The short version
- Ransomware is the dominant cyberattack in Washington's breach records. It made up 58% of cyberattacks reported to the Attorney General from July 2023 to July 2026, and businesses filed 231 of the 592 ransomware notices on record, more than any other sector.
- One attack, five coverage parts. Extortion, breach response, data restoration, business interruption, and often privacy liability all respond.
- The ransom is the smaller question. Downtime, restoration, and notification usually matter more, and attackers increasingly steal data as well as encrypting it.
- Paying is not automatic. Federal sanctions rules prohibit payments to sanctioned groups, and insurers require their approval and their advisors.
- Coverage depends on controls. Insurers may decline, exclude, or limit ransomware without multifactor authentication and separated backups.
How a ransomware attack unfolds, and what pays for it
| Stage | What happens | Coverage part |
|---|---|---|
| Discovery | Files are encrypted and a ransom note appears, often overnight or on a weekend | Breach response (hotline, breach attorney) |
| Investigation | Forensic investigators find how attackers got in and what they took | Breach response (forensics) |
| Negotiation | Specialists contact the attackers, verify claims, and check sanctions lists | Cyber extortion |
| Decision | Restore from backups, or pay for a decryption key if lawful and approved | Data restoration, or cyber extortion |
| Recovery | Systems are rebuilt and cleaned, sometimes over days or weeks | Data restoration; business interruption for lost income |
| Notification | If data was accessed or stolen, affected people and regulators must be told | Breach response (notification, call center, monitoring) |
| Claims | Customers, patients, or clients sue over exposed data | Privacy liability; regulatory defense |
Double extortion: why ransomware is usually a breach too
Many ransomware groups copy data before encrypting it, then threaten to publish it unless paid. That changes the response:
- Restoring from backups does not end it. The data is already out.
- Breach notice may be required. In Washington, unauthorized acquisition of personal information triggers notice within 30 days of discovery unless the breach is not reasonably likely to cause harm. See Washington data breach notification law.
- Liability exposure rises. People whose data was taken can bring claims.
Forensic investigators determine whether data left your network, which is one reason to engage them immediately through your insurer.
The ransom question
| Consideration | What it means for you |
|---|---|
| Sanctions | The U.S. Treasury's Office of Foreign Assets Control warns that ransom payments to sanctioned persons or groups can violate federal law, regardless of whether the victim knew |
| Insurer approval | Most policies cover a ransom only with the insurer's prior written consent |
| Law enforcement | The FBI and CISA discourage paying, and OFAC treats prompt reporting and cooperation with law enforcement as mitigating factors |
| No guarantee | Paying may not produce a working key, and does not ensure stolen data is deleted |
| Coinsurance and sublimits | Some policies make you share a percentage of ransom and extortion costs |
In practice, the decision is made with the breach attorney, the insurer, and its negotiators. Businesses with good, separated backups often restore without paying.
What the FBI sees
The FBI's Internet Crime Complaint Center received 3,156 ransomware complaints in 2024. The FBI notes that the reported losses do not include lost business, time, wages, files, or equipment, or the cost of outside remediation, and that many victims do not report a loss amount at all. For a small business, those excluded costs, especially downtime, are usually the largest part of the bill.
Where Washington ransomware notices come from
From Trella Commercial's analysis of Washington Attorney General breach notices, 2015 to 2026:
| Sector | Ransomware notices filed |
|---|---|
| Businesses | 231 |
| Health care | 114 |
| Nonprofits and charities | 85 |
| Finance | 74 |
| Education | 73 |
Only breaches affecting more than 500 Washington residents are filed, so smaller incidents do not appear.
What insurers require for ransomware coverage
Because ransomware drives so many claims, insurers focus on the controls that stop it:
- Multifactor authentication on email, remote access, and administrator accounts
- Backups that are offline, immutable, or otherwise separated, and tested by restoring
- Endpoint detection and response on every computer and server
- No remote desktop exposed to the internet, and prompt patching of known vulnerabilities
- Separate administrator accounts used only for admin work
Missing controls can mean a declined application, a ransomware exclusion, a lower sublimit, or coinsurance. See what a cyber insurance application asks.
The first steps if you are hit
- Disconnect affected devices from the network, but do not turn them off or wipe them; forensics needs them.
- Call your insurer's breach hotline or your broker before contacting the attackers or hiring vendors.
- Do not pay or negotiate on your own. Let the insurer's negotiators and breach attorney handle contact.
- Report to the FBI through ic3.gov or your local field office, as your advisors direct.
- Check your backups without connecting them to infected systems.
- Start the clock. If personal information was accessed, Washington's 30-day notice period runs from discovery.