Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • Treat Ransomware Criminals Like Terrorists, House Subcommittees Advised
    • Federal Court Asked to Block DoJ’s Demands for State Voter Data
    • Justices Wrestle With Arguments in FCC Privacy Cases
    • Legislation to Speed Data Deletion Requests Advances in California
    • Polish Agency Rejects Privacy Consultation With Lawyers’ Group
    • Postal Service, Bank Fined Over Privacy Violations in Italy
    • Preliminary Comments Sought on Potential Changes to California Privacy Rules
    • Spanish Privacy Regulator Analyzes Data Protection Issues in AI Voice Transcription
    • U.K. Agency Calls for Organizations to Focus on Severe Cyber Threats
    • VoIP Provider Given 14 Days to Respond to FCC’s Robocall Order
    • W.D. Mo.: Court trims data-breach suit against women’s health provider
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Treat Ransomware Criminals Like Terrorists, House Subcommittees Advised, (Apr 21, 2026)

    Organizations Mentioned:Federal Bureau of Investigation | USTelecom

    By Tom Leithauser

    Designating ransomware as a terrorist threat and deputizing private sector actors to go after foreign cyber scammers were among the ideas presented at a House hearing to reverse the rise of cyber-enabled financial crime.

    Noting reports that cyber crim ...

    By Tom Leithauser

    Designating ransomware as a terrorist threat and deputizing private sector actors to go after foreign cyber scammers were among the ideas presented at a House hearing to reverse the rise of cyber-enabled financial crime.

    Noting reports that cyber crime cost Americans more than $20 billion last year, Cynthia Kaiser, senior vice president of the Halcyon Ransomware Research Center, recommended that Congress direct the departments of State, Justice, and Treasury “to formally evaluate and report back to Congress on whether existing terrorism designation authorities ... can be applied to ransomware actors who knowingly target hospitals and critical life-safety infrastructure.”

    “The federal definition of terrorism under 18 U.S.C. § 2331 includes ‘violent acts or acts dangerous to human life’ that ‘appear to be intended to intimidate or coerce a civilian population,’” Ms. Kaiser noted in written testimony submitted for a joint hearing of the House Homeland Security Committee’s subcommittees on border security & enforcement and cybersecurity & infrastructure protection.

    “When a ransomware gang encrypts a hospital’s systems and demands payment under threat of continued system lockout—knowing that patients are being diverted, that dialysis is being delayed, that surgery schedules are being canceled—I believe a serious legal argument exists that this conduct falls within those [terrorism] definitions,” according to Ms. Kaiser, a former deputy assistant director of the Federal Bureau of Investigation’s cyber division.

    A terrorism designation “would unlock a powerful set of additional tools: asset freezing, heightened Intelligence Community collection authorities, expanded travel restrictions, and significant diplomatic consequences for nations harboring these individuals,” she noted.

    Josh Bercu, USTelecom’s SVP–policy, described the telecom sector’s work to prevent robocall-enabled cyber crime through its Industry Traceback Group. “The telecom industry has been making real and meaningful progress to protect American consumers by confronting illegal calls, including both illegal robocalls and scams,” he said in written testimony.

    He recommended, however, fostering closer partnerships among private-sector entities that combat cyber scams by providing a “safe harbor” for collaboration.

    “Emerging partnerships between telecom providers, financial institutions, tech platforms, and other stakeholders are showing real promise in identifying and disrupting scams,” Mr. Bercu noted.

    “A well-scoped safe harbor could unlock even deeper collaboration across the internet ecosystem to accelerate threat detection and better prevent consumer harm. Right now, however, privacy regulation and other legal concerns can inhibit companies from using and, where appropriate, sharing data that could help identify and stop fraud,” he told the subcommittees.

    Giving private-sector entities some law enforcement powers to disrupt cyber crime might also help, according to Ari Redbord, global head–policy at TRM Labs, a cryptocurrency research firm. “We live in a moment where the private sector holds much of the critical data and the public sector holds the authorities—but success depends on fusing the two in real time,” he said in written testimony.

    “Effective disruption requires ensuring government has access to actionable intelligence while enabling trusted private sector actors to move quickly, within clear legal frameworks, to freeze funds, identify bad actors, and dismantle criminal networks as activity unfolds,” Mr. Redbord said.

    “That reality should drive a more forward-leaning policy approach: granting narrowly scoped, government-authorized authorities for vetted private actors to take targeted action against the technical infrastructure of transnational criminal organizations,” he recommended.

    “Historically, governments have extended limited authorities to private actors to address threats that outpaced traditional state capacity. In the digital context, this could take the form of what might be called ‘cyber letters of marque,’ ‘authorized disruption authorities,’ or a structured ‘white hat intervention’ framework—mechanisms that allow approved entities, operating under strict oversight and accountability, to intervene in real time to disrupt illicit infrastructure, block transactions, or degrade criminal networks,” he explained.

    Megan Stifel, chief strategy officer at the Institute for Security and Technology, urged lawmakers to reverse personnel and funding cuts at the Cybersecurity and Infrastructure Security Agency if they hope to make progress against cyber crime.

    “Public reporting indicates CISA has lost one third of its workforce, an issue that this committee has raised during oversight hearings. While the cuts have been pitched as returning CISA to its core mission, this is clearly not the case in practice,” she told the subcommittees in her written testimony.

    “In an effort to fill some of the gaps left from these cuts, the Acting CISA Director recently announced a hiring sprint to bring on new talent to help protect the nation from the many threats arrayed against us. This quick reversal in hiring practices is clear evidence that the original cuts were too deep,” Ms. Stifel noted.

    She also recommended legislation to codify some of the private-public partnerships that were eliminated at CISA under the Trump administration, including the Critical Infrastructure Partnership Advisory Council (CPR, March 13, 2025).

    MainStory: TopStory FederalLegislation DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use