<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-DUN21758-C64-WK-KTF"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S2926 IS: To require certain entities to disclose to the Secretary of Homeland Security ransom payments, and for other purposes. </dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-10-04</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 2926</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20211004">October 4, 2021</action-date><action-desc><sponsor name-id="S366">Ms. Warren</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require certain entities to disclose to the Secretary of Homeland Security ransom payments, and for other purposes. </official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="HB02C894A46244E62B062EF473AACF289"><section section-type="section-one" id="H874EA66720C3493FAA93F47F52EA03DF"><enum>1.</enum><header>Disclosure of ransom payments</header><subsection id="HF059AF5EDF67441186EFCB8CF43970FC"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="HF270B09916264172B5A1C1A5F0E2003B"><enum>(1)</enum><header>Covered entity</header><text display-inline="yes-display-inline">The term <term>covered entity</term>—</text><subparagraph id="id45F96EA9FF194BEF8BC3116A4FA45DC5"><enum>(A)</enum><text display-inline="yes-display-inline">means a public or private entity that—</text><clause id="id203A030D0B734E2CA24917D566179162"><enum>(i)</enum><text display-inline="yes-display-inline">is engaged in interstate commerce or an activity affecting interstate commerce; or</text></clause><clause id="id5D702A6AFFA74102A8759C922CD722EC"><enum>(ii)</enum><text>receives Federal funds;</text></clause></subparagraph><subparagraph id="id8F37F89024C244218406FD8B8D46F2DA"><enum>(B)</enum><text>includes a local government; and</text></subparagraph><subparagraph id="id2BEEB9F0C8704F1EA1BD95963CC480C7"><enum>(C)</enum><text>does not include an individual.</text></subparagraph></paragraph><paragraph id="H065CF60F9ECC472585E3C23E342CE2AA"><enum>(2)</enum><header>Information system</header><text display-inline="yes-display-inline">The term <term>information system</term> has the meaning given such term in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="H4C8EA285CCBD4593B3EEA3B9E69AF87C" commented="no" display-inline="no-display-inline"><enum>(3)</enum><header>Ransom</header><text display-inline="yes-display-inline">The term <term>ransom</term> means money or other thing of value demanded by an actor from a covered entity or individual after such actor gains control of an information system of such entity or individual.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id046929DA9D9B4F36B0EF892DD78215BB"><enum>(4)</enum><header>Secretary</header><text display-inline="yes-display-inline">The term <term>Secretary</term> means the Secretary of Homeland Security.</text></paragraph></subsection><subsection id="HE37C6E0144E2479FA66217951D7F7F8B"><enum>(b)</enum><header>Disclosure required</header><text display-inline="yes-display-inline">Not later than 7 days after the date on which a covered entity pays a ransom, the entity shall disclose to the Secretary, in accordance with subsection (b), such payment. </text></subsection><subsection id="H30ABA7C8E82147779EECE09DC74AF068"><enum>(c)</enum><header>Contents</header><text>A disclosure made under subsection (b) shall include, with respect to the ransom at issue, the following: </text><paragraph commented="no" id="H25B0E3153CE7407CA14FF61585B6F09B"><enum>(1)</enum><text>The date on which such ransom was demanded.</text></paragraph><paragraph id="HEE65C7E1D56247BDA8099413960DCCE4"><enum>(2)</enum><text>The date on which such ransom was paid.</text></paragraph><paragraph commented="no" id="H570C74DAF8BE4AB18EC890C7986CB01D"><enum>(3)</enum><text>The amount of such ransom demanded.</text></paragraph><paragraph id="H0004C9B4CA47498499BBE54753F544A7"><enum>(4)</enum><text>The amount of such ransom paid.</text></paragraph><paragraph id="HD322E225C30C443B8BFFF91BF34574FD"><enum>(5)</enum><text>An identification of the currency, including if cryptocurrency, used for payment of such ransom.