context in which these incidents now sit.
The Four Steps in Detail
The Elliptic framework organises the response into four sequential phases. Each one has distinct accounting and compliance dimensions that internal teams need to understand before an incident occurs, not during it.
Step 1: Assess Whether Payment Is Warranted
Not every ransom demand should be paid, and not every payment will deliver the promised decryption. Elliptic notes that in some attacks, including the high-profile WannaCry campaign, there was no evidence at the time that the attacker ever intended to restore access to compromised machines. Before authorising any payment, a firm needs an expert assessment covering three questions: Can the ransomware be decrypted independently? Is there credible evidence the attacker has the capacity and intent to restore access on payment? Does the payment route touch any sanctioned address or entity?
From an accounting standpoint, the payment assessment phase also determines initial recognition. If the decision is made to pay, the organisation needs to establish whether the outflow will be treated as an operating expense, an extortion loss, or potentially a capital event depending on how Bitcoin is acquired and whether it is already held on the balance sheet. Under US GAAP, the relevant guidance on digital asset treatment has been evolving, and firms should ensure their crypto accounting software can correctly classify and document the transaction from acquisition through to settlement.
Step 2: Rapidly Access Sufficient Bitcoin
Ransomware operators typically set tight payment windows, sometimes as short as 24 hours. Most organisations do not hold Bitcoin on their treasury balance sheets. Acquiring a material amount of Bitcoin at short notice through a regulated exchange is harder than it sounds: KYC onboarding processes at exchanges are designed to prevent exactly the kind of rapid, large-volume purchase that a ransom scenario demands from a new account holder.
Elliptic's guidance highlights that firms should establish, in advance, relationships with exchanges and liquidity providers that can facilitate urgent acquisitions. This is a preparedness issue, not just an incident-response issue. For an accounting firm advising corporate clients, the practical recommendation is to include "rapid crypto access" alongside other business continuity provisions. If the client already holds Bitcoin or other digital assets on a custodied basis, the response time compresses significantly, but the transaction authorisation controls must still allow for emergency execution without creating insider-trading or governance issues.
Step 3: Construct and Execute the Transaction Correctly
Sending a large Bitcoin payment is not the same as a bank transfer. The transaction must be constructed with the correct fee level to ensure timely confirmation, the recipient address must be verified character by character (a single error means permanent loss of funds), and the transaction must be signed appropriately for the wallet architecture in use. Multi-signature wallets, hardware security modules, and cold-storage arrangements all add procedural steps that can be difficult to execute correctly under time pressure.
Critically, the attacker also needs to be able to identify which victim is making the payment. In multi-victim campaigns, a payment to the wrong address, or a payment that cannot be attributed, may result in no decryption even if funds clear. Elliptic offers both remote transaction preparation and on-site expert deployment for this phase.
For accounting teams, the transaction record generated at this stage is the foundation of the subsequent journal entry and audit trail. The on-chain transaction hash, the BTC amount, the USD or GBP equivalent at the time of broadcast (not settlement), and the wallet addresses involved all need to be captured and retained. Digital asset accounting software that can import transaction data directly from the blockchain removes the risk of manual transcription error and ensures the cost basis and fair-value figures are defensible.
Step 4: Forensic Tracing and Law Enforcement Collaboration
Once the payment is made, or in parallel with steps one through three, blockchain forensics begins. Elliptic's investigators use proprietary software to trace how the ransomware proceeds move through the Bitcoin network: through mixing services, through exchanges, or into clusters of addresses associated with known threat actors. This intelligence is shared with law enforcement agencies in the US, UK, and EU under formal collaboration arrangements.
The forensic step matters for accounting and compliance teams for two reasons. First, if law enforcement ultimately seizes recovered assets, there are asset-recognition questions about whether and when those funds re-enter the firm's balance sheet. Second, the forensic report, and any law-enforcement reference number, forms part of the documentation that supports a tax deduction claim for the loss and demonstrates to auditors that the firm acted in good faith and complied with its reporting obligations.
Understanding how blockchain analytics integrates with ongoing AML monitoring is covered in more depth in our article on how continuous monitoring closes the post-screening risk gap.
Accounting and Reporting Implications by Jurisdiction
The accounting treatment of a ransomware payment differs by standard and by the specific facts of the transaction. The table below outlines the key considerations across the three primary jurisdictions covered by Elliptic's framework.
| Jurisdiction | Accounting Standard | Key Ransomware Payment Consideration |
|---|---|---|
| United States | US GAAP / ASC 350-60 | Bitcoin acquired for ransom payment is likely recognised at cost on acquisition; the payment itself is an operating loss or extortion expense; OFAC sanctions screening is mandatory before payment. |
| United Kingdom | UK GAAP / FRS 102 | Ransom payments are generally treated as an exceptional item within operating expenses; OFSI must be considered for sanctions compliance; HMRC guidance on crypto losses applies if Bitcoin is held prior to the event. |
| European Union | IFRS (IAS 38 / IFRS 9) | Crypto assets held or acquired for ransom settlement are assessed under existing intangible asset or financial instrument classification; EU sanctions regulations require pre-payment screening; disclosure under IFRS 7 risk reporting may be triggered. |
What Accounting Firms and CFOs Should Do Now
The Elliptic four-step plan is most useful when it is not new to the people executing it. A firm that encounters the framework for the first time during an active attack is already at a disadvantage. The preparation steps that accounting teams and finance functions can take in advance fall into three categories.
