<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H9F997C370C6C4D12B0498D2CD61DDC6E" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 4551 IH: Reporting Attacks from Nations Selected for Oversight and Monitoring Web Attacks and Ransomware from Enemies Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-07-20</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 4551</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20210720">July 20, 2021</action-date><action-desc><sponsor name-id="B001257">Mr. Bilirakis</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend the U.S. SAFE WEB Act of 2006 to provide for reporting with respect to cross-border complaints involving ransomware or other cyber-related attacks, and for other purposes.</official-title></form><legis-body id="H145E4E3B85EA450D93B756A81CE8C8E6" style="OLC"><section id="HE3639D35BF8944E1952C797F68EA7D04" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Reporting Attacks from Nations Selected for Oversight and Monitoring Web Attacks and Ransomware from Enemies Act</short-title></quote> or the <quote><short-title>RANSOMWARE Act</short-title></quote>. </text></section><section id="HF540AECC96454538B89E9ECD88536FDD"><enum>2.</enum><header>Ransomware and other cyber-related attacks</header><text display-inline="no-display-inline">Section 14 of the U.S. SAFE WEB Act of 2006 (<external-xref legal-doc="public-law" parsable-cite="pl/109/455">Public Law 109–455</external-xref>; 120 Stat. 3382) is amended—</text><paragraph id="H2229AD9A30284E6D949278F65DD62773"><enum>(1)</enum><text>in the matter preceding paragraph (1)—</text><subparagraph id="H8672C6FD66A8421F9EE5D34812323F45"><enum>(A)</enum><text>by striking <quote>Not later than 3 years after the date of enactment of this Act,</quote> and inserting <quote>Not later than 1 year after the date of enactment of the <short-title>Reporting Attacks from Nations Selected for Oversight and Monitoring Web Attacks and Ransomware from Enemies Act</short-title>, and every 2 years thereafter,</quote>; and</text></subparagraph><subparagraph id="H079787435F574B6B89BC0F784B818A53" commented="no"><enum>(B)</enum><text>by inserting <quote>, with respect to the 2-year period preceding the date of the report (or, in the case of the first report transmitted under this section after the date of the enactment of the <short-title>Reporting Attacks from Nations Selected for Oversight and Monitoring Web Attacks and Ransomware from Enemies Act</short-title>, the 1-year period preceding the date of the report)</quote> after <quote>include</quote>;</text></subparagraph></paragraph><paragraph id="H7F21FC19D20148A1A3D4EC9D8640399F"><enum>(2)</enum><text>in paragraph (8), by striking <quote>; and</quote> and inserting a semicolon;</text></paragraph><paragraph id="H382FCAA62A59499C895660F899CEFAA5"><enum>(3)</enum><text>in paragraph (9), by striking the period at the end and inserting <quote>; and</quote>; and</text></paragraph><paragraph id="H6052206563B449459ED2697388C58CA8"><enum>(4)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" id="HE9FB5474E6234B9DA0E8B1928BD1E12E" display-inline="no-display-inline"><paragraph id="H3C2497544050497896CED143695E2E6A"><enum>(10)</enum><text display-inline="yes-display-inline">the number and details of cross-border complaints received by the Commission that involve ransomware or other cyber-related attacks—</text><subparagraph id="H2E3423350DE64750A5ECEFDBF3588FEA"><enum>(A)</enum><text display-inline="yes-display-inline">that were committed by individuals located in foreign countries or with ties to foreign countries; and</text></subparagraph><subparagraph id="H95A0633E7E154EAEA9AE9A6E8106BA44"><enum>(B)</enum><text display-inline="yes-display-inline">that were committed by companies located in foreign countries or with ties to foreign countries.</text></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section><section id="H231879B3FD2E4E54906AE6FB55F1C780"><enum>3.</enum><header>Report on ransomware and other cyber-related attacks by certain foreign individuals, companies, and governments</header><subsection id="HC1881D0C97BF4C2ABE36651A6899B189"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this Act, and every 2 years thereafter, the Federal Trade Commission shall transmit to the Committee on Energy and Commerce of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate a report describing its use of and experience with the authority granted by the U.S. SAFE WEB Act of 2006 (<external-xref legal-doc="public-law" parsable-cite="pl/109/455">Public Law 109–455</external-xref>) and the amendments made by such Act. The report shall include the following:</text><paragraph id="HCAF5CE7E7E1A41FD8AE783A0979D757C"><enum>(1)</enum><text display-inline="yes-display-inline">The number and details of cross-border complaints received by the Commission (including which such complaints were acted upon and which such complaints were not acted upon) that relate to incidents that were committed by individuals, companies, or governments described in subsection (b), broken down by each type of individual, type of company, or government described in a paragraph of such subsection.