</text></paragraph><paragraph id="H4220FE298DAC4D8DAC705A4D8A3C2C82"><enum>(6)</enum><text>Whether the covered entity that paid such ransom receives Federal funds.</text></paragraph><paragraph id="H6BD604245EE74100849253CB03531793"><enum>(7)</enum><text>Any known information regarding the identity of the actor demanding such ransom.</text></paragraph></subsection><subsection id="H735E510096D343B6AE46E331C365136D"><enum>(d)</enum><header>Noncompliance</header><text>The Secretary shall establish by regulation appropriate penalties for a covered entity that fails to make a disclosure required under subsection (b).</text></subsection><subsection id="H383A64F18F4E472CBBF423D43D38AA1F"><enum>(e)</enum><header>Public availability</header><paragraph id="HB37757DC26CF4D0F86CD8B5C5DC11E66"><enum>(1)</enum><header>In general</header><text>Not later than 1 year after the date of the enactment of this Act and annually thereafter, the Secretary shall publish on a publicly available website of the Department of Homeland Security the information disclosed under subsection (b) during the preceding 1-year period, including the total dollar amount of ransoms paid by covered entities during such period.</text></paragraph><paragraph id="HCDCCD907E170446EB77DBD12287FBAF4"><enum>(2)</enum><header>Exclusion of identifying information</header><text>Information that reveals the identity of a covered entity that made a disclosure under subsection (b) shall be excluded from the information published under paragraph (1).</text></paragraph></subsection><subsection id="H6C7DC1A841CC4DA28644C88D883B3D24"><enum>(f)</enum><header>Study and report on ransom commonalities</header><paragraph id="HA14C39B460094543B3BD70B5D4ED1152"><enum>(1)</enum><header>Study</header><text>The Secretary shall conduct a study to determine if—</text><subparagraph id="H7D7A91691E4D4C07860425B03D868DB4"><enum>(A)</enum><text>there are commonalities with respect to the information disclosed under subsection (b); and</text></subparagraph><subparagraph id="H9A2E6200AFB949DF9D0E43DD0961479A"><enum>(B)</enum><text>the extent to which cryptocurrency has facilitated the kinds of attacks that resulted in the payment of ransoms by covered entities.</text></subparagraph></paragraph><paragraph id="HF05D50A82472434B901148E6ADDB35C8"><enum>(2)</enum><header>Report</header><text display-inline="yes-display-inline">Not later than 15 months after the date of the enactment of this Act, the Secretary shall submit to Congress a report that includes—</text><subparagraph id="H570AB0437E51492BA6898BFC93C3E0C9"><enum>(A)</enum><text>the findings of the study conducted under paragraph (1); and</text></subparagraph><subparagraph id="HE2A466883DAC48EFB53364B158A98A15"><enum>(B)</enum><text>such recommendations as the Secretary considers appropriate for protecting the information systems of covered entities.</text></subparagraph></paragraph></subsection><subsection id="id78876A2E60044E9ABA61ABB0647B8C3F"><enum>(g)</enum><header>Individual reporting</header><paragraph id="idDC6BBD3A2FB24414B160345E3B395AA7"><enum>(1)</enum><header>In general</header><text>Not later than December 21, 2021, the Secretary shall establish a website through which individuals may voluntarily report the payment of a ransom by the individual.</text></paragraph><paragraph id="id03339A34B3E44634852FC69548739E57"><enum>(2)</enum><header>Incorporation of data</header><text>To the greatest extent practicable, the Secretary shall incorporate data from reporting by individuals under paragraph (1) in—</text><subparagraph id="id224F0AD0134A4F6495D99C5E3D204A58"><enum>(A)</enum><text>the information published under subsection (e); and</text></subparagraph><subparagraph id="id9541E0B5B8A7467DA4EBE89CC6F45AEA"><enum>(B)</enum><text>the study conducted under subsection (f).</text></subparagraph></paragraph></subsection><subsection id="H0E2FAE1712EE43B1AA026D832AFF8160"><enum>(h)</enum><header>Applicability</header><text>This section shall apply to ransoms paid on or after the date that is 90 days after the date of the enactment of this Act.</text></subsection></section></legis-body></bill> 

