Skip to main content

California poised to add ransomware law that carries sentence of up to four years

california ransomware law jailed
Image used with permission by copyright holder
A bill that would classify ransomware as extortion has made its way through California’s legislature, paving the way for potential jail sentences of between two and four years for offenders.

The bill, SB 1137, was authored by Sen. Robert Hertzberg. Last week, the bill passed the state assembly with a couple of amendments, and headed to the desk of Gov. Jerry Brown, along with a number of other bills, to be signed into law.

Cybercrime was previously covered in California by older laws but this newer bill classifies ransomware as extortion because it is specifically used to make money off victims. Ransomware encrypts a person’s device and holds it hostage until a ransom has been paid.

By classifying this particular cybercrime tactic as extortion, it allows prosecutors to call for jail terms of between two and four years. The bill also defines “triggering a system malfunction” or “password lockout” as felonies.

Hertzberg described ransomware as “electronic stickup,” and said the existing law needed greater clarity. “We need to make clear that intentionally using ransomware is a very serious crime that will not be tolerated and will be prosecuted, just like any stickup. That’s what this legislation does,” he said.

TechNet, a trade organization whose members include Microsoft, Cisco, and Apple, along with Los Angeles County District Attorney Jackie Lacey, co-sponsored the bill.

“These criminals are turning ransomware into a sure way to cash in on just about any network intrusion, and we must send the signal that this criminal activity is punishable in a way that will deter this type of activity,” said Andrea Deveau, executive director of TechNet.

California has had a few notable run-ins with ransomware. In February, a Los Angeles hospital paid $17,000 to pay off its ransom and regain access to its files.

Only one organization is known opposed the bill, according to StateScoop. Legal Services for Prisoners with Children said the bill will only make jail sentences longer and will not add any further protections to victims of ransomware.

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
A dangerous new jailbreak for AI chatbots was just discovered
the side of a Microsoft building

Microsoft has released more details about a troubling new generative AI jailbreak technique it has discovered, called "Skeleton Key." Using this prompt injection method, malicious users can effectively bypass a chatbot's safety guardrails, the security features that keeps ChatGPT from going full Taye.

Skeleton Key is an example of a prompt injection or prompt engineering attack. It's a multi-turn strategy designed to essentially convince an AI model to ignore its ingrained safety guardrails, "[causing] the system to violate its operators’ policies, make decisions unduly influenced by a user, or execute malicious instructions," Mark Russinovich, CTO of Microsoft Azure, wrote in the announcement.

Read more