</text></paragraph><paragraph id="H0AE54E4D8B014130ADE07BF47C6D4F63"><enum>(2)</enum><text display-inline="yes-display-inline">The number and details of cross-border complaints received by the Commission (including which such complaints were acted upon and which such complaints were not acted upon) that involve ransomware or other cyber-related attacks that were committed by individuals, companies, or governments described in subsection (b), broken down by each type of individual, type of company, or government described in a paragraph of such subsection.</text></paragraph><paragraph id="HB4AFC23C5E42401A8A2EAD86E3BC9483"><enum>(3)</enum><text display-inline="yes-display-inline">A description of trends in the number of cross-border complaints received by the Commission that relate to incidents that were committed by individuals, companies, or governments described in subsection (b), broken down by each type of individual, type of company, or government described in a paragraph of such subsection.</text></paragraph><paragraph id="HDC72762E394F43D99F5B96BA5DAD4A14"><enum>(4)</enum><text display-inline="yes-display-inline">Identification and details of foreign agencies (including foreign law enforcement agencies (as defined in section 4 of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/44">15 U.S.C. 44</external-xref>))) located in Russia, China, North Korea, or Iran with which the Commission has cooperated and the results of such cooperation, including any foreign agency enforcement action or lack thereof.</text></paragraph><paragraph id="HFFB973F6F30246B4AE2DC3831F2DCF97"><enum>(5)</enum><text>A description of Commission litigation, in relation to cross-border complaints described in paragraphs (1) and (2), brought in foreign courts and the results of such litigation.</text></paragraph><paragraph id="HF92A6CACC34D4B0AB58FC8D8FFC7D5D3"><enum>(6)</enum><text>Any recommendations for legislation that may advance the mission of the Commission in carrying out the U.S. SAFE WEB Act of 2006 and the amendments made by such Act.</text></paragraph><paragraph id="HE18BA6958E1246839150C6A85A314C42"><enum>(7)</enum><text>Any recommendations for legislation that may advance the security of the United States and United States companies against ransomware and other cyber-related attacks.</text></paragraph><paragraph id="H9A1F239C66124C048C9073085B08B36F"><enum>(8)</enum><text display-inline="yes-display-inline">Any recommendations for United States citizens and United States businesses to implement best practices on mitigating ransomware and other cyber-related attacks.</text></paragraph></subsection><subsection id="H8D6C29D4BC734496BD39993632A45B22"><enum>(b)</enum><header>Individuals, companies, and governments described</header><text>The individuals, companies, and governments described in this subsection are the following:</text><paragraph id="H73C4A12CCD684685871A0F2A1105EE7E"><enum>(1)</enum><text display-inline="yes-display-inline">An individual located within Russia or with direct or indirect ties to the Government of the Russian Federation.</text></paragraph><paragraph id="H054370CD117B4CFBB284413753AFDA23"><enum>(2)</enum><text>A company located within Russia or with direct or indirect ties to the Government of the Russian Federation.</text></paragraph><paragraph id="HB64DF35E40AE44409AC696D6574D526F"><enum>(3)</enum><text>The Government of the Russian Federation.</text></paragraph><paragraph id="HD5790E841F4F40019773592585F2E04F"><enum>(4)</enum><text>An individual located within China or with direct or indirect ties to the Government of the People’s Republic of China.</text></paragraph><paragraph id="H4B4D4D722E8B4188A7F09558DB4DF6A7"><enum>(5)</enum><text>A company located within China or with direct or indirect ties to the Government of the People’s Republic of China.</text></paragraph><paragraph id="HFCC9050B78D546E6AC735E278EE07919"><enum>(6)</enum><text>The Government of the People’s Republic of China.</text></paragraph><paragraph id="HFEA9CC2F5EFA49C3BD0F28B65ECE9A70"><enum>(7)</enum><text>An individual located within North Korea or with direct or indirect ties to the Government of the Democratic People’s Republic of Korea.</text></paragraph><paragraph id="HB273BAC4DC7344AD97A3DB878CCBD65D"><enum>(8)</enum><text>A company located within North Korea or with direct or indirect ties to the Government of the Democratic People’s Republic of Korea.</text></paragraph><paragraph id="H6D0C1273B0754981B9514240B854C154"><enum>(9)</enum><text>The Government of the Democratic People’s Republic of Korea.</text></paragraph><paragraph id="H2DAAFA6EDD7C4477A721BF5AB4E01D9B"><enum>(10)</enum><text>An individual located within Iran or with direct or indirect ties to the Government of the Islamic Republic of Iran.</text></paragraph><paragraph id="H8CCD9365687B45A2B50D06EA15248A54"><enum>(11)</enum><text>A company located within Iran or with direct or indirect ties to the Government of the Islamic Republic of Iran.</text></paragraph><paragraph id="H0C86871588074E789D1FE9B5FDB999F9"><enum>(12)</enum><text>The Government of the Islamic Republic of Iran.</text></paragraph></subsection></section></legis-body></bill> 