Policy and Procedure Readiness
Incident response plans should include a crypto-specific annex covering: the authorisation chain for approving a ransom payment, the sanctions screening process and which tool or service will be used, the wallet and exchange relationships needed to acquire Bitcoin rapidly, and the documentation protocol for capturing transaction data in real time. This annex should be reviewed and updated at least annually, given how quickly both the threat landscape and the regulatory environment move.
System and Software Readiness
Crypto accounting software and digital asset accounting software integrated into the firm's general ledger should be capable of ingesting blockchain transaction data and generating an auditable record without manual re-keying. Firms that use only spreadsheet-based crypto bookkeeping software are at material risk of error during a high-pressure incident, precisely when accuracy matters most. A pre-configured workspace for ransomware transaction recording, tested during a tabletop exercise, is a practical mitigation.
Regulatory Notification Readiness
In the US, the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI both operate ransomware reporting channels, and the Treasury's Financial Crimes Enforcement Network (FinCEN) has issued guidance indicating that ransomware payments may trigger Suspicious Activity Report (SAR) obligations for certain financial institutions. In the UK, firms should be familiar with their obligations to the National Cyber Security Centre (NCSC) and the Financial Conduct Authority (FCA) where applicable. EU firms must also consider NIS2 Directive incident reporting timelines. Knowing which notifications are required, and in what order, before an incident saves critical time during one.
The Broader AML Picture
Ransomware payments sit at the intersection of cybercrime and financial crime. The proceeds of ransomware attacks are laundered through cryptocurrency mixers, peer-to-peer exchanges, and in some cases through regulated exchanges with inadequate controls. Blockchain intelligence firms like Elliptic occupy a position in the financial crime ecosystem where their exchange-facing alert services and law-enforcement collaboration can disrupt that laundering chain. For compliance teams at banks and exchanges, receiving an alert that incoming funds are linked to a ransomware wallet is an immediate trigger for a SAR filing and, potentially, for asset freeze under applicable sanctions law.
This is also why the choice of blockchain analytics provider matters for exchanges and custodians. A provider that actively monitors ransomware wallet clusters and alerts counterparties in real time is providing a qualitatively different service from one that offers only retrospective transaction tagging.
Source: Elliptic
Frequently Asked Questions
Does paying a Bitcoin ransom create a tax-deductible loss?
In most cases, yes, a ransom payment made in the ordinary course of protecting business operations can be treated as a deductible business expense, but the specific treatment depends on the jurisdiction and the facts. In the US, the IRS generally allows deductions for theft and extortion losses subject to certain rules. In the UK, HMRC's approach depends on whether the payment is wholly and exclusively for trade purposes. EU treatment varies by member state. Firms should document the incident, the payment, the law enforcement report reference, and the business rationale before claiming the deduction.
What sanctions screening must a firm do before paying a ransomware demand?
In the US, OFAC has issued specific ransomware advisories stating that paying a designated entity or individual, even unknowingly, can result in civil liability. Firms should screen the payment address against OFAC's Specially Designated Nationals list and consult a blockchain analytics provider before authorising any transfer. In the UK, OFSI applies comparable rules. EU firms must check Council of the EU consolidated sanctions lists. If there is any doubt, legal counsel should be obtained and the relevant authority contacted before payment.
How should a ransomware payment be recorded in the general ledger?
The payment should be recorded at the fair value of the Bitcoin transferred at the point of transaction broadcast, converted to the firm's functional currency using a reliable exchange rate source. If Bitcoin was acquired specifically for the payment, the acquisition cost and any associated fees should also be captured. The resulting expense should be classified consistently with the firm's accounting policies, typically as an exceptional or non-recurring operating expense. The on-chain transaction hash should be stored as supporting documentation alongside the ledger entry.
Is a firm required to report a ransomware payment to financial regulators?
Potentially, yes. In the US, certain financial institutions are required to file a SAR with FinCEN when they have reason to suspect that a transaction involves funds from unlawful activity, and a ransomware payment may meet that threshold. CISA and the FBI both encourage voluntary reporting. In the UK, the National Crime Agency (NCA) operates the Suspicious Activity Reports regime, and firms in the regulated sector have mandatory reporting obligations. EU firms should review their obligations under the Anti-Money Laundering Directives and national transpositions. Non-reporting can itself constitute a compliance failure.
What documentation should be preserved after a ransomware incident for audit purposes?
Auditors will want to see: the original ransom demand and any attacker communications; the internal approval chain for the payment decision, including evidence of sanctions screening; the blockchain transaction record with hash, timestamp, amount in BTC and functional currency equivalent, and wallet addresses; any law enforcement reference number or report; the forensic investigation report if one was produced; and evidence of regulatory notifications made. This documentation supports both the financial statement presentation and any insurance claim or legal recovery action.
